Working with Your Existing Antivirus

2 min. readlast update: 01.21.2026

ThreatLocker plays nicely with existing antivirus software. We will neither conflict nor interfere with your AV software from running. However, you may need to create exceptions to prevent your antivirus software from blocking ThreatLocker. We recommend you exclude the following files from scanning:

Windows Antivirus software exclusions

C:\Program Files\HealthTLService\HealthService.exe

C:\Program Files\ThreatLocker\ThreatLockerAgent.x64.dll 

C:\Program Files\ThreatLocker\ThreatLockerAgent.x86.dll 

C:\Program Files\ThreatLocker\hostfxr.dll

C:\Program Files\ThreatLocker\System.ServiceProcess.ServiceController.dll

C:\Program Files\ThreatLocker\ThreatLockerAmsiProvider.x64.dll

C:\Program Files\ThreatLocker\ThreatLockerAmsiProvider.ARM64.dll

C:\Program Files\ThreatLocker\ThreatLockerAmsiProvider.x86.dll

C:\Program Files\ThreatLocker\ThreatLockerBits.dll

C:\Program Files\ThreatLocker\ThreatLockerConsent.exe

C:\Program Files\ThreatLocker\ThreatLockerDriver.cat

C:\Program Files\ThreatLocker\ThreatLockerDriver.inf

C:\Program Files\ThreatLocker\ThreatLockerDriver.sys

C:\Windows\System32\drivers\ThreatLockerDriver.sys

C:\Program Files\ThreatLocker\ThreatLockerElevationUI.dll

C:\Program Files\ThreatLocker\ThreatLockerElevationUI.dll.config

C:\Program Files\ThreatLocker\ThreatLockerElevationUI.exe

C:\Program Files\ThreatLocker\ThreatLockerElevationUI.runtime.config

C:\Program Files\ThreatLocker\threatlockerminhook.x64.dll

C:\Program Files\ThreatLocker\threatlockerminhook.x86.dll

C:\Program Files\ThreatLocker\threatlockerpowershellhook.dll 

C:\Program Files\ThreatLocker\ThreatLockerRemediator.exe

C:\Program Files\ThreatLocker\ThreatLockerService.dll

C:\Program Files\ThreatLocker\ThreatLockerService.dll.config

C:\Program Files\ThreatLocker\ThreatLockerService.exe

C:\Program Files\ThreatLocker\ThreatLockerService.exe.config

C:\Program Files\ThreatLocker\ThreartLockerService.runtimeconfig.json

C:\Program Files\ThreatLocker\ThreatLockerTray.dll

C:\Program Files\ThreatLocker\ThreatLockerTray.dll.config

C:\Program Files\ThreatLocker\ThreatLockerTray.exe

C:\Program Files\ThreatLocker\ThreatlockerTray.exe.config

C:\Program Files\ThreatLocker\ThreatLockerTray.runtimeconfig.json

Databases:

