167: Threatlocker
Episode
49 min
Read time
2 min
Topics
Leadership, Software Development, Books & Authors
AI-Generated Summary
Key Takeaways
- ✓Ransomware Response Protocol: When hit with Conti ransomware encrypting 250 servers in 15 minutes, immediately shut down all systems, identify entry points, verify backups are clean, and establish red-amber-green device tracking before restoration to prevent reinfection.
- ✓Application Whitelisting Implementation: Deploy zero trust endpoint security in learning mode first to catalog legitimate business applications, then switch to deny-by-default where only approved software runs. Users request new apps through portal for IT approval, blocking ransomware automatically.
- ✓VPN Security Requirements: Multi-factor authentication on VPNs is critical—one hospital breach occurred when attackers bought domain admin credentials on dark web and accessed VPN without MFA, then pivoted to connected hospital systems lacking protection.
- ✓Defense in Depth Strategy: Security requires three layers—people training to avoid phishing, detection tools to identify threats, and controls like IP restrictions and application blocking. Only controls are fully manageable by IT since users make mistakes and detection misses new threats.
What It Covers
ThreatLocker CEO Danny Jenkins and security professionals share ransomware attack stories, explaining how application whitelisting and zero trust security models prevent malware by blocking all unauthorized software from running by default.
Key Questions Answered
- •Ransomware Response Protocol: When hit with Conti ransomware encrypting 250 servers in 15 minutes, immediately shut down all systems, identify entry points, verify backups are clean, and establish red-amber-green device tracking before restoration to prevent reinfection.
- •Application Whitelisting Implementation: Deploy zero trust endpoint security in learning mode first to catalog legitimate business applications, then switch to deny-by-default where only approved software runs. Users request new apps through portal for IT approval, blocking ransomware automatically.
- •VPN Security Requirements: Multi-factor authentication on VPNs is critical—one hospital breach occurred when attackers bought domain admin credentials on dark web and accessed VPN without MFA, then pivoted to connected hospital systems lacking protection.
- •Defense in Depth Strategy: Security requires three layers—people training to avoid phishing, detection tools to identify threats, and controls like IP restrictions and application blocking. Only controls are fully manageable by IT since users make mistakes and detection misses new threats.
Notable Moment
An IT director drove six hours home from vacation after ransomware hit, worked 27 straight days rebuilding infrastructure, and convinced leadership to take three weeks for proper rebuild instead of five-day quick restore, fundamentally changing their security approach.
No transcript yet — request it by email, free
We'll transcribe this episode on request and email you the full transcript and AI summary — usually within a day. No account needed.
One email, no spam. We’ll also show you what SignalCast does.
You just read a 3-minute summary of a 46-minute episode.
Get Darknet Diaries summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from Darknet Diaries
179: The Courthouse - Revisited
Sep 1 · 95 min
a16z Podcast
The Reality of AI-Powered Cyberattacks | Truffle Security & Socket
Aug 7
More from Darknet Diaries
LOW - Trailer
Aug 6 · 2 min
20VC (20 Minute VC)
20VC: 70% of Neolabs Will Die | There Will be a $100BN US Open-Source Model | Data is a Trillion $ Market | Governments Cannot Regulate Models: It is Too Late | The Cyber Attacks to Come Will be Insane with Anastasios Angelopoulos @ Arena
Aug 3
Books, tools, and gear mentioned in this episode
SignalCast may earn commission on purchases via these links.
company
- ThreatLockerRecommended
“ThreatLocker CEO Danny Jenkins and security professionals share ransomware attack stories, explaining how application whitelisting and zero trust security models prevent malware by blocking all unauthorized software from running by default.”
More from Darknet Diaries
We summarize every new episode. Want them in your inbox?
Similar Episodes
Related episodes from other podcasts
a16z Podcast
Aug 7
The Reality of AI-Powered Cyberattacks | Truffle Security & Socket
20VC (20 Minute VC)
Aug 3
20VC: 70% of Neolabs Will Die | There Will be a $100BN US Open-Source Model | Data is a Trillion $ Market | Governments Cannot Regulate Models: It is Too Late | The Cyber Attacks to Come Will be Insane with Anastasios Angelopoulos @ Arena
The Prof G Pod
Jul 13
What SpaceX's IPO Means for Tech Stocks, and Coping With Panic Attacks
The Prof G Pod
Jun 29
Is Wall Street Rigging the Game for SpaceX? Plus, What Investment Banking Really Teaches You
The Daily (NYT)
Jun 4
How Trump Was Persuaded to Regulate A.I.
Explore Related Topics
This podcast is featured in Best Tech Podcasts (2026) — ranked and reviewed with AI summaries.
Read this week's Software Engineering Podcast Insights — cross-podcast analysis updated weekly.
You're clearly into Darknet Diaries.
Every Monday, we deliver AI summaries of the latest episodes from Darknet Diaries and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime