For the best experience, the playbook should be discussed during onboarding with Cyber Hero Managed Detection and Response.
Please Note: The phone number for the ThreatLocker MDR team has changed to +1 (689) 444-3099. We suggest you save this number in your contacts list. All calls are recorded and saved for 60 days.
Cyber Hero Managed Detection and Response (MDR) allows the ThreatLocker Cyber Heroes to triage both Endpoint and Cloud Detect alerts and make decisions on your behalf following your playbook. This helps reduce alert fatigue, as you will only be contacted when alerts indicate a high probability of an incident.
By default, ThreatLocker has policies for known IoCs that will be applied to all organizations using Cyber Hero MDR, and alerts for those policies will automatically be monitored by the Cyber Heroes. Custom policies can also be eligible for monitoring, but they must first go through an approval process.
Configuring the Response Playbook
Once an organization has enabled Cyber Hero MDR, the playbook needs to be configured.
Navigate to Modules > ThreatLocker Detect.
At the top left-hand side of the screen, select the gray hamburger button.

Next, select either Endpoint Response Settings or Cloud Response Settings. The corresponding edit window will slide out from the right.
Configuring the Endpoint Response Playbook
From this sidebar, playbooks can be configured for the entire organization, specific computer groups, and individual computers based on an organization's specific needs.

Please Note: At a minimum, organizations will need to have playbook instructions specified at the Entire Organization level.
- Select the level at which the Response Settings should apply. By default, Entire Organization will be selected, but you can apply your Response Settings to individual groups or computers to better fit your needs.
- Select 'Enabled' to make these Response Settings active and viewable by the Cyber Hero MDR Team once all changes are finalized. Switching this option to Disabled will remove these settings from view.
- To apply this runbook to child organizations, make sure this switch is turned on. This switch will not be visible unless you select Entire Organization as your Applies To option.
- This dropdown field will appear once you have turned the switch for #3 on. Here, select the child organizations you also want to apply this runbook to. You can select individual child organizations from your list or include all of them.
- Please note that leaving this dropdown field blank will only apply your runbook to the organization you are currently in.
- Insert the name of a contact you would like the Cyber Hero Team to reach out to when your specified conditions are met.
- Enter the email address of the same listed contact; make sure this contact is okay with receiving emails at the specified address from the Cyber Hero Team.
- Enter the phone number of the same listed contact; make sure this contact is okay with receiving calls at the specified phone number from the Cyber Hero Team.
- Select the 'Add' button to save this contact information and add this user to the list of contacts the Cyber Hero Team is allowed to reach.
- Multiple contacts can be entered by repeating steps 5-8.
- Your list of specified contacts. After a contact is added via the button in #8, it will appear here. You can change the added contact's information by selecting the 'wrench' icon, or delete the contact by selecting the 'trash can' icon.
- Add your specified runbook instructions to this field. This can include any information you want the Cyber Hero team to follow in the event of a suspected security breach. Some information that should be included consists of:
- What should the Cyber Heroes do in the event that no one answers the phone?
- How many times should the Cyber Heroes attempt to call before defaulting to the fallback response?
- Should the Cyber Heroes Isolate or Lockdown machines when certain alerts are triggered?
When all information is entered, select the 'Save' button to save the playbook.
If needed, change the 'Applies To' dropdown selection and create a new set of playbook instructions for all areas that require different instructions from the 'Entire Organization' level. When finished, select 'Save' to commit the changes.
Configuring the Cloud Response Playbook
Cloud Detect Response Setting will apply to all connected tenants.

1. Add the name of a contact that will be contacted if the Cyber Heroes observe suspicious behavior.
2. Add the phone number of the listed contact.
3. Select the 'Add' button to commit the contact to the list of contacts.
Multiple contacts can be entered by repeating steps 1-3.
4. In the text box, insert the instructions the Cyber Heroes need to follow in the event there is a suspected cyber incident.
Key information to include in the text of the playbook:
What should the Cyber Heroes do in the event no one answers the phone?
How many times should the Cyber Heroes attempt to call before defaulting to the fallback response?
Should the Cyber Heroes Lock Out accounts if certain alerts trigger?
Press 'Save' to save the playbook.
It is very important that both playbooks include accurate contact information and instructions so the Cyber Hero team can act appropriately in the event IoCs are observed.
When the Cyber Heroes receive an alert, the instructions outlined in the playbook level closest to the computer experiencing the alert will be followed. For example, if there is a computer-level playbook for that computer, those instructions will be followed. If there are no computer-level instructions, group-level instructions will be followed. If there are no group-level instructions, the organization-level instructions will be followed.
It is very important that the playbook includes accurate contact information and instructions so the Cyber Hero team can act appropriately in the event IoCs are observed.
Submitting Custom Policies for Cyber Hero MDR
To submit custom ThreatLocker Endpoint and Cloud Detect policies for Cyber Hero MDR, policies will need to have an action to 'Create Alert'.
In the Policy Action section, select 'Create Alert'. Set the Severity, Threat Level, Summary, and Details as desired.
Press the 'Request Monitoring' button.

Press the 'Create' button at the bottom of the policy to save and submit the policy for approval. Once a policy has been submitted for approval, it will no longer be editable. Until you receive notification that a policy has been approved, it will be your responsibility to triage any alerts received from that policy.

Press 'Yes' to acknowledge the information and proceed with submitting the policy for Cyber Hero MDR review.
You will receive a link to the Help Desk ticket associated with this request, where you can follow its progress.

The Cyber Hero team will continually evaluate policies and can decline or remove a policy from management if it is causing too many false alerts.
For more information or assistance, please reach out to the Cyber Heroes, who are always available to help.
Help Center