Working with Your Existing Antivirus

3 min. readlast update: 08.08.2025

ThreatLocker plays nicely with existing antivirus software. We will neither conflict nor interfere with your AV software from running. However, you may need to create exceptions to prevent your antivirus software from blocking ThreatLocker. We recommend you exclude the following files from scanning:

Windows Antivirus software exclusions

  • C:\Program Files\ThreatLocker\threatlockerservice.exe
  • C:\Program Files\ThreatLocker\threatlockertray.exe
  • C:\Program Files\ThreatLocker\ThreatLockerConsent.exe
  • C:\Windows\System32\drivers\ThreatLockerDriver.sys
  • C:\ProgramData\HealthTService\Healthservice.exe
  • C:\Program Files\ThreatLocker\threatlockerelevationui.exe 
  • C:\Program Files\ThreatLocker\ThreatLockerMinHook.x64.dll
  • C:\Program Files\ThreatLocker\ThreatLockerMinHook.x86.dll
  • C:\Program Files\ThreatLocker\ThreatLockerAgent.x64.dll 
  • C:\Program Files\ThreatLocker\ThreatLockerAgent.x86.dll 
  • C:\Program Files\ThreatLocker\ThreatLockerPowerShellHook.dll 
  • C:\Program Files\ThreatLocker\ThreatLockerBits.dll 
  • C:\Program Files\ThreatLocker\6.0AMD64.db
  • C:\Program Files\ThreatLocker\6.0AMD64.db-journal 
  • C:\Program Files\ThreatLocker\6.0x86.db 
  • C:\Program Files\ThreatLocker\6.0x86.db-journal 
  • C:\Program Files\ThreatLocker\6.1AMD64.db 
  • C:\Program Files\ThreatLocker\6.1AMD64.db-journal 
  • C:\Program Files\ThreatLocker\6.1x86.db
  • C:\Program Files\ThreatLocker\6.1x86.db-journal 
  • C:\Program Files\ThreatLocker\6.2AMD64.db
  • C:\Program Files\ThreatLocker\6.2AMD64.db-journal 
  • C:\Program Files\ThreatLocker\6.2x86.db
  • C:\Program Files\ThreatLocker\6.2x86.db-journal 
  • C:\Program Files\ThreatLocker\6.3AMD64.db
  • C:\Program Files\ThreatLocker\6.3AMD64.db-journal 
  • C:\Program Files\ThreatLocker\6.3x86.db
  • C:\Program Files\ThreatLocker\6.3x86.db-journal 
  • C:\Program Files\ThreatLocker\10.0AMD64.db
  • C:\Program Files\ThreatLocker\10.0AMD64.db-journal 
  • C:\Program Files\ThreatLocker\10.0x86.db
  • C:\Program Files\ThreatLocker\10.0x86.db-journal 
  • C:\Program Files\ThreatLocker\apps.db
  • C:\Program Files\ThreatLocker\Application.db
  • C:\Program Files\ThreatLocker\apps.db-journal 
  • C:\Program Files\ThreatLocker\AzureAD.db
  • C:\Program Files\ThreatLocker\azuread.db-journal 
  • C:\Program Files\ThreatLocker\cert.db
  • C:\Program Files\ThreatLocker\cert.db-journal 
  • C:\Program Files\ThreatLocker\configmgr.db 
  • C:\Program Files\ThreatLocker\configmgr.db-journal 
  • C:\Program Files\ThreatLocker\detect.db 
  • C:\Program Files\ThreatLocker\detect.db-journal 
  • C:\Program Files\ThreatLocker\deniedactionqueue.db 
  • C:\Program Files\ThreatLocker\deniedactionqueue.db-journal 
  • C:\Program Files\ThreatLocker\dns.db
  • C:\Program Files\ThreatLocker\dns.db-journal 
  • C:\Program Files\ThreatLocker\fileinfov4.db
  • C:\Program Files\ThreatLocker\fileinfov4.db-journal 
  • C:\Program Files\ThreatLocker\fileinstall.db
  • C:\Program Files\ThreatLocker\fileinstall.db-journal 
  • C:\Program Files\ThreatLocker\nac.db
  • C:\Program Files\ThreatLocker\nac.db-journal 
  • C:\Windows\System32\drivers\etc\ThreatLockerPersistentRules.db
  • C:\Windows\System32\drivers\etc\ThreatLockerPersistentRules.db-journal 
  • C:\Windows\System32\drivers\etc\ThreatLockerCoreFileRules.db
  • C:\Windows\System32\drivers\etc\ThreatLockerCoreFileRules.db-journal 
  • C:\Program Files\ThreatLocker\apphash.json
  • C:\Program Files\ThreatLocker\appfiles.json
  • C:\Program Files\ThreatLocker\applications.json
  • C:\Program Files\ThreatLocker\policies.txt
  • C:\Program Files\ThreatLocker\256Mappings.json
  • C:\Program Files\ThreatLocker\actionlogqueue.json
  • C:\Program Files\ThreatLocker\certcache.json
  • C:\Program Files\ThreatLocker\dnscache.json
  • C:\Program Files\ThreatLocker\GroupMembers.json
  • C:\Program Files\ThreatLocker\ringfencedPaths.json
  • C:\Program Files\ThreatLocker\storagepolicies.txt
  • C:\Program Files\ThreatLocker\logo.jpg
  • C:\Program Files\ThreatLocker\icon.ico
  • C:\Program Files\ThreatLocker\v5policydownloaded.txt
  • C:\ProgramData\HealthTService\healthmonitorlog.txt
  • C:\Program Files\threatlocker\log.txt 
  • C:\Program Files\ThreatLocker\pk.dat 
  • C:\Program Files\ThreatLocker\ringfencehistory.json 
  • C:\Program Files\ThreatLocker\offlinepermissionrequests.json 
  • C:\Program Files\ThreatLocker\detectpolicies.txt 
  • C:\program files\threatlocker\fileinformationcache.json
  • C:\program files\threatlocker\authorizationhosts.txt
  • C:\Program Files\ThreatLocker\localadminsusers.txt 
  • C:\Program Files\ThreatLocker\configurationmanagerpolicies.txt 
  • C:\Program Files\ThreatLocker\configurations.txt 
  • C:\program files\threatlocker\networkaccesspolicies.txt
  • C:\program files\threatlocker\tags.json
  • C:\Program Files\ThreatLocker\opspolicies.txt 
  • C:\program files\threatlocker\threatlockerdriver.inf
  • C:\program files\threatlocker\ThreatLockerService.exe.config
  • C:\program files\threatlocker\ThreatLockerDriver.sys
  • C:\Program Files\HealthTLService\Healthservice.exe
  • C:\temp\ThreatLockerStub.exe
  • C:\ProgramData\threatlocker\*
  • C:\Program Files\ThreatLocker\logs

