A Fortify 24x7 brand. Security engineering for the companies that build things.Client sign inTalk to an engineer
EagleTech Innovations
Sheet 04 / Execution control

Approved software runs. Nothing else gets a turn.

Detection is a wager that you will recognize the bad thing quickly enough. Allowlisting is a different wager entirely: only software you approved may execute, so the binary nobody recognizes never gets a chance to make its case. On the right machines it is the single highest value control we sell.

ThreatLockerDefault denyStaffed approval desk
1 line / default deny / approvals in minutes
Lines on this sheet1
PlatformThreatLocker
Rate basisEndpoint
ApprovalsWorked by our desk

How default deny actually feels

The first stretch is a learning phase. The agent watches what your team runs and builds the permitted set from your real toolchain rather than from a generic list somebody wrote at a vendor. Nothing is blocked while that happens. After it, anything new needs a decision.

Those decisions land with our desk, and in practice they return inside a few minutes. It remains a hop that was not there previously, and saying so plainly beats letting you discover it. Teams forever installing new tooling notice. Teams whose signing hardware runs a narrow and stable set of software barely do, and those are precisely the machines where this control repays its price many times over.

Anything unfamiliar needs a decision, and those usually return inside a few minutes.

Where to put it first

Start with the machines that would hurt most: whatever holds your signing keys, the build host, the workstation with the complete CAD library, and the finance machine that moves money. Most teams settle on tight policy there and something gentler across general workstations.

Ringfencing is the underrated half. Past the question of whether something may run, it pins down the child processes a permitted tool may start, the files it may open, and the addresses it may talk to. That is how a legitimate utility stops doubling as a convenient way to shift somebody else's data.

Lines on this sheet

Specifications and rates

Prices below are pulled straight out of billing. Anything you add sits in your basket while you carry on reading.

Fortify-ZeroTrustSpecification

Execution Control

ThreatLocker, deciding what may execute at all

Application allowlisting with automatic tracking of vendor updates and an approval desk staffed around the clock, so default deny does not become a queue your engineers wait in.

  • A learning phase builds the permitted set from the software you genuinely use.
  • Vendor updates are tracked so a routine release does not lock your team out.
  • Ringfencing bounds the processes, files, and addresses a permitted tool may touch.
  • Elevation requests reach an engineer who is already on shift.
ModelDeny by default. Approved software is the only software that runs
BaselineBuilt by watching your estate through the opening phase
UpdatesVendor application updates tracked, approvals kept current
RingfencingPer application limits on child processes, files, and network
ApprovalsWorked by Fortify 24x7 engineers around the clock
Best fitSigning hosts, build machines, finance and design workstations
Rate basisEndpoint, monthly
Fetchingper endpoint
billed monthly, up front
QTY
Honest scope

Where this sheet stops

Allowlisting decides what may execute. It has no opinion at all about what a person chooses to approve, and that boundary is worth being clear about before you buy.

  • It governs code, not consent. Somebody opening a permitted browser, landing on a persuasive page, and clicking approve never consulted an allowlist at any point. Inbox defense, filtering, and training are the controls covering that route.
  • Budget for the learning phase. It is real work in a real week, not a checkbox. A rollout that pretends otherwise produces a bad first month and a team that resents the tool.
  • Browser extensions are not unapproved binaries. Something added through the ordinary store route does not look like fresh code to an allowlist. Keeping extensions sane is a policy question, and we will help you draft one rather than sell you a line for it.
  • It does not read or classify your files. Knowing which documents are sensitive and where they ended up is the data protection sheet. This line decides what may run, not what is worth protecting.
  • Unmanaged machines are outside it. The policy applies to endpoints under management. A personal laptop that never enrolls is not covered and cannot be.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - EagleTech Innovations is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.