Requires Windows Agent 10.9.1 or greater.
To provide customers with the ability to control the registry keys that are monitored by ThreatLocker, we have introduced a new Advanced Setting called 'Monitored Registry Keys'.
By default, if this Advanced Setting is not enabled, ThreatLocker will monitor all of the ThreatLocker tamper-protected registry keys and all of the registry keys included in Detect policies.
To add additional registry keys that ThreatLocker should monitor, wildcarded registry paths can be set in the Monitored Registry Keys Advanced Setting.

Navigate to the Advanced Settings page.
Select '+ New Setting' button to open the Create Settings sidebar.

1. Under Setting Type, select Monitored Registry Keys.
2. Select the desired 'Applies To' level.
3. Select to place this setting at the top or bottom of the Advanced Settings list.
4. Input the desired registry key paths, which can include a * as a wildcard.
5. Click the green Add button to add that path.
Continue adding until all desired keys have been input.
Be sure to click the blue 'Create' button in the bottom left corner of the sidebar to save all settings.
Press the Update Agents button to deploy all newly added settings.
Help Center