MAC Antivirus software exclusions

  • /Applications/ThreatLocker.app
  • /Applications/ThreatLocker.app/Contents/Resources/ThreatLocker UIAgent.app
  • /Applications/ThreatLocker.app/Contents/Resources/ThreatLocker Baseline Scanner.app
  • /Applications/ThreatLocker.app/Contents/Resources/ThreatLockerLogCollector
  • /Applications/ThreatLocker.app/Contents/Resources/ThreatLocker Health Service
  • /Applications/ThreatLocker.app/Contents/Resources/ThreatLockerUninstaller
  • /Library/Application Support/ThreatLocker/ThreatLockerStorage.db
  • /Library/Application Support/ThreatLocker/ThreatLockerStorage.db-shm
  • /Library/Application Support/ThreatLocker/ThreatLockerStorage.db-wal  
  • /Library/LaunchAgents/com.threatlocker.app.UIAgent.plist
  • /Library/SystemExtensions/{randomGuid}/com.threatlocker.app.agent.systemextension 
  • /Library/Application Support/ThreatLocker/ElevationConfigurationStorage.db
  • /Library/Application Support/ThreatLocker/ConfigurationStorage.db
  • /Library/Application Support/ThreatLocker/ConfigurationStorage.db~shm
  • /Library/Application Support/ThreatLocker/ConfigurationStorage.db~wal
  • /Library/Application Support/ThreatLocker/CacheStorage.db
  • /Library/Application Support/ThreatLocker/CacheStorage.db~shm
  • /Library/Application Support/ThreatLocker/CacheStorage.db~wal
  • /Library/Security/SecurityAgentPlugins/ThreatLockerAuthPlugin.bundle
  • /usr/local/lib/pam/ThreatLockerAuthModule.dylib

For the GUID System Extension installation, this is created automatically during installation and will need to be entered with the correct GUID in place of the {randomGuid} text, including the curly braces.

Linux Antivirus Software Exclusions

  • /etc/threatlocker/config.cfg
  • /etc/threatlocker/groupkey
  • /etc/threatlocker/ignoredRuleList
  • /etc/threatlocker/policies
  • /etc/threatlocker/policies/threatlocker/
  • /etc/threatlocker/policies/threatlocker_block/
  • /etc/threatlocker/policies/threatlocker_domain/
  • /etc/threatlocker/policies/threatlocker_locked_exec/
  • Only Ubuntu - /etc/threatlocker/policies/threatlocker_ubuntu_default/
  • /var/log/threatlocker.log, /var/log/threatlocker.1.log, /var/log/threatlocker.2.log, /var/log/threatlocker.3.log, /var/log/threatlocker.4.log
  • /etc/sudoers.d/threatlocker_sudoers_general
  • /etc/sudoers.d/threatlocker/
  • /etc/systemd/system/threatlocker-agent.service
  • /etc/systemd/system/threatlocker-policy@.service
  • /usr/local/bin/threatlocker-agent
  • /usr/local/bin/threatlockerctl
  • /usr/local/bin/threatlockerstarter
  • /bin/threatlockerctl
  • /usr/share/selinux/devel/include/threatlocker/
  • /etc/threatlocker/computerID
  • /etc/threatlocker/controlledApps.backup
  • /etc/threatlocker/<app name>_<type>_declaration/
  • /etc/threatlocker/<app name>_<type>/
  • /etc/threatlocker/threatlocker_controlled_applications/
  • /etc/threatlocker/threatlocker_restricted_users/
  • /etc/threatlocker/<user type or app>/
  • /etc/threatlocker/<user or app type>/<user type or app>.log
  • /etc/sudoers.d/threatlocker/'<user>_<app name>_elevation'
  • /var/cache/threatlocker/apps.db
  • /var/cache/threatlocker/downloads/
  • /var/cache/threatlocker/updates/
Was this article helpful?