API key: checking…Session: checking…SettingsDRY RUN
Sign in
ThreatLocker Policy Push
or
API Key (token auth)
A persistent API User token pulls audit data without a browser session —
no more session-expiry. This is the preferred auth once confirmed working.
Portal → Administrators → API Users → create/copy a token.
Paste the raw key below (no Bearer prefix).
Save — pulls will prefer token auth; session stays as fallback.
Update Session Auth
Browser session tokens expire at each logout. Paste fresh values from DevTools below.
Log into portal.threatlocker.com in your browser.
Press F12 → Network tab.
Navigate to Unified Audit and let some data load.
Find a request to ActionLogGetByParametersV2 → click Headers.
Copy the Authorization and Cookie values below.
0groups to push0rules selected0 of 0reviewed0auto-skipped
Pull audit from API
Pulls deny records directly from ThreatLocker using the same filters
you'd set in the portal's Unified Audit. Writes a CSV in the project
folder and auto-loads it.