Working With Your Existing Antivirus

2 min. readlast update: 07.29.2026

ThreatLocker plays nicely with existing antivirus software. We will neither conflict with nor interfere with your AV software. However, you may need to create exceptions to prevent your antivirus software from blocking ThreatLocker. We recommend you exclude the following files from scanning:

Please Note: ThreatLocker has now provided some of these files with wildcards for a more precise list of exclusions.

Windows Antivirus Software Exclusions

Executables and DLL Files:

C:\Program Files\ThreatLocker\*.exe

C:\Program Files\ThreatLocker\*.dll

C:\Program Files\HealthTLService\HealthService.exe

C:\Program Files\ThreatLocker\shared\libraries\*.*

C:\Program Files\ThreatLocker\shared\microsoft.netcore.app\8.0.8\*.*

C:\Program Files\ThreatLocker\shared\microsoft.windowsdesktop.app\8.0.8\*.*

Executables and DLL Files for 10.x and below:

C:\Program Files\ThreatLocker\costura\*.dll

C:\Program Files\ThreatLocker\x64\*.dll

C:\Program Files\ThreatLocker\x86\*.dll

Databases:

C:\Program Files\ThreatLocker\*.db

C:\Program Files\ThreatLocker\*.db-wal

C:\Program Files\ThreatLocker\*.db-shm

C:\Program Files\ThreatLocker\*.db-journal

Other data files:

C:\Program Files\ThreatLocker\*.json

C:\Program Files\ThreatLocker\*.txt

C:\Program Files\ThreatLocker\*.pk

C:\Program Files\ThreatLocker\*.dat

C:\Program Files\ThreatLocker\*.cat

C:\Program Files\ThreatLocker\*.inf

C:\Program Files\ThreatLocker\*.config

C:\Program Files\ThreatLocker\logs\*.txt

C:\Program Files\HealthTLService\*.cfg

Installation Script:

Ensure that "ThreatLockerStub.exe" is permitted.

Program Data File Path:

C:\ProgramData\ThreatLocker\*

Driver Files:

C:\Windows\System32\drivers\etc\ThreatLocker*.db

C:\Windows\System32\drivers\ThreatLockerDriver.sys


macOS Antivirus Software Exclusions 

These files should be excluded from third-party antiviruses and other software that monitor computer activity and may interfere with the ThreatLocker Mac Agent

Application bundles:

Bundles must be excluded as wildcards or treated like folders when setting up exclusions.

  • /Applications/ThreatLocker.app
  • /Library/SystemExtensions/{RandomUUID}/com.threatlocker.app.agent.systemextension
  • /Library/SystemExtensions/{RandomUUID}/com.threatlocker.app.secure-network.systemextension - Mac Agent version > 11.0
  • /Library/Security/SecurityAgentPlugins/ThreatLockerAuthPlugin.bundle

Binaries:

  • /usr/local/lib/pam/ThreatLockerAuthModule.dylib

Folders and files:

  • /Library/Application Support/ThreatLocker/*
  • /Library/LaunchAgents/com.threatlocker.app.UIAgent.plist
  • /Library/LaunchAgents/com.threatlocker.app.plist
  • /Library/LaunchDaemons/com.threatlocker.app.health-service.plist
  • /Library/Preferences/com.threatlocker.app.plist - Mac Agent version < 5.0
  • /private/var/root/Library/Preferences/com.threatlocker.app.agent.plist - Mac Agent version < 5.0

Web Control Browser Extensions (only when installed):

  • /Applications/ThreatLocker Web Control.app/*
  • /Users/{Username}/Library/Application Support/Google/Chrome/Default/Extensions/hmblejjjbiighoepgehkcallcgiadpmc/*
  • /Users/{Username}/Library/Application Support/Firefox/Profiles/*/extensions/{6bdd07ae-1b18-4478-8e83-c1d2f0afb94a}.xpi

For browser extensions try to locate actual folder names because wildcards may be dangerous for exclusions if folders are not protected.


Linux Antivirus Software Exclusions

/etc/threatlocker/*
/etc/threatlocker/config.cfg
/etc/threatlocker/systemd/*.service
/etc/threatlocker/systemd/threatlocker-cleanup
/etc/threatlocker/certs/*
/etc/threatlocker/certs/hosts/*

/etc/sudoers.d/threatlocker_sudoers_general
/etc/sudoers.d/threatlocker/

/etc/systemd/system/threatlocker-agent.service
/etc/systemd/system/threatlocker-cleanup.service
/etc/systemd/system/threatlocker-agent.service.d/
/etc/systemd/system/multi-user.target.wants/threatlocker-agent.service

/etc/tmpfiles.d/threatlocker.conf

/etc/default/grub.d/99-threatlocker-lsm-bpf.cfg
/etc/default/grub.threatlocker.backup

/etc/kernel/postinst.d/threatlocker_modules

/etc/modprobe.d/99-threatlocker.conf

/var/lock/threatlocker.lock
/var/lock/threatlocker-exec-monitor.lock
/var/lock/threatlocker-broker-agent.lock

/var/cache/threatlocker/*.db
/var/cache/threatlocker/*.json
/var/cache/threatlocker/segfault_marker
/var/cache/threatlocker/downloads/
/var/cache/threatlocker/updates/

/var/log/threatlocker/*.log
/var/log/threatlocker/update.log.sent

/var/log/threatlocker-ua/*

/var/run/threatlocker/*

/bin/threatlockerctl

/usr/local/bin/threatlocker-agent
/usr/local/bin/threatlocker-exec-monitor
/usr/local/bin/threatlocker-broker-agent
/usr/local/bin/threatlockerctl
/usr/local/bin/threatlocker_modules
/usr/local/bin/threatlocker_modules_path

/lib/threatlocker/*
/lib/threatlocker/updates/

# /lib/threatlocker/ stores copies of all shared libs that agent requires

/lib/modules/threatlocker_modules/*

# /lib/modules/threatlocker_modules/ stores quite a lot of subfolders with modules for all supported kernels

/lib/threatlocker-ebpf/*.o

/tmp/.threatlocker.computerID
/tmp/threatlocker.sock

/dev/tl_app_control
/dev/tl_anti_tamper
/dev/tl_app_monitor
/dev/tl_network_control
/dev/tl_exec_monitor
/dev/shm/threatlocker_exec_monitor_memory_handler
/dev/shm/threatlocker_broker_agent_memory_handler

/sys/kernel/tl_sysfs/tl_antitamper
/sys/kernel/tl_app_control/control_status

Was this article helpful?