ThreatLocker portal users are administrative accounts, not a directory of people on endpoints. Wirespeed treats usernames from endpoints and audit events as observables. Connect your identity provider separately for directory context.
Create a ThreatLocker API user
- In the ThreatLocker Portal, navigate to Users > API Users.
- Create an API user for Wirespeed with access to the target organization.
- Grant the API user permission to view computers and the Unified Audit.
- Generate and copy the API token. ThreatLocker displays it only once.
Authorization header. Do not add a Bearer prefix to the PortalAPI token.
Find your instance and organization
Your PortalAPI hostname has the formportalapi.INSTANCE.threatlocker.com. Enter only the INSTANCE value in Wirespeed, such as g, ca1, or eu1.
For every integration, open Manage > Organizations, select the target organization, and copy its Organization ID GUID. Use the primary organization’s GUID for a direct customer and the target child’s GUID for an MSP-managed customer. An MSP parent API token can be reused across child integrations; Wirespeed scopes every request to the Organization ID you enter.
Connect ThreatLocker in Wirespeed
- In Wirespeed, navigate to Integrations > Add Integration > ThreatLocker.
- Enter the PortalAPI instance.
- Enter the target Organization ID.
- Paste the raw ThreatLocker API token into API Token.
- Complete the integration.
Data ingested
Wirespeed synchronizes:- ThreatLocker computers: ID, hostname, operating system, last check-in, and logged-in user when returned by the PortalAPI
- Unified Audit true denies: actions ThreatLocker actually blocked, excluding monitor-only (simulated) denies. Each deny becomes a blocked detection. The endpoint, user, process, file path and SHA-256, matched policy, and source/destination IPs are included when the PortalAPI returns them for that deny.
Current limitations
- Endpoint isolation and lockdown are not available through this integration.
- ThreatLocker does not assign a severity to Unified Audit denies, so every deny is ingested at medium severity.
- Only true denies are ingested. Permitted actions and ThreatLocker Detect alerts are not.
- Detection categorization remains non-escalating until ThreatLocker WDC rules are defined.

