ThreatLocker Tools
Written By Christopher Scaminaci
Last updated 7 days ago
ThreatLocker Tools
tl_ · 93 tools · Free 53 · Pro 40
Application allowlisting, ringfencing and endpoint control. The credential is an API user token sent as the raw Authorization value with no Bearer prefix - adding a scheme fails every call. The instance host is per tenant. Organization scope rides a managed organization id, defaulted from the credential and overridable on every tool. POST carries search filters here, so many POSTs are reads and the HTTP verb is not the safety boundary; there are no DELETE verbs at all, and deletion is a named POST or PUT. Paging is a page number with a page size capped at 500 here, since the vendor documents no maximum, and there are no cursors. The vendor publishes no response schemas, no rate limit and no idempotency contract, and its status meanings are inverted: a 401 means a missing permission and a 403 means a bad credential.
All connector tools · ThreatLocker setup guide
ThreatLocker tool groups
- Unified Audit — 1 tool
- System Audit — 2 tools
- Applications — 10 tools
- Application Files — 4 tools
- Approval Requests — 6 tools
- Config Manager — 2 tools
- Computers — 17 tools
- Device Activity — 2 tools
- Computer Groups — 10 tools
- DAC Analysis — 2 tools
- Policies — 8 tools
- Policy Deployment — 2 tools
- Maintenance Modes — 4 tools
- Organizations — 5 tools
- Override Codes — 3 tools
- Scheduled Agent Actions — 6 tools
- Reports — 3 tools
- Users & Roles — 4 tools
- Lookups — 2 tools
Unified Audit
tl_search_unified_audit details
tl_search_unified_audit details
[ThreatLocker] Search the Unified Audit — the activity log behind the Portal's Audit page. Requires a UTC start and end date (e.g. 2026-07-30T00:00:00Z) plus paging. Filters: actionId (Permit=1, Deny=2, Deny with request option=3, Ringfenced=6, Any Deny=99); actionType (execute, install, network, registry, read, write, move, delete, baseline, powershell, elevate, configuration, dns); hostname; fullPath; onlyTrueDenies; simulateDeny; showChildOrganizations. For a large range: run the search, read totalItems from the response headers, then pass that value back as totalRows on later pages — totalRows is a total-count hint, never a page size. Returns raw ThreatLocker JSON.
System Audit
tl_get_system_audit_health_center details
tl_get_system_audit_health_center details
[ThreatLocker] Get the Health Center view of the System Audit — the recent-activity rollup the Portal shows over a trailing number of days. Requires the day count, whether to scope to the signed-in administrator, and paging. Returns raw ThreatLocker JSON.
tl_search_system_audit details
tl_search_system_audit details
[ThreatLocker] Search the System Audit — the record of administrative and configuration changes in the ThreatLocker Portal. Requires a UTC start and end date plus paging; optional filters include the acting user's email address, the source IP address, a specific object id, an action list, free-text details, and child-organization inclusion. Use this to answer 'who changed this policy and when'. Returns raw ThreatLocker JSON.
Applications
tl_confirm_delete_applications details
tl_confirm_delete_applications details
[ThreatLocker] DESTRUCTIVE: step 2 of ThreatLocker's two-step application delete — confirms the deletion marked by tl_delete_applications. This is the irreversible step: the applications and their file rules are removed, and anything only permitted through them stops running. Send the same applicationsJson array ({applicationId, name, organizationId, osType}). This operation additionally requires the Edit Application Control Policies permission. Returns raw ThreatLocker JSON.
tl_create_application details
tl_create_application details
[ThreatLocker] Create a custom Application Control application. Requires a name and osType (Windows=1, MAC=2, Linux=3, Windows XP=5). Optionally seed its file rules with applicationFileUpdatesJson — a JSON array whose items are either {fullPath, processPath, installedBy, cert, notes, updateStatus} or {hash, notes, updateStatus}. An application on its own grants nothing until a policy references it. Returns raw ThreatLocker JSON.
tl_delete_applications details
tl_delete_applications details
[ThreatLocker] DESTRUCTIVE: step 1 of ThreatLocker's two-step application delete — marks the selected applications for deletion. Follow with tl_confirm_delete_applications to complete it. Deleting an application removes the allowlist definition, so anything only permitted through it stops running. Requires applicationsJson: a JSON array whose items are {applicationId, name, organizationId, osType}. Returns raw ThreatLocker JSON.
tl_get_application details
tl_get_application details
[ThreatLocker] Get one Application Control application by its GUID, as shown on the Portal's Applications page. Find ids with tl_search_applications. Returns raw ThreatLocker JSON.
tl_get_application_research_details details
tl_get_application_research_details details
[ThreatLocker] Get ThreatLocker's research data for one application — the vendor's own analysis shown on an application that has research available. Useful when deciding whether to permit an unfamiliar application. Returns raw ThreatLocker JSON.
tl_get_matching_applications details
tl_get_matching_applications details
[ThreatLocker] Find existing applications that already match a requested file — the check the Portal runs when you open an Application Control approval request. Supply the file's identity from the approval request: certificates, creators, TLHash, OS type, path, process path, and SHA256. Use this before approving so an existing application can be reused instead of creating a duplicate. Returns raw ThreatLocker JSON.
