Huntress vs Todyl: are you buying a layer or a whole stack?
Todyl sells a six-module platform including the network layer, channel-only, with no published pricing. Huntress sells a layer and publishes its rates.
Read articleEndpoint & Detection
ThreatLocker blocks what is not on the list. Huntress watches what gets through. Most businesses comparing them are asking the wrong question.
This pairing shows up on shortlists constantly, and it is the least like-for-like comparison in the small-business security market. They are not two versions of the same product. They are two different theories about how you stop a breach.
ThreatLocker's theory: if only approved software can execute, most attacks never start.
Huntress's theory: something will get through anyway, so somebody needs to be watching.
Both are correct, which is why the interesting question is not which one wins.
Disclosure: Obsidian Ridge is a Huntress MSSP partner and delivers Huntress-powered managed detection and response. Read the recommendation below with that in mind. We deploy alongside allowlisting rather than against it, and the case for running both is made honestly below.
ThreatLocker's own framing of allowlisting could not be blunter:
"Only approved software runs, everything else, including ransomware, is blocked by default." … "If it's on the list, it runs. If it's not, it doesn't."
— threatlocker.com, retrieved 28 August 2026
Around that core they sell Ringfencing ("Decide exactly what every application is allowed to do"), privileged access management for application-level elevation, external storage device control, a zero trust endpoint firewall with default-deny network policy, and a policy-driven EDR that "automatically reacts and isolates threats in real time."
That last one matters for accuracy: ThreatLocker's EDR is policy-driven automation, not analyst judgement. Which brings us to the correction most comparison articles get wrong.
You will read a lot of comparisons claiming ThreatLocker has no managed detection and response. That was true once and is not true now.
There are two distinct Cyber Hero services and they are easy to conflate:
Cyber Hero Approvals is the support service most people mean. Their team is "available 24 hours a day, 365 days a year, including holidays," evaluating user application requests "according to established organizational policies" with approvals averaging "15 minutes or less." That is an approvals desk, not threat hunting.
Cyber Hero MDR, launched April 2024, is a genuine managed detection capability — a team that "verifies alerts, isolates devices, and stops attacks before they spread" and will "validate every alert, filter the false positives, and escalate only real threats." (threatlocker.com.)
So the clean "prevention versus MDR" split does not hold. The defensible statement is narrower: ThreatLocker's core model is prevention, and MDR is a separately listed capability whose commercial packaging is not published.
ThreatLocker's pricing page says: "A price quote built around your environment. No two organizations are identical." No figures, tiers or rates. Their terms do publish one useful number — renewal increases "will not exceed eight percent (8%) annually" — which is more transparency than most vendors offer on renewal risk.
Huntress publishes Managed EDR at $8.99 per endpoint per month. That is a genuine difference in how you can plan, and we are not neutral about it.
Treat any ThreatLocker per-endpoint figure from a review site as unverified.
This is the single most important thing to understand before choosing, and to ThreatLocker's credit they publish it themselves.
Deployment begins in Learning Mode: "Upon deployment, ThreatLocker enters a Learning Mode and baselines your machine(s)… The Learning Mode timeframe defaults to a week." After that, "your complimentary Solutions Engineer will help you adjust your allowlist."
Then it continues, indefinitely. Their own guidance:
"Allowlisting is not a set-it-and-forget-it solution."
Every time an employee installs a legitimate new tool, updates something in an unexpected way, or a vendor ships a signed binary you have never seen, somebody approves it. ThreatLocker offers to handle those requests for you, which is exactly why Cyber Hero Approvals exists as a product.
That is not a criticism. It is the cost of the model, and the model genuinely works. But a five-person business that has never run a change process should know what they are signing up for.
With allowlisting. An employee downloads something. It does not run. They see a popup and request approval. Somebody — your admin or ThreatLocker's team — decides. The attack that would have started with that download did not start. You also have a slightly annoyed employee, and you have a workflow you did not have before.
With managed detection and response. The same employee's credentials get phished a month later on a device where nothing new was ever installed. No binary executed. Allowlisting has nothing to block. An analyst sees the anomalous session and kills it.
Those are different Mondays. That is the whole argument for running both.
Most businesses asking "Huntress or ThreatLocker" have a budget for one and are hoping one covers the other. It does not, in either direction.
If you must pick one, pick based on what your last near-miss looked like. If it was someone downloading something they should not have, allowlisting addresses it directly. If it was a phishing email, a fake login page, or an invoice that nearly got paid, no allowlist would have helped and you want the watching.
If you can afford both, run both — reduce what can execute, and cover what happens when nothing needed to.
Our managed detection and response deploys alongside allowlisting without conflict, and Ridge Watch pricing is public. If you want help deciding which half your actual risk sits in, book a briefing.
One caveat if insurance is the driver. Allowlisting is a strong control, but carrier questionnaires ask specifically about detection and response, and an application-control answer does not always satisfy that question. Check the wording before you buy — that is the cyber insurance readiness step.
Last updated
September 1, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
ThreatLocker does not publish pricing. Their pricing page offers a custom quote and states that no two organizations are identical. Any per-endpoint figure on an aggregator or review site is unverified until you have a quote in writing. Their terms note that renewal price increases will not exceed eight percent annually.
ThreatLocker's core model is deny-by-default application allowlisting: approved software runs and everything else is blocked, including ransomware. Around that it sells Ringfencing to constrain what trusted applications may do, privileged access management, external storage device control, a zero trust endpoint firewall, and a policy-driven EDR.
Its core model is prevention rather than detection and response, but ThreatLocker does also market a distinct Cyber Hero MDR capability with 24/7 human alert verification and device isolation. That is separate from Cyber Hero Approvals, which is the application-approval support service. Commercial packaging of the two is not published.
More than most buyers expect, and ThreatLocker says so. Deployment starts in a Learning Mode that defaults to a week while the agent baselines each machine, after which an engineer helps tune the allowlist. Ongoing, their own guidance states that allowlisting is not a set-it-and-forget-it solution and that help desk staff need training to handle user approval requests.
Many mature environments do, because they address different halves of the problem. Allowlisting reduces what can execute; managed detection and response covers what happens when something legitimate is abused, credentials are stolen, or the attack never involves a new binary at all. Neither one makes the other redundant.
Related reading
Todyl sells a six-module platform including the network layer, channel-only, with no published pricing. Huntress sells a layer and publishes its rates.
Read articleBoth run a 24/7 SOC for small businesses. Huntress publishes its prices and sells direct. Blackpoint publishes none and sells mainly through MSPs.
Read articleIf you pay for Microsoft 365 Business Premium you already have EDR. The question is who reads the alerts — and Microsoft will not sell you that service.
Read article