C:\Program Files\ThreatLocker\6.0AMD64.db

C:\Program Files\ThreatLocker\6.0AMD64.db-journal

C:\Program Files\ThreatLocker\6.0AMD64.db-shm

C:\Program Files\ThreatLocker\6.0AMD64.db-wal

C:\Program Files\ThreatLocker\6.0x86.db

C:\Program Files\ThreatLocker\6.0x86.db-journal

C:\Program Files\ThreatLocker\6.0x86.db-shm

C:\Program Files\ThreatLocker\6.0x86.db-wal

C:\Program Files\ThreatLocker\6.1AMD64.db

C:\Program Files\ThreatLocker\6.1AMD64.db-journal

C:\Program Files\ThreatLocker\6.1AMD64.db-shm

C:\Program Files\ThreatLocker\6.1AMD64.db-wal

C:\Program Files\ThreatLocker\6.1x86.db

C:\Program Files\ThreatLocker\6.1x86.db-journal

C:\Program Files\ThreatLocker\6.1x86.db-shm

C:\Program Files\ThreatLocker\6.1x86.db-wal

C:\Program Files\ThreatLocker\6.2AMD64.db

C:\Program Files\ThreatLocker\6.2AMD64.db-journal

C:\Program Files\ThreatLocker\6.2AMD64.db-shm

C:\Program Files\ThreatLocker\6.2AMD64.db-wal

C:\Program Files\ThreatLocker\6.2x86.db

C:\Program Files\ThreatLocker\6.2x86.db-journal

C:\Program Files\ThreatLocker\6.2x86.shm

C:\Program Files\ThreatLocker\6.2x86.db-wal

C:\Program Files\ThreatLocker\6.3AMD64.db

C:\Program Files\ThreatLocker\6.3AMD64.db-journal

C:\Program Files\ThreatLocker\6.3AMD64.db-shm

C:\Program Files\ThreatLocker\6.3AMD64.db-wal

C:\Program Files\ThreatLocker\6.3x86.db

C:\Program Files\ThreatLocker\6.3x86.db-journal

C:\Program Files\ThreatLocker\6.3x86.db-shm

C:\Program Files\ThreatLocker\6.3x86.db-wal

C:\Program Files\ThreatLocker\10.0AMD64.db

C:\Program Files\ThreatLocker\10.0AMD64.db-journal

C:\Program Files\ThreatLocker\10.0AMD64.db-shm

C:\Program Files\ThreatLocker\10.0AMD64.db-wal

C:\Program Files\ThreatLocker\10.0ARM64.db

C:\Program Files\ThreatLocker\10.0ARM64.db-journal

C:\Program Files\ThreatLocker\10.0ARM64.db-shm

C:\Program Files\ThreatLocker\10.0ARM64.db-wal

C:\Program Files\ThreatLocker\10.0x86.db

C:\Program Files\ThreatLocker\10.0x86.db-journal

C:\Program Files\ThreatLocker\10.0x86.db-shm

C:\Program Files\ThreatLocker\10.0x86.db-wal

C:\Program Files\ThreatLocker\apps.db

C:\Program Files\ThreatLocker\apps.db-journal 

C:\Program Files\ThreatLocker\Application.db

C:\Program Files\ThreatLocker\Application.db-journal

C:\Program Files\ThreatLocker\Application.db-shm

C:\Program Files\ThreatLocker\Application.db-wal

C:\Program Files\ThreatLocker\AzureAD.db

C:\Program Files\ThreatLocker\AzureAD.db-journal 

C:\Program Files\ThreatLocker\cert.db

C:\Program Files\ThreatLocker\cert.db-journal 

C:\Program Files\ThreatLocker\ConfigMgr.db 

C:\Program Files\ThreatLocker\ConfigMgr.db-journal 

C:\Program Files\ThreatLocker\DeniedActionQueue.db 

C:\Program Files\ThreatLocker\DeniedActionQueue.db-journal

C:\Program Files\ThreatLocker\Detect.db 

C:\Program Files\ThreatLocker\Detect.db-journal 

C:\Program Files\ThreatLocker\dns.db

C:\Program Files\ThreatLocker\dns.db-journal 

C:\Program Files\ThreatLocker\FileHistory.db

C:\Program Files\ThreatLocker\FileHistory.db-journal

C:\Program Files\ThreatLocker\FileHistory.db-shm

C:\Program Files\ThreatLocker\FileHistory.db-wal

C:\Program Files\ThreatLocker\fileinfov4.db

C:\Program Files\ThreatLocker\fileinfov4.db-journal

C:\Program Files\ThreatLocker\FileInformation.db

C:\Program Files\ThreatLocker\FileInformation.db-journal

C:\Program Files\ThreatLocker\FileInformation.db-shm

C:\Program Files\ThreatLocker\FileInformation.db-wal

C:\Program Files\ThreatLocker\FileInstall.db

C:\Program Files\ThreatLocker\FileInstall.db-journal 

C:\Program Files\ThreatLocker\nac.db

C:\Program Files\ThreatLocker\nac.db-journal

C:\Program Files\ThreatLocker\Patch.db

C:\Program Files\ThreatLocker\Patch.db-journal

C:\Program Files\ThreatLocker\Patch.db-shm

C:\Program Files\ThreatLocker\Patch.db-wal 

C:\Program Files\ThreatLocker\Tag.db

C:\Program Files\ThreatLocker\Tag.db-journal

C:\Program Files\ThreatLocker\Tag.db-shm

C:\Program Files\ThreatLocker\Tag.db-wal

C:\Windows\System32\drivers\etc\ThreatLockerCoreFileRules.db

C:\Windows\System32\drivers\etc\ThreatLockerCoreFileRules.db-journal

C:\Windows\System32\drivers\etc\ThreatLockerPersistentRules.db

C:\Windows\System32\drivers\etc\ThreatLockerPersistentRules.db-journal

Other data files:

C:\Program Files\HealthTLService\SkipInitialDelay.exe

C:\Program Files\ThreatLocker\Modules\AppUpgrade.psm1

C:\Program Files\ThreatLocker\256Mappings.json

C:\Program Files\threatlocker\authorizationhosts.txt

C:\Program Files\ThreatLocker\actionlogqueue.json

C:\Program Files\ThreatLocker\apphash.json

C:\Program Files\ThreatLocker\appfiles.json

C:\Program Files\ThreatLocker\applications.json

C:\Program Files\ThreatLocker\configurationmanagerpolicies.txt 

C:\Program Files\ThreatLocker\certcache.json

C:\Program Files\ThreatLocker\configurations.txt

C:\Program Files\ThreatLocker\detectpolicies.txt

C:\Program Files\ThreatLocker\dnscache.json

C:\Program Files\threatlocker\fileinformationcache.json

C:\Program Files\ThreatLocker\GroupMembers.json

C:\Program Files\ThreatLocker\harddrives.json

C:\Program Files\ThreatLocker\icon.ico

C:\Program Files\ThreatLocker\localadminusers.txt

C:\Program Files\threatlocker\log.txt

C:\Program Files\ThreatLocker\logo.jpg

C:\Program Files\ThreatLocker\monitoredpaths.txt

C:\Program Files\ThreatLocker\monitoredpoliciesdeny.json

C:\Program Files\ThreatLocker\monitoredRegistry.json

C:\Program Files\ThreatLocker\networkaccesspolicies.txt

C:\Program Files\ThreatLocker\offlinepermissionrequests.json

C:\Program Files\ThreatLocker\opspolicies.txt 

C:\Program Files\ThreatLocker\pk.dat

C:\Program Files\ThreatLocker\policies.txt

C:\Program Files\ThreatLocker\public_suffix_list.dat

C:\Program Files\ThreatLocker\ringfencehistory.json

C:\Program Files\ThreatLocker\ringfenceitems.json

C:\Program Files\ThreatLocker\ringfencedPaths.json

C:\Program Files\ThreatLocker\storagepolicies.txt

C:\Program Files\threatlocker\tags.json

Directories:

C:\Program Files\HealthTLService\Logs\*.txt

C:\Program Files\ThreatLocker\logs\*.txt

C:\Program Files\ThreatLocker\shared\*

C:\ProgramData\threatlocker\*

Installation Script:

C:\temp\ThreatLockerStub.exe

MAC Antivirus software exclusions

/Applications/ThreatLocker.app

/Applications/ThreatLocker.app/Contents/Resources/ThreatLocker UIAgent.app

/Applications/ThreatLocker.app/Contents/Resources/ThreatLocker Baseline Scanner.app

/Applications/ThreatLocker.app/Contents/Resources/ThreatLockerLogCollector

/Applications/ThreatLocker.app/Contents/Resources/ThreatLocker Health Service

/Applications/ThreatLocker.app/Contents/Resources/ThreatLockerUninstaller

/Library/LaunchAgents/com.threatlocker.app.UIAgent.plist

/Library/Application Support/ThreatLocker/*

/Library/SystemExtensions/{randomGuid}/com.threatlocker.app.agent.systemextension

/Library/Security/SecurityAgentPlugins/ThreatLockerAuthPlugin.bundle

/usr/local/lib/pam/ThreatLockerAuthModule.dylib

/Library/SystemExtensions/{randomGuid}/com.threatlocker.app.agent.systemextension/Contents/MacOS/com.threatlocker.app.agent

/private/var/root/Library/Preferences/com.threatlocker.app.agent.plist

 

For the GUID System Extension installation, this is created automatically during installation and will need to be entered with the correct GUID in place of the {randomGuid} text, including the curly braces.

Linux Antivirus Software Exclusions

/etc/threatlocker/config.cfg

/etc/threatlocker/groupkey

/etc/threatlocker/ignoredRuleList

/etc/threatlocker/policies

/etc/threatlocker/policies/threatlocker/

/etc/threatlocker/policies/threatlocker_block/

/etc/threatlocker/policies/threatlocker_domain/

/etc/threatlocker/policies/threatlocker_locked_exec/

Only Ubuntu - /etc/threatlocker/policies/threatlocker_ubuntu_default/

/var/log/threatlocker.log, /var/log/threatlocker.1.log, /var/log/threatlocker.2.log, /var/log/threatlocker.3.log, /var/log/threatlocker.4.log

/etc/sudoers.d/threatlocker_sudoers_general

/etc/sudoers.d/threatlocker/

/etc/systemd/system/threatlocker-agent.service

/etc/systemd/system/threatlocker-policy@.service

/usr/local/bin/threatlocker-agent

/usr/local/bin/threatlockerctl

/usr/local/bin/threatlockerstarter

/bin/threatlockerctl

/usr/share/selinux/devel/include/threatlocker/

/etc/threatlocker/computerID

/etc/threatlocker/controlledApps.backup

/etc/threatlocker/<app name>_<type>_declaration/

/etc/threatlocker/<app name>_<type>/

/etc/threatlocker/threatlocker_controlled_applications/

/etc/threatlocker/threatlocker_restricted_users/

/etc/threatlocker/<user type or app>/

/etc/threatlocker/<user or app type>/<user type or app>.log

/etc/sudoers.d/threatlocker/'<user>_<app name>_elevation'

/var/cache/threatlocker/apps.db

/var/cache/threatlocker/downloads/

/var/cache/threatlocker/updates/

Was this article helpful?