tl_list_applications_for_add_to_application details
tl_list_applications_for_add_to_application details
[ThreatLocker] List the applications a requested file can be added to — the pick-list used in the approval-processing workflow. Pass the osType of the requesting computer; searchText filters by application name. Note: ThreatLocker documents this operation only inside the approval workflow article, so its required/optional split is inferred from that text rather than a formal reference. Returns raw ThreatLocker JSON.
tl_list_applications_for_maintenance_mode details
tl_list_applications_for_maintenance_mode details
[ThreatLocker] List the applications selectable when starting a maintenance mode on a computer (the pick-list on the computer sidebar's Maintenance tab). Optionally filter by osType: Windows=1, MAC=2, Linux=3, Windows XP=5. Returns raw ThreatLocker JSON.
tl_search_applications details
tl_search_applications details
[ThreatLocker] Search Application Control applications. Requires orderBy, paging, and searchBy, which selects WHICH field searchText matches: app=Application Name, full=Full Path, process=Process Path, hash=Hash, cert=Certificate, created=Created By, categories=Category, countries=Where Code is Compiled. Optional category (0=All Applications, 1=My Applications/custom, 2=Built-In, 4=Patch Supported), osType (All=0, Windows=1, MAC=2, Linux=3, Windows XP=5), isAscending, isHidden, permittedApplications, includeChildOrganizations. Returns raw ThreatLocker JSON.
tl_update_application details
tl_update_application details
[ThreatLocker] Update one of your organization's custom applications (name, description, OS type) — the Save action on an application's Information tab. Built-in ThreatLocker applications cannot be edited. All four fields are required by the vendor, so read the current values with tl_get_application first and resend the ones you are not changing. Returns raw ThreatLocker JSON.
Application Files
tl_create_application_file_rule details
tl_create_application_file_rule details
[ThreatLocker] Add a file rule to an application (the Add Rule action on its Application Files tab). This widens what the application matches, so it widens what any policy permitting that application allows. The vendor requires every field: pass an empty string for conditions you are not using, and set isHashOnly true for a hash-only rule. Returns raw ThreatLocker JSON.
tl_delete_application_file_rule details
tl_delete_application_file_rule details
[ThreatLocker] DESTRUCTIVE: permanently delete one file rule from an application (the trash-can action on its Application Files tab, confirmed). Removing a rule narrows what the application matches, so files that relied on it stop being permitted. Requires the numeric applicationFileId plus the rule's identifying fields — read them with tl_list_application_files first. Returns raw ThreatLocker JSON.
tl_list_application_files details
tl_list_application_files details
[ThreatLocker] List the file rules inside one application — the Application Files tab. Requires the application GUID and paging; optionally restrict to hash-only rules, to custom (non-built-in) rules, or filter by text. Returns raw ThreatLocker JSON.
tl_update_application_file_rule details
tl_update_application_file_rule details
[ThreatLocker] Update an existing file rule inside an application (the Save action after editing a rule). Requires the numeric applicationFileId from tl_list_application_files plus every condition field — read the current rule first and resend the values you are not changing. Returns raw ThreatLocker JSON.
Approval Requests
tl_authorize_approval_request_permit details
tl_authorize_approval_request_permit details
[ThreatLocker] Authorize an approval request that the Cyber Hero team escalated to a customer administrator for a decision. Requires the approval request GUID; an optional message is recorded with the authorization. This grants the request's permit — review it with tl_get_approval_request_permit_application first. Returns raw ThreatLocker JSON.
tl_get_approval_request_count details
tl_get_approval_request_count details
[ThreatLocker] Get the number of PENDING approval requests — the badge the Portal shows on the Response Center. Requires includeChildOrganizations, so pass false for this organization only or true to count across child organizations. Cheap way to check whether there is a queue before searching it. Returns raw ThreatLocker JSON.
tl_get_approval_request_file_download_details details
tl_get_approval_request_file_download_details details
[ThreatLocker] Get the download details ThreatLocker holds for the file behind an approval request — the metadata shown when inspecting the requested file. Returns raw ThreatLocker JSON.
tl_get_approval_request_permit_application details
tl_get_approval_request_permit_application details
[ThreatLocker] Get the full detail behind one approval request — what the Portal loads when you click a request in the Response Center, including the requested file's identity and the permit options available. Read this before calling tl_permit_approval_request_application. Returns raw ThreatLocker JSON.
tl_permit_approval_request_application details
tl_permit_approval_request_application details
[ThreatLocker] Process an Execute or Elevate approval request into a permit — the Response Center's approve action. This CREATES a permit policy, so review the request first (tl_get_approval_request_permit_application) and check for an application to reuse (tl_get_matching_applications). ThreatLocker's request body is deeply nested, so pass it as JSON: required top-level fields are approvalRequest {approvalRequestId, comments, json, requestorEmailAddress, ticketApprovalManager, ticketId}, computerId, computerGroupId, fileDetails , isElevationRequest, matchingApplications {useMatchingApplication, matchingApplication, useExistingApplication, existingApplication, useNewApplication, newApplicationName}, organizationHasElevation, organizationId, organizationIds, osType, policyConditions {useExistingPolicy, manualOptions, ruleId}, policyLevel {toEntireOrganization, toComputerGroup, selectedComputerGroup, toComputer}, and ringfenceActionId. Optional groups add elevationStatus/elevationExpiration, networkExclusions, policyExpirationDate, and ringfencingOptions. See ThreatLocker's approval-processing article for the full template. Returns raw ThreatLocker JSON.
tl_search_approval_requests details
tl_search_approval_requests details
[ThreatLocker] Search Application Control approval requests (the Response Center's Approval tab). Requires statusId — Pending=1, Approved=4, Not Learned=6, Rejected=10, Added to Application=12, Escalated from the Cyber Heroes=13, Self-Approved=16 — plus paging. Optional searchText, orderBy, isAscending, and showChildOrganizations. Start here to find the approvalRequestId the other approval tools need. Returns raw ThreatLocker JSON.
Config Manager
tl_list_config_manager_configurations details
tl_list_config_manager_configurations details
[ThreatLocker] List the available Config Manager configurations with their categories — the settings catalog the Portal offers when creating or editing a Config Manager policy. Takes no inputs beyond the organization scope. Returns raw ThreatLocker JSON.
tl_search_config_manager_policies details
tl_search_config_manager_policies details
[ThreatLocker] Search Config Manager policies. Requires appliesTo (the GUID of the organization, computer group, or computer the policies apply to), paging, and status — Not Configured=-1, Disabled=0, Enabled=1, All=99. Optional searchText filters by name. Returns raw ThreatLocker JSON.
Computers
tl_delete_computers details
tl_delete_computers details
[ThreatLocker] DESTRUCTIVE: delete a computer from ThreatLocker. The device stops being managed and its history is removed from the Portal's device list. Requires the computer GUID and its organization GUID — verify both with tl_search_computers first. Returns raw ThreatLocker JSON.
tl_disable_computer_protection details
tl_disable_computer_protection details
[ThreatLocker] DESTRUCTIVE: disable ThreatLocker protection on one or more computers for a window. This REMOVES enforcement — during the window the endpoints are not protected by the allowlist. Requires computerDetailDtosJson (a JSON array of {computerGroupId, computerId, organizationId}), the start and end of the window as UTC ISO-8601, permitEnd, an applicationId (empty string when not scoping to one application), and maintenanceModeType: Application Control Monitor Only=1, Application Control Learning Mode=3, Disable Tamper Protection=6. Prefer the shortest window that does the job. Returns raw ThreatLocker JSON.
tl_enable_computer_protection details
tl_enable_computer_protection details
[ThreatLocker] Enable (secure) ThreatLocker protection on one or more computers — the hardening direction, moving devices back to Secure. Requires computerDetailDtosJson: a JSON array whose items are {computerId, organizationId}. Use tl_disable_computer_protection for the reverse. Returns raw ThreatLocker JSON.
tl_get_computer details
tl_get_computer details
[ThreatLocker] Get one computer's editable detail by GUID — what the Portal loads when you open a device for editing (name, group, proxy settings, options). Read this before tl_update_computer so you can resend the fields you are not changing. Returns raw ThreatLocker JSON.
tl_get_new_computer_defaults details
tl_get_new_computer_defaults details
[ThreatLocker] Get the defaults and options the Portal offers when adding a new computer to the organization. Takes no inputs beyond the organization scope. Returns raw ThreatLocker JSON.
tl_get_sample_deployment_path details
tl_get_sample_deployment_path details
[ThreatLocker] Get the sample deployment path for a brand, using an organization auth key. SENSITIVE: this call both takes and returns installation material — the auth key it needs is the organization's agent installation key (see tl_get_organization_auth_key), and anyone holding it can install agents into the organization. ThreatLocker does not document this endpoint's media type, so the call may fail with a content-type error on some instances. Returns raw ThreatLocker JSON.
tl_get_signed_deployment_script details
tl_get_signed_deployment_script details
[ThreatLocker] Get the SIGNED ThreatLocker agent deployment script for a brand. SENSITIVE: the response is deployment material for installing agents into this organization — handle it like a secret and do not paste it into shared channels. Note ThreatLocker does not document what media type this endpoint returns, so on some instances the call may fail with a content-type error; download the script from the Portal in that case. Returns raw ThreatLocker JSON.
tl_get_unsigned_deployment_script details
tl_get_unsigned_deployment_script details
[ThreatLocker] Get the UNSIGNED ThreatLocker agent deployment script for a brand. SENSITIVE: the response is deployment material for installing agents into this organization — handle it like a secret. ThreatLocker does not document this endpoint's media type, so the call may fail with a content-type error on some instances; download the script from the Portal in that case. Returns raw ThreatLocker JSON.
tl_move_computers_to_organization details
tl_move_computers_to_organization details
[ThreatLocker] DESTRUCTIVE: move computers to a different organization and computer group. This re-scopes which policies apply to those devices, so protection can change immediately. Requires computerDetailDtosJson — a JSON array whose items are {computerGroupId, computerId, computerName, group, hostname, maintenanceTypeId, operatingSystem, organization, organizationId, osType} — plus the target organization and group GUIDs and whether to run a learning rescan after the move. Discover targets with tl_list_organizations_for_move_computers. Returns raw ThreatLocker JSON.
tl_remove_duplicate_computers details
tl_remove_duplicate_computers details
[ThreatLocker] DESTRUCTIVE: remove duplicate computer records in the managed organization. The only input is whether to include child organizations — there is no per-computer selection and no preview, so ThreatLocker decides which records are duplicates. Run tl_search_computers first if you need to know what is currently registered. Returns raw ThreatLocker JSON.
tl_rescan_computer_baseline details
tl_rescan_computer_baseline details
[ThreatLocker] Trigger a baseline rescan on one or more computers, optionally enabling learning while it runs. Requires computerDetailDtosJson — a JSON array whose items are {computerId, organizationId, computerGroupId}. A rescan re-inventories what is installed so the allowlist reflects current software. Returns raw ThreatLocker JSON.
tl_restart_computers details
tl_restart_computers details
[ThreatLocker] DESTRUCTIVE: flag a computer to restart. This interrupts whoever is using the endpoint — confirm the target before running it. Requires the computer GUID and its organization GUID. Returns raw ThreatLocker JSON.
tl_restart_organization_computers details
tl_restart_organization_computers details
[ThreatLocker] DESTRUCTIVE and ORG-WIDE: flag EVERY computer in the managed organization to restart. There are no parameters — the target is whichever organization this call is scoped to, so double-check managedOrganizationId (or the connector's default) before running it. This interrupts every user in that organization. Returns raw ThreatLocker JSON.
tl_search_computers details
tl_search_computers details
[ThreatLocker] Search computers (the Devices page). Requires orderBy and paging. Optional filters: searchBy selects the field searchText matches (Computer and Asset Name=1, Username=2, Computer Group Name=3, Last Check-in IP Address=4, Organization Name=5); action filters by current mode or update channel (Secure, Installation, Learning, MonitorOnly, Manual Update, Pre-Releases, Regular, Expedited, Slow and Steady); kindOfAction selects which grouping the action applies to (Computer Mode, TamperProtectionDisabled, NeedsReview, ReadyToSecure, BaselineNotUploaded, Update Channel); plus computerId, computerGroup, childOrganizations, and isAscending. Returns raw ThreatLocker JSON.
tl_set_computer_maintenance_mode details
tl_set_computer_maintenance_mode details
[ThreatLocker] DESTRUCTIVE: put a computer into a maintenance mode. Several of these modes weaken enforcement (monitor-only, learning, tamper protection disabled) or cut the device off (isolation, lockdown), so treat it as a protection-state change. Note this operation takes the SINGULAR nested object computerDetailDtoJson = {computerId, maintenanceEndDate, maintenanceTypeId, organizationId, startDateTime} (dates UTC ISO-8601), unlike its sibling actions which take an array. maintenanceTypeId: Application Control Monitor Only=1, Application Control Learning=3, Elevation Mode=4, Secured=8, Disable ThreatLocker Detect=16, Network Control Monitor Only=17, Storage Control Monitor Only=18, Installation Legacy=19. applicationId accepts an application GUID or one of the documented literals autocomp, autogroup, autosystem, or an empty string. Returns raw ThreatLocker JSON.
tl_update_computer details
tl_update_computer details
[ThreatLocker] Update a computer's editable settings — name, computer group, and proxy configuration. The vendor requires every field, so read the current values with tl_get_computer first and resend the ones you are not changing. proxyServerOption is the scheme ("http://" or "https://"); optionsJson is the computer's options array. Moving a computer to a different group changes which policies apply to it. Returns raw ThreatLocker JSON.
tl_update_computer_agent_version details
tl_update_computer_agent_version details
[ThreatLocker] DESTRUCTIVE: change the installed ThreatLocker agent version on specific computers. An agent update touches the security software on managed endpoints and can require a restart. Resolve the version and version id with tl_list_agent_versions. Requires computerDetailDtosJson — a JSON array whose items are {computerId, organizationId, osType}. For a scheduled, batched rollout use tl_create_scheduled_agent_action instead. Returns raw ThreatLocker JSON.
Device Activity
tl_list_online_devices details
tl_list_online_devices details
[ThreatLocker] List the devices currently online in the managed organization. Paging is optional — omit both parameters to take ThreatLocker's own defaults. Returns raw ThreatLocker JSON.
tl_search_computer_checkins details
tl_search_computer_checkins details
[ThreatLocker] List one computer's agent check-in history. Requires the computer GUID, paging, and hideHeartbeat — pass true to suppress routine heartbeat rows and see only meaningful check-ins. Use this to diagnose an agent that has stopped reporting. Returns raw ThreatLocker JSON.
Computer Groups
tl_create_computer_group details
tl_create_computer_group details
[ThreatLocker] Create a computer group. Requires a name and osType — Windows=1, MAC=2, Linux=3, Windows XP=5, Ingester=6, iOS=10, Android=11. Optional settings shape how devices in the group behave: autoCreatePolicies, baselineAllPaths, baselineOptionsJson (a JSON string array), cyberHeroUseOrgSettings, exclusionsJson (a JSON array of {exclusionType, filePath, value}; one documented variant omits filePath), initialMonitorModeHours, optionsJson (a JSON string array), policyRefreshIntervalSeconds, and tlInstructions. Returns raw ThreatLocker JSON.
tl_delete_computer_group details
tl_delete_computer_group details
[ThreatLocker] DESTRUCTIVE: delete a computer group. Policies attached at the group level go with it, so any device that relied on them loses that protection or permission — check membership with tl_list_computer_groups_and_computers first. Requires the group GUID, its name, and its organization GUID. Returns raw ThreatLocker JSON.
tl_get_computer_group details
tl_get_computer_group details
[ThreatLocker] Get one computer group by GUID, including its baseline, exclusion, and monitor-mode configuration. Read this before tl_update_computer_group so you can resend the settings you are not changing. Returns raw ThreatLocker JSON.
