Linux Agent
ThreatLocker Modules Supported Linux Agent
- Version 1.x Allowlisting & sudo Elevation
- Version 2.x Network Control
- Version 3.x ThreatLocker Detect & eBPF
- Version 11.x ( upcoming ) Secure Network
- Version 12.x ( upcoming ) Storage Control
- Version 13.x ( upcoming ) Ringfencing
Supported Linux Versions | ThreatLocker Help Center
Linux Agent Version 11.0:
Beta: 8/28/2026
Bug Fixes
- The Linux Agent now automatically detects and synchronizes local machine hostname changes to the ThreatLocker Portal during regular heartbeat intervals.
- Resolved an issue and enhanced the Linux Agent registration process to ensure the agent remains in a stable state if a registration failure occurs.
- Resolved an issue in the Linux Agent where intermittent PID errors occurred on eBPF-enabled systems by preventing concurrent execution attempts from multiple threads within the same application.
- Resolved an issue where built-in policies were not correctly taking precedence over custom policies with matching rules.
- Resolved an issue where the Linux Agent attempted network challenges for inactive Network Access Control (NAC) policies.
- Resolved an issue with the severity level of internal logging when applying products and features simultaneously, ensuring more accurate reporting in agent logs.
- Resolved an issue with the performance of SSH connections on Linux systems by reducing connection latency when the agent is installed.
- Resolved an issue where Network Control policies for specific Windows processes incorrectly blocked outbound traffic on Linux devices.
- Resolved an issue where the Linux Agent failed to start correctly after a version downgrade on RHEL-based distributions.
- Fixed an issue where the Linux Agent could fail to start following an upgrade or downgrade process.
- Resolved an issue where the Linux Agent's IP address caching logic to prevent redundant log entries when local network configurations remain unchanged.
- Resolved an issue where policy handling was updated to ensure private key checks are only performed for policies routing through broker servers, resolving an "error: private key is not set" issue.
- Resolved an issue where the Linux Agent update and downgrade process on SUSE 12.5
- Resolved an issue where exclusions were not correctly applied to the Linux Agent, ensuring that defined process and file exclusions are properly recognized and enforced.
- Resolved an issue where Docker container /runc errors occurred during path reconstruction on Linux servers.
- Resolved an issue where Linux SSH connections via ZTNA would occasionally fail to complete.
- Resolved an issue where the Linux Agent incorrectly attempted to route network traffic through the broker even when no relevant policies or ZTNA beneficiaries were configured.
New Features and Improvements
- The Linux Agent now supports the implementation and application of Secure Network Policies and Network Configuration (ZTNA).
- Introduced support for new secure network policy routing values, including ZTNA, direct bypass, website categories, and SaaS applications.
- Implemented automatic identification and connection to the closest server for ZTCA policies, improving connection performance and reliability.
- Enhanced the Linux Agent to support custom SaaS application tagging, enabling more granular control and integration with Zero Trust Cloud Access policies.
- The Linux Agent now displays a block page when a Secure Network policy with a Website Category type is triggered, providing users with information about the block and the ability to request access.
- Improved Linux Agent device-to-device communication by ensuring peer validation is only attempted when a valid subnet mapping exists.
- The Linux Agent now automatically sends update logs to the portal at 10-second intervals during the update process, providing improved visibility into agent updates
- Improved restart policy to no more than once every two minutes, ensuring only the most recent restart request is applied during this interval.
- The Linux Agent now reports unsupported kernel versions to the portal before shutting down, providing improved visibility and troubleshooting for kernel compatibility issues.
- The Linux Agent now includes command-line interface (CLI) support for tracking and displaying agent diagnostic counters.
- Improved Linux Agent diagnostics by including symbol files with release builds to facilitate more efficient debugging.
- Updated the Linux Agent to utilize the latest registration and IP reporting APIs for improved communication efficiency.
- Introduced enhanced logic for applying network policies and managing packet redirection during runtime.
- Improved Linux Agent troubleshooting capabilities by integrating a diagnostic collector that allows for the remote gathering and uploading of system information and agent logs.
- The Linux Agent now supports the ability to enable or disable Elevation Control features, including Application Control Elevation policies and Local Admin Management, via a centralized advanced setting.
- Improved the Linux Agent to support domain-level URL parsing, providing more granular control and consistency with other platforms.
- Enhanced the Unified Audit to include the Application File ID for application matches, allowing for more precise identification of the specific rule or file responsible for an event.
- Updated the Linux Agent's internal communication infrastructure to enhance performance and system stability.
- Enhanced the Linux Agent to perform automated version and compatibility checks for kernel drivers during startup to ensure system stability and continuous endpoint protection.
Linux Agent Version 4.0.9:
Live: 8/24/2026
Beta: 8/21/2026
Bug Fixes
- Resolved an issue with extensive logging by optimizing Tag Policies are applied promptly during the next heartbeat.
- Resolved an issue where the Linux Agent could experience high CPU utilization due to inefficient connection management.
Linux Agent Version 4.0.8:
Live: 8/13/2026
Beta: 8/12/2026
Bug Fixes
- Resolved an issue where the Linux agent kernel modules failed to load on specific supported RHEL 8.6 kernel versions.
Linux Agent Version 4.0.7:
Live: 8/10/2026
Beta: 8/6/2026
Bug Fixes
- Resolved an issue where "Failed to lock pthread mutex" error messages were incorrectly generated in the system logs
- Improved system performance and login responsiveness on Linux endpoints by optimizing event processing and user identification timeouts
Linux Agent Version 4.0.6:
Live: 8/5/2026
Beta: 7/31/2026
Bug Fixes
- Improved the efficiency of application updates by optimizing the data transfer process for large application sets.
- Resolved an issue where the Linux Agent failed to apply global policies to child organizations due to SQL syntax errors during application definition updates
New Features and Improvements
- Improved the application file download process to only include files relevant to an organization's active policies.
- Introduced the running kernel version within the Operating System information on the Computer Sidebar.
- Improved encryption of stored API credentials and installation keys to prevent unauthorized access.
Linux Agent Version 4.0.5:
Live: 7/21/2026
Beta: 7/20/2026
Bug Fixes
- Resolved an issue where the Linux Agent could intermittently cause image pull failures in Containerd by holding file handles on ephemeral mounts.
Linux Agent Version 4.0.4:
Live: 7/9/2026
Beta: 7/8/2026
Bug Fixes
- Resolved an issue with Linux Agent's performance by optimizing process lookups where high CPU usage could occur after several days of continuous operation on the same events.
Linux Agent Version 4.0.3:
Live: 6/24/2026
Beta: 6/9/2026
New Features and Improvements
- Introduced real-time unified audit logging for the Linux Agent, allowing users to enable or disable local log files via the command-line interface to monitor permit and deny events
- Improved the Linux Agent update process by optimizing library path parsing to ensure consistent performance across different distributions
- Improved the Linux Agent baseline process to ensure complete directory scanning when encountering symbolic link loops or missing files
- Improved Linux Agent logging by refining error classifications during baseline scans to ensure more accurate system reporting
- Optimized agent check-in times on Linux systems by resolving network communication delays during service restarts
- Introduced the ability to configure network exclusions within the Linux Agent to provide more granular control over network access control (NAC) policies
- Improved the Linux Agent installer to allow successful installation on RHEL 8.6 systems by broadening kernel version pattern matching.
- Removed the unnecessary certificate field from the Linux Agent Real-Time Unified Audit file to improve data accuracy.
- Updated the Linux Agent Real-Time Unified Audit to align logging behavior and interface formatting with Windows, including updated column names and improved data visibility.
Bug Fixes
- Resolved an issue where enabling Application Control on Linux caused increased execution times for Ansible Playbooks.
- Resolved an issue in the Linux Agent where command-line arguments in the Unified Audit logs were occasionally missing or incorrectly displayed
- Resolved an issue where certain files within Docker containers were being blocked due to hash calculation failures, ensuring consistent execution and learning for containerized processes.
- Resolved an issue in the Linux Agent where baseline logs were not uploading correctly due to looped symbolic links or missing files.
- Resolved an issue in Agent stability by resolving a filesystem error encountered during baseline directory scans on SUSE 12.
Linux Stub Installer 11.0:
Live: 06/01/2026
Bug Fixes
- Updated the Linux Stub Installer to prioritize connections through configured proxies or relays, only falling back to a direct connection if the proxy or relay is unavailable
Linux Agent Version 4.0.2:
Live: 5/21/2026
Beta: 5/20/2026
New Features and Improvements
- Added configurable network timeout options to threatlockerctl in Linux Agent
- Added configurable caching for Linux Agent network logs, allowing separate cache periods for permits, denies, inbounds, and outbounds, managed via threatlockerctl commands
Bug Fixes
- Resolved an issue in the Linux Agent where using 'ANY' and 'ALL' conditions together in Detect policies could cause incorrect policy logic
- Adjusted Linux Agent log reporting so only true errors are marked as "ERROR" level
Linux Agent Version 4.0.1:
Live: 4/30/2026
Beta: 4/10/2026
New Features and Improvements
- Added a new feature that can be triggered to optimize the Apps database by freeing up unused space.
- Adjusted the log level for non-critical messages to reduce unnecessary error reporting.
- Improved identification of executable files.
Bug Fixes
- Resolved an issue where enabling Tamper Protection on Ubuntu 24.04 could cause system instability.
- Resolved an issue where the Linux Agent did not consistently fall back to a direct portal connection after relay disconnection.
- Resolved an issue where upgrading the Linux Agent to version 4.x with older modules did not properly apply products, ensuring correct activation after upgrade.
- Resolved an issue where the heartbeat thread could stop unexpectedly, ensuring reliable agent check-ins and improved stability.
- Resolved an issue with file system monitoring.
Linux Agent Version 4.0:
Live: 4/4/2026
Beta: 3/31/2026
New Features and Improvements
- Added functionality to the Linux Agent to detect and report whether a device's IP address is static or dynamic during heartbeat/check-in.
- Added scheduled update functionality for the Linux Agent, available in version 4.0 and requires using the "Update Agent" action.
- Added support for Amazon Linux 2023 (AL2023).
- Added support for the new device registration flow in the Linux Agent, including handling of pending, approved, and rejected registration statuses.
- Implemented support for a feature-centric billing model, allowing more granular control over features and continued compatibility with the existing product-based structure.
Bug Fixes
- Resolved an issue causing random crashes on RHEL 7.9.
- Resolved an issue where upgrades or downgrades could fail due to a race condition, ensuring reliable agent updates.
- Resolved an issue where the Linux Agent could lose connection and stop checking in after restarting with swapped feature packages.
- Resolved an issue where Ansible related proceses could cause high CPU usage.
Linux Agent Version 3.1.1:
Live: 2/12/2026
Beta: 2/10/2026
Bug Fixes
- Resolved an issue in Linux Agent where Docker processes were incorrectly denied.
- Resolved an issue with Netfilter buffer exhaustion
Linux Agent Version 3.1.0:
Live: 2/4/2026
Beta: 1/30/2026
New Features and Improvements
- Added conditional logging for inode number and flags to improve anti-tamper debugging.
- Added support for Rocky Linux 8.10 LKM.
- Added support for SUSE Linux Enterprise Server 12.5 SLES 15.5+.
- Added support in the Linux Agent installer for direct installation on testing instances using a new argument, improving testing flexibility.
- SUSE support has been improved in the Linux Agent 3.0 release, including enhanced compatibility and bug fixes for systems using the btrfs filesystem.
- The Linux Agent now automatically removes signing keys from the user's machine when the package is uninstalled.
- The Linux Agent now only logs ioctl commands in Anti Tamper mode when debug logging is enabled via the sysfs tl_debug flag.
- The Linux Agent STUB installer now supports automatic failover across multiple ISP IPs returned by DNS, improving connectivity and resiliency in multi-ISP environments.
- The Linux Agent STUB installer now supports SLES
Bug Fixes
- Improved the Linux Agent to properly cycle through backend IPs during endpoint calls, reducing installation failures and timeouts.
- Improved check-in times for Ubuntu 20 and earlier when network block policies are applied and the agent is restarted.
- Resolved an installation issue where the stub failed to install on Instance A.
- Resolved an issue in Linux Agent where private IP addresses were not always displayed.
- Resolved an issue where some execute actions were incorrectly logged as installs.
- Resolved an issue where certain blocked files could be executed without a permit policy.
- Resolved an issue where Flatpak applications were not being properly denied on RHEL-based Linux machines with kernel versions below 5.10.
- Resolved an issue where Tamper Protection interfered with system functionality on Ubuntu 16 machines.
- Resolved an issue with Linux Agent installation on RHEL 7 and similar systems, ensuring proper support for signed package installations on older operating systems.
- The Linux Agent now retains eBPF settings during uninstallation, eliminating the need for a reboot and ensuring user-enabled eBPF is not removed.
- Updated the Linux Agent to ensure IPv4 and IPv6 network policies are matched correctly, preventing unnecessary log warnings.
Linux Agent Version 3.0.2:
Live: 1/12/2026
Beta: 1/9/2026
New Features and Improvements
- Implemented support of Secure Boot for eBPF installations
Bug Fixes
- Resolved an issue with Linux system freezes in certain cases
Linux Agent Version 3.0.1:
Live: 12/31/2025
Beta: 12/30/2025
New Features and Improvements
- Implemented the signing process for Linux Agent binaries
Bug Fixes
- Resolved an issue with Debian 11 can be unsupported after upgrading to 3.0
- Resolved an issue with Agent/System (Ubuntu 24.04) that can hang after autoupdate
- Resolved an issue with hangs after being unable to reach to API
- Resolved an issue with a long reboot after enabling eBPF
- Resolved an issue in Linux Agent where "deny all inbound/outbound" network policies could block ThreatLocker APIs, ensuring agent connectivity is maintained.
- Resolved an issue in Linux Agent 3.0 that caused server crashes on Red Hat Enterprise Linux
Linux Agent Version 3.0:
Live:12/3/2025
This is being rolled out to all instances from 12/03/2025-12/05/2025.
Beta: 12/3/2025
Important
The eBPF approach to a Linux Agent will support every Linux Kernel version on supported systems. The eBPF feature is turned ON by default on most systems.
If it is turned OFF, TL Linux Agent 3.0 and up will turn it ON. To apply this change, the system must be rebooted.
To have proper notification on the portal side that your machine must be rebooted, please update to 2.4 first and then to 3.0.
New Features and Improvements
- Implemented eBPF (extended Berkeley Packet Filter), which allows our agent to plug into the kernel without requiring agent changes for each specific kernel (Kernel versions 5.10 and above)
- Added ThreatLocker Detect for Linux (coming in Portal 3.7)
- Added the ability to Lockdown and Isolate machines as part of Detect
- Added support for RHEL 10 (6.12.0-55.16.1 and 6.12.0-55.9.1.el10_0)
- Added support for Keywords and Objects in Network Control
- Added the ability to force kill running processes
- Made improvements to how ThreatLocker files are recognized by the agent
- Improved handling of SUSE dependencies
Bug Fixes
- Fixed an issue in which Oracle Server stopping checking in after update and restart
- Resolved an issue in which Scheduled Policies were not correctly being recognized
- Addressed a security issue in Linux Agent by ensuring all required shared libraries are bundled and validated during installation to prevent unauthorized code loading
- Updated the Linux Agent to block unauthorized processes from registering as the agent with the Anti-Tamper driver
- Fixed issue preventing the stub installer from completing installation on machines that do not support secure boot
- Resolve an issue in which uninstallation was failing to remove ThreatLocker packages
- Resolved an issue where private IP addresses were not being displayed
- Resolved an issue in the Linux Agent where certain Flatpak application files were skipped
- Resolved an issue in which the wrong API Url was being sent when using the Relay
- Resolved an issue in which the reboot message was not consistently being displayed for machines that the agent enabled eBPF on once installation was complete
- Added support for some Ubuntu 20 systems with certain kernels to use the legacy LKMs method instead of eBPF, preventing system hangs during installation.
Known Limitations
Additional instructions for Ubuntu 20.04:
Automatic activation of the LSM BPF option was disabled on Ubuntu 20.04, due to a critical bug in Ubuntu kernels before 5.15.0-53
If you are installing on a machine with a kernel which is older than 5.15.0-53 (not including).
No additional steps are needed; you can work with the agent as usual, and it will use the LKM implementation.
If you are installing on a machine with a kernel which is newer than 5.15.0-53 (including).
You need to manually enable the BPF LSM option. To do that, use Instruction 1. (Will be provided on request)
Note: You should do it before the agent is registered or immediately after.
In order to remove this option, use Instruction 2. (Will be provided on request)
Linux Agent Version 2.4:
Live: 12/1/2025
Beta: 11/12/2025
New Features
- Added ability to detect and enable eBPF during agent upgrades to version 3.0+.
Please note: A system reboot will be required if eBPF was enabled by the ThreatLocker Agent. Notification of the need to reboot will be displayed on the Devices page in the ThreatLocker portal.
- Added support for Linux stub use on ThreatLocker FedRAMP instance
Bug Fixes
- Resolved an issue where the Linux Agent did not automatically connect directly to ThreatLocker's APIs when all configured proxies or relays became unavailable
Linux Agent Version 2.3.1:
Live: 11/10/25
Beta: 11/4/25
Bug Fixes
- Resolved an issue with excessive disk space utilization on some systems
Linux Agent Version 2.3:
Live: 10/29/25
Beta: 10/27/25
New Features
- Added support for ThreatLocker Relay
Bug Fixes
- Resolved an issue with failed check-ins after the update
Linux Stub Installer 1.8:
10/27/2025
- Added support for ThreatLocker Relay
Linux Stub Installer 1.7:
10/15/2025
- Added support for STUB installer to install Rocky 9.5, 9.6
Linux Stub Installer 1.6:
10/9/2025
- Made improvements to the stub installer for Linux Agent
Linux Agent Version 2.2:
Live: 10/16/25
Beta: 10/10/25
Known issue
Proxmox Deny all network policy interrupts communication with the TL Cloud
Requires Linux Stub installer 1.7 or installation will fail
New Features
- Added Debian 11, 12, 13 support
- Added support for Regex custom rules
- Added proxy support for a STUB installer and agent
- Added support for the new API for registering a machine
Bug Fixes
- Fixed issue preventing the stub installer from completing installation on machines that do not support secure boot
- Changed Linux network logs to match Windows network logs behavior
- Resolved a case sensitivity issue affecting the Linux Agent's handling of files and directories
- Resolved an issue where manually restarting the Linux Agent did not take effect immediately
- Fixed an issue with incorrect encryption values while communicating with the Portal
- Resolved an issue where Linux upgrading sometimes failed during the process
- Resolved a problem where Linux maintenance modes were not ending as intended after expiration
- Fixed compatibility issues between Linux firewall and network control
- Resolved a problem with Linux IPv6 network policies not functioning properly
- Resolved application policies not matching when applied to a user or group
- Resolved caching issues related to policies in Ubuntu environments
- Fixed the logging of file executions in the /home mount
- Added caching to error logs to reduce the number of duplicate logs
- Network policies are now stored in a local file
- Added the ability for the agent to kill the running processes for an application
- Fixed scheduled Network Control policies not being applied
- Reduced the time that denies are cached for
- Baselining no longer learns customs during the KeyFile phase
- Resolved an issue where NFTables Firewall could overriding Network Control
- Resolved an issue with Flatpak
Linux Agent Version 2.1.2: Live 9/15/25
Bug Fixes
- Resolved an issue with the improper sending of OSType to the API
Linux Agent Version 2.1.1: Live 8/18/25
Bug Fixes
Resolved an issue where Install action types were not correctly logged.
After updating to 2.1.1 re-baselining is recommended.
If you require assistance with updating or re-baselining, please reach out to the Cyber Hero Team.
Previous versions of Linux 2.0.2 to 2.1.0 will be removed from production.
- Fixed an issue with Kernel Memory Leak
- Fixed an issue with agent settings being sent down
- Resolved an issue with spin locks to prevent crashing
- Optimized baselineing process to lower CPU load and crash possibility
- Resolved an issue with caching that would cause performance issues
New Features
- Added support for:
Ubuntu 22.04: 5.15.0-142-generic
Oracle Server 7.9: 5.4.17-2136.343.5.1.el7uek.x86_64
Oracle Server 8.10: 5.15.0-307.178.5.el8uek.x86_64 & 5.4.17-2136.345.3.5.el7uek.x86_64 - Added sending additional logs to the portal
- Added support for Oracle Linux 9.0, 9.4
- Updated Stub Installer with error message handling on Secure Boot
- Added support for:
Ubuntu 20: 5.4.0-214-generic
Ubuntu 22: 5.15.0-138-generic & 6.8.0-60-generic
Ubuntu 24: 6.8.0-58-generic & 6.11.0-21-generic
RHEL 9.6: 5.14.0-570.12.1
Linux Agent Version 2.0.1: Live 6/24/25
New Features
- Updated Stub Installer with error message handling on Secure Boot
- Added support for CentOS 9 Kernels:
5.14.0-582.el9.x86_64,
5.14.0-583.el9.x86_64,
5.14.0-585.el9.x86_64,
5.14.0-587.el9.x86_64,
5.14.0-590.el9.x86_64
Bug Fixes
- Resolved an issue with High CPU Usage
- Resolved an issue with the forceful swap of instances
- Resolved an issue with Tamper Protection reapplying
- Resolved an issue with RHEL 7.9 not matching built-ins
- Resolved an issue with the ability to change the API with Tamper Protection Enabled
Linux Agent Version 2.0: Live 5/27/25
New Features
- Network Control
- Added support Ubuntu 16.04, 18.04, 20.04, 22.04, 24.04
- Added support Centos 7.9, 9
- Added support RHEL 7.9
- Added support RHEL 9.x
- Added support RHEL 8.4, 8.5, 8.6, 8.8, 8.9, 8.10
- Added support Oracle Server 7.9
- Implemeted a Stub Installer
- Added Override Codes
- Increased stability
Bug Fixes
- Resolved an issue with downgrading the agent not properly working
- Resolved an issue in the Unified Audit with the Computer Mode for Linux showing the wrong values
- Resolved an issue where the Override Code was not bypassing Tamper Protection
- Resoved an issue where finishing a Baseline scan does not remove the "Waiting for Baseline" message on the Computers Page
- Resolved an issue in which Linux applications were being learned with the incorrect order by number
New list of supported systems:
Oracle Server 7.9: 2.0.0-692_ol_7_9.x86_64.rpm
Red Hat Enterprise Linux Server 7.9: 2.0.0-692_rhel_7.x86_64.rpm
RHEL [8.4, 8.5, 8.6, 8.8, 8.9, 8.10]: 2.0.0-692_rhel_8.x86_64.rpm
RHEL 9: 2.0.0-692_rhel_9.x86_64.rpm
CentOS 8: 2.0.0-692_rhel_8.x86_64.rpm
CentOS 7.9: 2.0.0-692_rhel_7.x86_64.rpm
CentOS 9: 2.0.0-692_rhel_9.x86_64.rpm [5.14.0-565.el9.x86_64]
You need to install this package for all RPM-based systems:
threatlocker_2.0.0-692_modules.rpm
Ubuntu Server 16.04: 2.0.0-692_ubuntu_16_4.x86_64.deb
Ubuntu Server 18.04: 2.0.0-692_ubuntu_18_4.x86_64.deb
Ubuntu Server 20.04: 2.0.0-692_ubuntu_20_4.x86_64.deb
Ubuntu Server 22.04: 2.0.0-692_ubuntu_22_4.x86_64.deb
Ubuntu Server 24.04: 2.0.0-692_ubuntu_24_4.x86_64.deb
You need to install this package for all DEB-based systems:
threatlocker_2.0.0-692_modules.deb
We still removed support for the following kernels due to inaccessible CentOS 8 repositories (temporary):
4.18.0-536.el8.x86_64
4.18.0-544.el8.x86_64
4.18.0-546.el8.x86_64
Known issues:
- it is possible to delete /etc/sudoers.d/threatlocker/ folder if it is empty (it will be re-created on Policy Update automatically, does not affect operations)
- it is possible to delete /var/cache/threatlocker/updates and /var/cache/threatlocker/downloads folders if they are empty (breaks auto-update)
- Some events can delay their appearance on the portal under heavy load
Installation/uninstallation instructions for ThreatLocker Linux Agent:
Linux Agent Installing and Uninstalling process
Linux Agent Version 1.4: Beta 3/4/25
New Features
- Added support Ubuntu 18.04
- Added support Ubuntu 16.04
- Added support Centos 7.9
- Added support Centos 8
- Updated heartbeat check in to call a new endpoint
- Implemeted a Stub Installer
Bug Fixes
- Downgrading not properly working
- Unified Audit - Computer Mode for Linux shows wrong values
- Add override capability to antitamper module
- Finishing a Baseline does not remove "Waiting for Baseline" message on Computers Page
- Build the ability to block specified TCP/UDP Traffic OUTBOUND
- Log Network Traffic Inbound and Outbound
- Logging Serial Number/Service Tag for Computers
- Resolved an issue in which Linux applications were being learned with the incorrect order by number
New list of supported systems:
Oracle Server 7.9 - 1.4.0-569_ol_7_9.x86_64.rpm
Red Hat Enterprise Linux Server 7.9 - 1.4.0-569_rhel_7.x86_64.rpm
RHEL 8.9 - 1.4.0-569_rhel_8.x86_64.rp
RHEL 8.10 - 1.4.0-569_rhel_8.x86_64.rpm
RHEL 9 - 1.4.0-569_rhel_9.x86_64.rpm
Centos 8 - 1.4.0-569_rhel_8.x86_64.rpm
Centos 7.9 - 1.4.0-569_rhel_7.x86_64.rpm
You need to install this package for all RPM based systems:
threatlocker_1.4.0-569_modules.rpm
You need to install both the threatlocker rpm and the module at the same time.
Example: sudo dnf install ./1.4.0-583_rhel_8.x86_64.rpm ./threatlocker_1.4.0-583_modules.rpm
Ubuntu Server 16.04 - 1.4.0-569_ubuntu_16_4.x86_64.deb
Ubuntu Server 18.04 - 1.4.0-569_ubuntu_18_4.x86_64.deb
Ubuntu Server 20.04 - 1.4.0-569_ubuntu_20_4.x86_64.deb
Ubuntu Server 22.04 - 1.4.0-569_ubuntu_22_4.x86_64.deb
Ubuntu Server 24.04 - 1.4.0-569_ubuntu_24_4.x86_64.deb
You need to install this package for all DEB based systems:
threatlocker_1.4.0-569_modules.deb
Example: sudo apt install ./1.4.0-583_ubuntu_24_4.x86_64.deb ./threatlocker_1.4.0-583_modules.deb
You need to install both the threatlocker deb and the module at the same time.
Linux Agent Version 1.3: Beta 3/4/25
New Features
- Added an Ubuntu Server 20.04 Agent
- Added an RHEL 8.9, 8.10 Agent
- Added support for Built-In Applications
- Added logging of inbound and outbound network traffic
- Made improvements to the baselining process
- We build and install our kernel modules on all systems including 5.0+ kernels. So now you need to install both packages on any supported system.
(For example, Ubuntu 24.04 require to install both [1.3.0-495_ubuntu_24_4.x86_64.deb, threatlocker_1.3.0-495_modules.deb]) - Added Override Codes
Bug Fixes
- Resolved an issue in which Applications were not learned until after the baseline was scanned
- Resolved an issue in which ThreatLocker modules were not installed on kernel update
- Resolved an issue in which snap applications for Linux do not fully capture in Learning Mode unless a baseline scan is run
- Resolved an issue with override capability to antitamper module
- Resolved an issue in which downgrading was not properly working
New list of supported systems:
Oracle Server 7.9 - 1.3.0-495_ol_7_9.x86_64.rpm
Red Hat Enterprise Linux Server 7.9 - 1.3.0-495_rhel_7.x86_64.rpm
RHEL 8.9 - 1.3.0-495_rhel_8.x86_64.rp
RHEL 8.10 - 1.3.0-495_rhel_8.x86_64.rpm
RHEL 9 - 1.3.0-495_rhel_9.x86_64.rpm
You need to install this package for all RPM based systems:
threatlocker_1.3.0-495_modules.rpm
Ubuntu Server 20.04 - 1.3.0-495_ubuntu_20_4.x86_64.deb
Ubuntu Server 22.04 - 1.3.0-495_ubuntu_22_4.x86_64.deb
Ubuntu Server 24.04 - 1.3.0-495_ubuntu_24_4.x86_64.deb
You need to install this package for all DEB based systems:
threatlocker_1.3.0-495_modules.deb
Linux Agent Version 1.2.1: Beta 3/4/25
Bug Fixes
- Resolved an issue in which downgrading was not properly working
Linux Agent Version 1.2: Live 10/18/24
New Features
- Added support for Policy statuses
- Added the ability to use Installation mode
- Added visibility of the Created By Process on Execute logs, and support to use the Created By Process in custom rules
- Added the ability to trigger a baseline scan from the portal
- Added logic to pull down Policies and Application definitions before the baseline scan begins
Bug Fixes
- Resolved an issue in which Applications were not learned until after the baseline was scanned
Linux Agent Version 1.2: Beta 09/25/24
New Features
- Added support for Policy statuses
- Added the ability to use Installation mode
- Added visibility of the Created By Process on Execute logs, and support to use the Created By Process in custom rules
- Added the ability to trigger a baseline scan from the portal
- Added logic to pull down Policies and Application definitions before the baseline scan begins
Bug Fixes
- Resolved an issue in which Applications were not learned until after the baseline was scanned
Linux Agent Version 1.1: Live 09/11/24
New Features
- Added Linux support for Heatbeat Check in and Full Check in
Bug Fixes
- Resolved an issue in which storage device serial numbers were not displaying correctly in the Unified Audit from a Linux machine
- Resolved an issue in which the Process Path in the Unified Audit was not reflecting the exact path of a file executed on Linux
Linux Agent Version 1.1: Beta 09/09/24
New Features
- Added Linux support for Heatbeat Check in and Full Check in
Bug Fixes
- Resolved an issue in which storage device serial numbers were not displaying correctly in the Unified Audit from a Linux machine
- Resolved an issue in which the Process Path in the Unified Audit was not reflecting the exact path of a file executed on Linux
Linux Agent Version 1.0.5.272: Live 9/9/24
New Features
- Install and uninstall instructions found here: Linux Agent Installing and Uninstalling Process | ThreatLocker Help Center
- Added the ability to specify an API URL into the installer file
- Added the ability to block and unblock files
- Added Tamper Protection
- Added support for Ubuntu Server 22.04.4 LTS (Jammy Jellyfish) and Red Hat Enterprise Linux 9.4 (Plow)
- Added the ability to request an application/file
- Added support for enabling/disabling products
Bugs and Fixes
- Resolved an issue in which user permission was denied on newly created Permit policies
- Resolved an issue in which the agent was ignoring Application Definition updates
- Resolved an issue in which installation failed due to lack of synchronization
- Resolved an issue in which the Linux agent was terminated on reboot if the machine lost internet access
- Resolved an issue in which actions that were performed with the same file by different users were only logging for the first user
- Resolved an issue in which multiple policies referring to the same binary were leading to a permanent binary lock
- Resolved an issue in which unexpected policies were generated for some applications
- Resolved an issue in which Sudo was not being impacted by Default - Deny
- Resolved an issue in which the Policy Name and Policy ID were not being displayed in the Unified Audit
Linux Agent Version 1.0.5.272: Beta (8/29/2024)
New Features
- Install and uninstall instructions found here: Linux Agent Installing and Uninstalling Process | ThreatLocker Help Center
- Added the ability to specify an API URL into the installer file
- Added the ability to block and unblock files
- Added Tamper Protection
- Added support for Ubuntu Server 22.04.4 LTS (Jammy Jellyfish) and Red Hat Enterprise Linux 9.4 (Plow)
- Added the ability to request an application/file
- Added support for enabling/disabling products
Bugs and Fixes
- Resolved an issue in which user permission was denied on newly created Permit policies
- Resolved an issue in which the agent was ignoring Application Definition updates
- Resolved an issue in which installation failed due to lack of synchronization
- Resolved an issue in which the Linux agent was terminated on reboot if the machine lost internet access
- Resolved an issue in which actions that were performed with the same file by different users were only logging for the first user
- Resolved an issue in which multiple policies referring to the same binary were leading to a permanent binary lock
- Resolved an issue in which unexpected policies were generated for some applications
- Resolved an issue in which Sudo was not being impacted by Default - Deny
- Resolved an issue in which the Policy Name and Policy ID were not being displayed in the Unified Audit
Help Center