What is ThreatLocker? #
ThreatLocker is a zero-trust endpoint protection platform that enforces application allow-listing, ring-fencing, storage control, and elevation control across managed Windows, macOS, and Linux computers.
Why Should You Use the ThreatLocker Connector? #
The ThreatLocker connector provides visibility into the assets in your environment. You can use this visibility to:
- ensure assets are managed per your security policies
- derive relationships between assets, users, applications, and data
How Does This Connector Work? #
Meridian executes read-only requests to the ThreatLocker REST API and ingests only meta-data about ThreatLocker devices. Meridian does not retrieve any data stored on your assets.
Configuring the Connector in Meridian #
| Field | Description | Example |
|---|---|---|
| URL | The URL for the ThreatLocker API. Format is: https://portalapi.<customer instance>.threatlocker.com | https://portalapi.acme.threatlocker.com |
| API Key | An API key that provides read access to device data. For details on creating an API User and its API token in ThreatLocker, see: | p7g444S3IZ5wmFvmzWmx14qACXdzQ25b |
| Organization ID | The GUID of the organization from which you want Meridian to ingest data. To use the top-level organization, leave the field value as all zeroes. | 00000000-0000-0000-0000-000000000000 |
Source Documentation #
Creating Credentials #
To create an API Token:
For details on creating an API User and API token in ThreatLocker, see:
.https://threatlocker.kb.help/api-users/
- For Role, select the new role that includes Computer Permissions > View Computers.
- For Organization, select the organizations you want to allow Meridian to access.
Required Permissions #
You must create a user role with the following permissions and assign the role to the new API User:
Computer Permissions > View Computers
https://support.kandji.io/kb/kandji-api#inspect-or-modify-a-token