tl_list_computer_group_options_by_organization details
tl_list_computer_group_options_by_organization details
[ThreatLocker] List the computer group dropdown options for the managed organization. Optionally filter by computerGroupOSTypeId (Windows=1, MAC=2, Linux=3, Windows XP=5) or by the string computerOSType ("windows", "mac", "linux", "windows xp"). Returns raw ThreatLocker JSON.
tl_list_computer_group_options_with_organization details
tl_list_computer_group_options_with_organization details
[ThreatLocker] List computer group dropdown options together with their organization. Note: ThreatLocker documents the includeAvailableOrganizations parameter's NAME but neither its type nor its accepted values, so StackJack forwards whatever literal you pass without interpreting it — omit it unless your instance's own API documentation tells you what to send. Returns raw ThreatLocker JSON.
tl_list_computer_groups_and_computers details
tl_list_computer_groups_and_computers details
[ThreatLocker] List computer groups together with their member computers — the combined tree the Portal uses for group-and-device pickers. Optional includeGlobal, includeOrganizations, includeParentGroups, and includeLoggedInObjects control how much of the tree comes back. NOTE the osType parameter: ThreatLocker labels it a boolean while documenting integer values (All=0, Windows=1, MAC=2, Linux=3, Windows XP=5), so StackJack forwards your literal without interpreting it rather than guessing which type is right. Returns raw ThreatLocker JSON.
tl_list_computer_groups_for_download details
tl_list_computer_groups_for_download details
[ThreatLocker] List the computer groups offered when downloading an agent installer — the group a newly installed device would join. Takes no inputs beyond the organization scope. Returns raw ThreatLocker JSON.
tl_list_computer_groups_for_permit_application details
tl_list_computer_groups_for_permit_application details
[ThreatLocker] List the computer groups selectable when permitting an application (the group-level choice in the approval flow). Optionally filter by osType: Windows=1, MAC=2, Linux=3, Windows XP=5. Returns raw ThreatLocker JSON.
tl_search_computer_groups details
tl_search_computer_groups details
[ThreatLocker] Search computer groups. Requires paging; optional searchText, showAllGroups, and an osType filter — All=0, Windows=1, MAC=2, Linux=3, Windows XP=5, Ingester=6, iOS=10, Android=11. Returns raw ThreatLocker JSON.
tl_update_computer_group details
tl_update_computer_group details
[ThreatLocker] Update a computer group. Requires its GUID, name, and osType (Windows=1, MAC=2, Linux=3, Windows XP=5, Ingester=6, iOS=10, Android=11.); the optional settings match tl_create_computer_group. Group settings apply to every device in the group, so read the current values with tl_get_computer_group first and resend what you are not changing. Returns raw ThreatLocker JSON.
DAC Analysis
tl_get_dac_analysis_item details
tl_get_dac_analysis_item details
[ThreatLocker] Get one DAC analysis item by its numeric id — the detail behind a single finding returned by tl_search_dac_analysis_results. Returns raw ThreatLocker JSON.
tl_search_dac_analysis_results details
tl_search_dac_analysis_results details
[ThreatLocker] Search DAC analysis results — configuration findings with their criticality. Requires paging. Optional filters: criticalityId (Low=1, Moderate=2, High=3, Critical=4); entityTypeId (organization=1, computer group=2, computer=3) with appliesToId naming the entity; categoryId (Network Policy=1, Storage Policy=2, Application Control=3, Registry Policy=4, Group Policy=6, Account and Authentication=7, Advanced Audit Configuration=8, Local Security=9, Patch Management=10, Remote Desktop and Access Control=11, User Rights Assignment=12, Detect and Response=13); plus includeChildOrgs, searchText, and sortBy. Returns raw ThreatLocker JSON.
Policies
tl_copy_policies details
tl_copy_policies details
[ThreatLocker] Copy existing policies from one scope to one or more target scopes. Requires osType (Windows=1, MAC=2, Linux=3, Windows XP=5), policiesJson (a JSON array of ), the source scope and organization GUIDs, and targetAppliesToIdsJson (a JSON array of destination scope GUIDs). The copies land at the target scopes and take effect once deployed. Returns raw ThreatLocker JSON.
tl_create_network_access_policy details
tl_create_network_access_policy details
[ThreatLocker] Create a Network Control access policy for a computer group. ThreatLocker documents every field as required. Enums: direction (Inbound=1, Outbound=2); protocol (Only TCP=1, Only UDP=2, Both TCP and UDP=3); policyActionId (Permit=1, Deny=2); policyScheduleStatus (No schedule/expiration=0, Expiration=1, Schedule=2); status (Active=1, Inactive=3). Array fields: sourceLocationsJson and destinationLocationsJson are JSON arrays of {ruleLocationTypeId, text, value}; networkAccessRulePortDtosJson is a JSON string array of ports; policySchedulesJson is a JSON array of {dayoftheWeek, startTime, durationHours, durationMinutes} — note the vendor's spelling of dayoftheWeek — and is used when policyScheduleStatus is 2. Pass an empty array for a group you are not scoping and set the matching allSources / allDestinations / allPorts flag instead. Returns raw ThreatLocker JSON.
