Darket Diaries
Darket Diaries

167: Threatlocker

A manufacturer gets hit with ransomware. A hospital too. Learn how Threatlocker stops these types of attacks. This episode is brought to you by Threatlocker.Sponsors This episode is sponsored by ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastru

Featured Speakers

Jack Rhysider HostDanny Jenkins Guest

Topics Discussed

Episode Summary

Executive Summary: The episode centers on how ransomware devastated a large manufacturing company, forcing a weeks-long recovery and leading to adoption of ThreatLocker’s default-deny zero-trust approach. It then expands into a broader case study from a hospital environment where ThreatLocker blocked ransomware tools, and closes with ThreatLocker CEO Danny Jenkins explaining the company’s origin, philosophy, and mission to replace default-allow security with application control and layered controls.

Main Topics: Ransomware outbreak at a large manufacturing company (Priority: 5/5): An IT leader describes a Conti ransomware attack that encrypted hundreds of servers and endpoints within minutes, halting operations and triggering an emergency recovery effort. Incident response under pressure (Priority: 5/5): The team had no mature playbook, had to isolate systems, rebuild imaging infrastructure manually, manage anxious executives, and make difficult choices between speed and full reconstruction. ThreatLocker as a default-deny control (Priority: 5/5): After traditional tools like Malwarebytes proved insufficient, the company adopted ThreatLocker to allow only approved applications and stop unknown software from executing. Hospital breach prevented by layered security (Priority: 5/5): A managed security provider used ThreatLocker and EDR at a hospital; stolen VPN credentials enabled intrusion, but ThreatLocker blocked ransomware tools such as AnyDesk and Rclone. ThreatLocker’s founding story and mission (Priority: 4/5): CEO Danny Jenkins explains that recovery from a devastating ransomware case inspired application control and a broader mission to shift the industry from default allow to default deny. Zero trust and practical security controls (Priority: 4/5): Jenkins argues that security should combine people, detection, and controls, with controls like MFA, IP restrictions, and application whitelisting being the most reliable. Operational tradeoffs and user friction (Priority: 3/5): The discussion addresses user complaints, support burdens, and why blocking by default is still viable because most users need only a small set of applications.

Key Arguments: Ransomware can encrypt an entire enterprise extremely quickly, so response must prioritize containment before restoration. Restoring from backup without understanding the intrusion can simply reintroduce the attacker or restore infected assets. Default-deny application control is more effective against ransomware than relying only on detection-based tools. Defense in depth matters: MFA, endpoint controls, and network restrictions should all be layered together. Zero trust is not about denying everything; it is about granting only the access required for a role. Detection tools can fail on unknown or novel attacks, but controls can still prevent execution or access. ThreatLocker’s value is strongest when malware or ransomware tries to run but is blocked before it can act. The best security posture is proactive prevention rather than hoping an alert will stop the breach in time.

Data Points: Employees at manufacturing company: 1,000 - The IT leader oversees a business with about a thousand employees across multiple UK and European sites. Sites operated: 17 - The manufacturing company runs across 17 sites in the UK and Europe. Servers encrypted: 250 - Conti ransomware encrypted all 250 Windows servers in about 15 minutes. Endpoints affected: 350 - The same attack also hit roughly 350 endpoints. Team size: 10 - The recovery team had about 10 people managing rebuilds and incident response. Outage duration proposed: 5 days or 3 weeks - Leadership was told business could come back faster in five days or be rebuilt properly in three weeks. Internet/Wi-Fi shutdown: 3 weeks - Wi-Fi was not turned back on until the end of the three-week recovery to avoid reinfection. ThreatLocker customer count: 70,000 companies - Danny Jenkins says roughly 70,000 companies use ThreatLocker. Ransom demand: $100,000s - The hospital’s attackers reportedly demanded hundreds of thousands of dollars in ransom. Initial ransom payment: $22,000 - In Jenkins’ early recovery case in Australia, the victim paid a $22,000 ransom but did not recover data. ThreatLocker support tickets: 70% to 80% unrelated to ThreatLocker - Jenkins says most support tickets stem from other software or environment issues, not ThreatLocker itself. Ransomware cases observed: ~125 - Across the 70,000 customers, he says around 125 ransomware cases were tracked. Trips to events: 120 - Jenkins says he did about 120 trips in a year to educate people about zero trust. Trade shows attended: 1,000+ - ThreatLocker reportedly attended over a thousand trade shows in a year.

Pivotal Quotes: "we were hit by ransomware, attackers are in my network, the alternative is you shut down the entire network" — Danny Jenkins: Explaining why default-deny controls are attractive after a ransomware incident. "I want to change the way the world thinks about security from default allow to default deny." — Danny Jenkins: Jenkins states ThreatLocker’s core mission. "It stopped everything from running if you didn't allow it to run." — IT leader at manufacturing company: Describing why ThreatLocker was compelling after the Conti attack.

Implications: The episode argues that ransomware resilience now depends on prevention-first controls, not just detection and recovery. For IT teams, zero trust, MFA, and application whitelisting can dramatically reduce attack impact and recovery time.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries