The ThreatLocker Device Discovery Feature helps administrators identify Windows devices on their network that do not have the ThreatLocker agent installed. This provides greater visibility into unprotected Windows devices connected to an organization's network.
Device Discovery and Unprotected Devices
Device Discovery helps identify devices on your network that may be eligible for ThreatLocker protection but do not currently have a ThreatLocker agent installed.
Discovered devices that are not recognized as protected appear under the 'Unprotected Devices' tab on the 'Assets' page.

How Device Discovery Works
A designated ThreatLocker-protected Windows computer acts as a Network Scanner. The computer must have ThreatLocker Agent version 11.0.33 or later installed.
The Network Scanner searches the network for Windows devices. When it discovers one, ThreatLocker compares the device with the list of computers that already have ThreatLocker installed.
- If ThreatLocker is installed, the device is reconized as protected and does not appear on the 'Unprotected Devices' page.
- If ThreatLocker is not installed, the device is added to the Unprotected Devices page.
When a device is discovered, ThreatLocker collects the following available information:
- Device type
- MAC address
- Manufacturer (when it can be identified from the MAC address)
- IP address
- Date/Time of observation
- Open ports
Note: Device Discovery currently looks for Windows devices only.
Configure Network Scanners
Navigate to the Assets page.
Select the Unprotected Devices tab in the upper right corner.
Select 'Configure Network Scanners' to open the Network Scanner configuration window.


From this window, authorized users can:
- Add a Network Scanner
- View configured Network Scanners
- Change the computers designated as Network Scanners
- Remove a Network Scanner
- Start a scan using the 'Scan Now' button
Use the computer dropdown to select a protected Windows computer to act as a Network Scanner.
We recommend you configure no more than 2 network scanners per network. For reliable discovery, select computers that are typically powered on and connected to the network, such as an Active Directory or File server.

Scan Frequency
Device Discovery runs automatically once per day.
Authorized users can also start a scan by selecting Scan Now. No more than four scans can be run within a 24-hour period.
Help Center