Learn how ThreatLocker can automatically create allowlist policies based on your organization’s needs after deployment.
Book DemoThreatLocker Learning Mode simplifies the process of setting up your Zero Trust environment, including your allowlist.
It's typically used to create an initial set of policies, for either a device or a group of devices, to allow software that's running on these devices to continue to run once the environment is secured. By default, the ThreatLocker agent is deployed in Learning Mode.
When a device is in Learning Mode, nothing is blocked or interrupted. The agent logs what is running in the environment, including all executables, libraries, and scripts.
During Learning Mode this data is used to create a set of recommended policies using advanced algorithms.
These advanced algorithms not only permit files by hash, but also where appropriate, will use a combination of variables such as path and certificate to give applications the ability to update themselves, even if specific files change.