tl_create_policy details
tl_create_policy details
[ThreatLocker] Create an Application Control policy. A policy is what actually permits, denies, or ringfences an application, so review the effect before creating one — and remember it does not reach endpoints until deployed (tl_deploy_policies). ThreatLocker's body is deeply nested, so pass it as JSON: required fields are applicationIdList (array of application GUIDs), computerGroupId, name, osType (Windows=1, MAC=2, Linux=3, Windows XP=5), and policyActionId: Permit=1, Deny=2, Permit with Ringfence=6. Optional groups include a schedule (policyScheduleStatus + policySchedules with dayoftheWeek / startTime / durationHours / durationMinutes), networkExclusions (tagPrefixTypeId: Domain=1, IPv4=2, IPv6=3), elevationStatus (Do not Elevate=0, Elevate to run as local administrator=1), killRunningProcesses, monitorMode, and ringfencingOptions with rfFilePolicy / rfNetworkPolicy / rfRegistryPolicy / rfAssociatedApplicationPolicy. See ThreatLocker's Policy article for the full template. Returns raw ThreatLocker JSON.
tl_delete_policies details
tl_delete_policies details
[ThreatLocker] DESTRUCTIVE: delete a policy. Whatever that policy permitted stops being permitted (or whatever it denied stops being denied), so check its effect with tl_get_policy first. ThreatLocker implements this deletion as a PUT rather than a DELETE — that is the vendor's design, not a mistake. Requires the policy and organization GUIDs; name is optional. Returns raw ThreatLocker JSON.
tl_get_policy details
tl_get_policy details
[ThreatLocker] Get one policy by GUID, including its conditions, schedule, and ringfencing configuration. Read this before tl_update_policy — an update replaces the policy body, so start from the current one. Returns raw ThreatLocker JSON.
tl_list_policies_for_application details
tl_list_policies_for_application details
[ThreatLocker] List the policies that reference one application — answers 'what would break if I delete or change this application'. Requires the application and organization GUIDs plus paging; optional appliesToId narrows to one scope and includeDenies adds deny policies. Returns raw ThreatLocker JSON.
tl_search_policies details
tl_search_policies details
[ThreatLocker] Search policies for a computer group. Requires the computer group GUID, a filter string, and paging. Optional activeOnly, showAllPolicies, searchText, and osType (Windows=1, MAC=2, Linux=3, Windows XP=5). Returns raw ThreatLocker JSON.
tl_update_policy details
tl_update_policy details
[ThreatLocker] Update an existing Application Control policy (a PUT — it replaces the policy body). Read the current policy with tl_get_policy first and send it back with your changes applied, or you may drop conditions, schedules, or ringfencing you did not mean to remove. Required fields are applicationIdList, computerGroupId, name, osType, policyActionId: Permit=1, Deny=2, Permit with Ringfence=6. and policyId. Optional groups match tl_create_policy, with elevationStatus adding Elevate (Do Not Notify User)=2. Changes reach endpoints only after deployment. Returns raw ThreatLocker JSON.
Policy Deployment
tl_deploy_policies details
tl_deploy_policies details
[ThreatLocker] DESTRUCTIVE and ORG-WIDE: deploy all pending policy changes to every endpoint in the managed organization. This is the moment policy edits start being enforced, so anything staged by someone else deploys too — check what is pending before running it. There are no parameters: the target is whichever organization this call is scoped to, so verify managedOrganizationId (or the connector's default) first. Returns raw ThreatLocker JSON.
tl_deploy_policies_for_computer details
tl_deploy_policies_for_computer details
[ThreatLocker] DESTRUCTIVE: deploy pending policy changes to ONE computer — the narrower alternative to tl_deploy_policies, and the safer way to verify a policy change before rolling it out. Requires both the computer GUID and its name (ThreatLocker documents both as query parameters for this endpoint). Returns raw ThreatLocker JSON.
Maintenance Modes
tl_create_maintenance_mode details
tl_create_maintenance_mode details
[ThreatLocker] DESTRUCTIVE: start a maintenance mode on a computer. Several of the documented modes WEAKEN enforcement (monitor-only, installation, learning, tamper protection disabled) and two cut the device off (isolation, lockdown), so this changes the device's security state for the whole window — prefer the shortest window that does the job. maintenanceTypeId: Application Control Monitor Only=1, Application Control Installation Mode=2, Learning=3, Elevation=4, Tamper Protection Disabled=6, Isolation=14, Lockdown=15, Disable Ops Alerts=16, Network Control Monitor Only=17, Storage Control Monitor Only=18. automaticApplicationType: empty=0, Automatic Computer=1, Automatic Group=2, Automatic System=3. All fields are documented required: dates are UTC ISO-8601 (computerDateTime is the device's own local time), existingApplicationJson is {applicationId, name}, newApplicationJson is {applicationId, applicationName, createApplicationOnly, appliesToId}, and usersListJson is a JSON array of users (empty array when allUsers is true). Returns raw ThreatLocker JSON.
tl_end_maintenance_mode details
tl_end_maintenance_mode details
[ThreatLocker] End an active maintenance mode on a computer now, restoring normal enforcement. This is the hardening direction, which is why it is not flagged destructive — but note that ending an installation window early can leave a half-installed application unlearned. Requires the computer GUID, the maintenance mode GUID (from tl_list_computer_maintenance_modes), and the mode's type. maintenanceTypeId: Application Control Monitor Only=1, Application Control Installation Mode=2, Learning=3, Elevation=4, Tamper Protection Disabled=6, Isolation=14, Lockdown=15, Disable Ops Alerts=16, Network Control Monitor Only=17, Storage Control Monitor Only=18. This operation also documents Installation Legacy=19. Returns raw ThreatLocker JSON.
tl_list_computer_maintenance_modes details
tl_list_computer_maintenance_modes details
[ThreatLocker] List the maintenance modes on one computer — current and historical windows, with their types and end times. Use this to see whether a device is currently in a relaxed state before troubleshooting a block, and to find the maintenanceModeId that tl_end_maintenance_mode needs. Requires the computer GUID and paging. Returns raw ThreatLocker JSON.
tl_update_maintenance_mode_end_date details
tl_update_maintenance_mode_end_date details
[ThreatLocker] Change when a computer's maintenance mode ends. Shortening the window restores enforcement sooner; EXTENDING it keeps the device in a relaxed (or isolated) state for longer, so check the mode type before extending. Requires the computer GUID, the new end date as UTC ISO-8601, and the mode's type. maintenanceTypeId: Application Control Monitor Only=1, Application Control Installation Mode=2, Learning=3, Elevation=4, Tamper Protection Disabled=6, Isolation=14, Lockdown=15, Disable Ops Alerts=16, Network Control Monitor Only=17, Storage Control Monitor Only=18. Returns raw ThreatLocker JSON.
Organizations
tl_create_child_organization details
tl_create_child_organization details
[ThreatLocker] Create a child organization (onboard a customer). Requires a displayName and timezoneId — list valid timezone ids with tl_list_timezones. Optional: name, domainsJson (a JSON string array of email domains), itarCompliant, hasDisabledEmailNotifications, optionsJson (a JSON string array), proxy settings, elevationDefaultHours (0, 1, 2, 6, 12, or 24), and timeoutOnLogin (15, 30, 60, 120, 240, 480, or 1440 minutes). Returns raw ThreatLocker JSON.
tl_get_organization_auth_key details
tl_get_organization_auth_key details
[ThreatLocker] Get the organization's agent installation auth key. SENSITIVE: the response IS a secret — anyone holding this key can install ThreatLocker agents into the organization, so do not paste it into tickets or shared channels. There are no parameters: the key returned belongs to whichever organization this call is scoped to, so be deliberate about managedOrganizationId — a wrong value returns a DIFFERENT customer's key. Returns raw ThreatLocker JSON.
tl_list_organizations_for_move_computers details
tl_list_organizations_for_move_computers details
[ThreatLocker] List the organizations a computer can be moved into — the destination pick-list for tl_move_computers_to_organization. Optional searchText filters by name. Returns raw ThreatLocker JSON.
tl_rotate_organization_auth_key details
tl_rotate_organization_auth_key details
[ThreatLocker] DESTRUCTIVE: rotate the organization's agent installation auth key. The existing key stops working immediately, so any deployment script, RMM package, or pending install still carrying the old key WILL FAIL until it is updated with the new one. There are no parameters — the key rotated belongs to whichever organization this call is scoped to, so verify managedOrganizationId (or the connector's default) before running it. Read the current key first with tl_get_organization_auth_key if you need to compare. Returns raw ThreatLocker JSON.
tl_search_child_organizations details
tl_search_child_organizations details
[ThreatLocker] Search the child organizations under the managed organization — your customer list. The GUIDs returned here are what you pass as managedOrganizationId on any other ThreatLocker tool to act on a specific customer. Requires orderBy and paging; optional includeAllChildren walks the whole tree, plus isAscending and searchText. Returns raw ThreatLocker JSON.
Override Codes
tl_create_override_code details
tl_create_override_code details
[ThreatLocker] DESTRUCTIVE: mint an override code — a code that lets an end user BYPASS ThreatLocker protection on the target scope. Treat it as handing out a temporary key: prefer the narrowest scope (a single computer over a whole organization) and the shortest usage limit. Requires appliesToId, appliesToType (Organization=1, Computer Group=2, Computer=3), noTimeLimit, and usageLimitMinutes. Setting noTimeLimit true creates a code that does not expire on its own — avoid it unless you have a specific reason, and revoke it when done. Returns raw ThreatLocker JSON.
tl_revoke_override_code details
tl_revoke_override_code details
[ThreatLocker] DESTRUCTIVE: revoke override codes for the managed organization. Anyone currently relying on a revoked code loses their bypass immediately. There are no parameters — the revoke applies to whichever organization this call is scoped to, so check what exists with tl_search_override_codes and verify managedOrganizationId (or the connector's default) first. Returns raw ThreatLocker JSON.
tl_search_override_codes details
tl_search_override_codes details
[ThreatLocker] Search the override codes issued for a scope — use this to audit which protection bypasses currently exist and how long they last. Requires appliesToId (the organization, computer group, or computer GUID) and paging; optional includeChildOrganizations, searchText, and showOnlyCustomerCodes. Returns raw ThreatLocker JSON.
Scheduled Agent Actions
tl_abort_scheduled_agent_action details
tl_abort_scheduled_agent_action details
[ThreatLocker] DESTRUCTIVE: abort a scheduled agent action. The queued work is destroyed — devices that already acted keep their new version, so an aborted rollout can leave the fleet on mixed versions. Requires the scheduledId, abortAll (true to abort every target), and appliesToJson (a JSON array of {appliesToId, appliesToTypeId} — appliesToTypeId: Organization=1, Computer Group=2, Computer=3, Global Computer Group=6.) naming the targets to abort when abortAll is false. Check progress with tl_search_scheduled_agent_actions first. Returns raw ThreatLocker JSON.
tl_create_scheduled_agent_action details
tl_create_scheduled_agent_action details
[ThreatLocker] Schedule an agent action — in practice a batched agent version rollout, and the safer alternative to forcing versions immediately. Requires appliesToJson (a JSON array of {appliesToId, appliesToTypeId} — appliesToTypeId: Organization=1, Computer Group=2, Computer=3, Global Computer Group=6. note the create article types appliesToId as a string while the abort article types it as a GUID), scheduledType (Version Update=1), and scheduledTypePayload (the type-specific payload, e.g. the target version). Optional batchAmount limits how many devices act at once, and startDate / windowStartTime / windowEndTime confine the rollout to a maintenance window. Returns raw ThreatLocker JSON.
tl_get_scheduled_agent_action details
tl_get_scheduled_agent_action details
[ThreatLocker] Get one scheduled agent action's full configuration by its GUID — the hydration read the Portal uses when reopening a schedule for editing. Returns raw ThreatLocker JSON.
tl_list_scheduled_action_applies_to details
tl_list_scheduled_action_applies_to details
[ThreatLocker] List the organizations, groups, and computers a scheduled agent action can target. Requires osType — note this operation's enum differs from the rest of the API: Windows=1, MAC=2, Linux=3, Red Hat Enterprise Linux 6=7. Optional includeChildren and searchText. Use the ids returned here to build the appliesTo array for tl_create_scheduled_agent_action. Returns raw ThreatLocker JSON.
tl_list_scheduled_agent_actions details
tl_list_scheduled_agent_actions details
[ThreatLocker] List the scheduled agent actions of a given type — currently only Version Update=1 is documented. Optional includeChildren includes schedules in child organizations. Start here to find a scheduledId. Returns raw ThreatLocker JSON.
tl_search_scheduled_agent_actions details
tl_search_scheduled_agent_actions details
[ThreatLocker] Search the detail of one scheduled agent action — its targets and their progress. Requires the scheduledId; optional computerGroupIdsJson and organizationIdsJson (JSON arrays of GUIDs) narrow the view, and paging, ordering, and searchText are all optional. Returns raw ThreatLocker JSON.
Reports
tl_get_report_data details
tl_get_report_data details
[ThreatLocker] Get one report's data by its GUID (from tl_list_reports). Only reportId is required. ThreatLocker documents four further fields — data, startDate, endDate, and id — without explaining what they mean for a given report, so pass them only if your instance's own documentation tells you to; they are forwarded as given. Returns raw ThreatLocker JSON.
tl_list_reports details
tl_list_reports details
[ThreatLocker] List the reports available to the managed organization. Takes no inputs beyond the organization scope; use the report ids it returns with tl_get_report_data. Returns raw ThreatLocker JSON.
tl_list_research_categories details
tl_list_research_categories details
[ThreatLocker] List the research categories ThreatLocker classifies applications under — the vocabulary behind application research data and the category filter on application search. Optional getStoreCategories includes store categories. Returns raw ThreatLocker JSON.
Users & Roles
tl_get_administrator_permissions details
tl_get_administrator_permissions details
[ThreatLocker] Get the effective permissions of the API User this connector authenticates as. Run this first when another ThreatLocker tool returns 401 — ThreatLocker uses 401 for a MISSING PERMISSION (403 is the bad-credential case), so this read shows whether the API User's role is short and what to add in the Portal. Takes no inputs beyond the organization scope. Returns raw ThreatLocker JSON.
tl_invite_user details
tl_invite_user details
[ThreatLocker] Invite a user to the ThreatLocker Portal with one or more roles. Requires the username (their email address) and rolesJson — a JSON array of {organizationId, userRoleId}, so one invitation can grant roles in several organizations. Resolve role GUIDs with tl_search_user_roles. The roles you grant decide what that person can see and change, so grant the least that fits. Returns raw ThreatLocker JSON.
tl_list_timezones details
tl_list_timezones details
[ThreatLocker] List the timezones ThreatLocker recognizes, with their ids — the values tl_create_child_organization needs. ThreatLocker documents this read as requiring no specific permission beyond a valid token, so it is also the cheapest way to confirm the connector's credentials are alive. Returns raw ThreatLocker JSON.
tl_search_user_roles details
tl_search_user_roles details
[ThreatLocker] Search the organization's user roles. Requires paging; optional searchText filters by name. The role GUIDs returned here are what tl_invite_user needs. Returns raw ThreatLocker JSON.
Lookups
tl_list_agent_versions details
tl_list_agent_versions details
[ThreatLocker] List the ThreatLocker agent versions available for deployment, as shown in the Portal's version dropdown. Use the returned version and version id with tl_update_computer_agent_version or tl_create_scheduled_agent_action. Returns raw ThreatLocker JSON.
tl_list_tag_options details
tl_list_tag_options details
[ThreatLocker] List the tag dropdown options available in the managed organization. Tags name reusable network locations (domains, IPv4/IPv6 values) that policy and ringfencing rules reference. Returns raw ThreatLocker JSON.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team