Lavawall® is a multi-tenant RMM and remote support platform for MSPs and IT teams, with patching, security monitoring, Microsoft 365 and Google Workspace breach detection, and compliance built into the same agent and console. ThreatLocker is a well-known kernel-driver-based application control and ringfencing platform. Lavawall covers the same risk with administrator elevation (Windows) with certificate-based rules and ringfencing, plus execution prevention for high-risk tools, and no kernel driver. That removes BSOD risk and cloud-callback dependencies, and it keeps working on Remote Desktop Session Hosts where kernel-level agents typically struggle.
Where Lavawall® wins for MSPs
No kernel driver, so there is no BSOD risk, no driver-signing dance, and no compatibility breakage when Microsoft ships a kernel update.
Works without callback to the cloud, which matters for clients in remote, regulated, or air-gapped environments.
Elevation rules can follow the publisher’s signing certificate rather than a file hash, so vendor updates don’t silently break your rules every Patch Tuesday.
Works on Remote Desktop Session Hosts where kernel-level agents historically fall over.
Runs standalone on any modern Windows fleet, with no learning-mode aggregator or ringfencing model required to get value.
Bundled into the same console as patching, GRC, M365 breach detection, helpdesk, remote support, and replacement prioritization. One vendor, one bill, one platform.
Built by ThreeShield, an MSP and audit firm with CISSP and CISA certifications, and designed first for our own clients.
Cross-platform endpoint coverage on Windows, macOS, and Linux from one agent and one console.
Where ThreatLocker wins
Mature ringfencing model that limits what allowed applications can do (network, registry, files, child processes) at a granular level.
Large existing MSP customer base with established workflows and 24/7 Cyber Hero support.
Strong learning-mode tooling for getting up and running on a noisy environment.
Established storage and elevation modules with detailed control surfaces.
Feature comparison
| Feature | Lavawall® | ThreatLocker |
|---|---|---|
| Kernel driver required | No | Yes |
| BSOD / kernel-bug-class risk | No | Possible, via kernel-level code paths |
| Operates without cloud callback | Yes | Check ThreatLocker’s documentation |
| Remote Desktop Session Host (RDS) support | Yes, designed to work | Check ThreatLocker’s documentation |
| Pre-approval model | By publisher certificate, not file hash; survives vendor updates | Check ThreatLocker’s documentation |
| Works alongside endpoint AV / EDR (Defender, Huntress, Sophos) | Yes, integrated and correlated | Yes |
| Bundled GRC framework mapping | 70+ frameworks including CMMC 2.0 | Add-on |
| Bundled patching across Windows / macOS / Linux | 7,400+ applications | Check ThreatLocker’s documentation |
| Bundled M365 / Azure / Google Workspace breach detection | Yes | Check ThreatLocker’s documentation |
| Bundled helpdesk and remote support | Yes, same console | Check ThreatLocker’s documentation |
| Cross-platform (Windows, macOS, Linux) from one agent | Yes | Primarily Windows + macOS, with Linux server support |
| Pricing model | Bundled into Lavawall® tiers, or a single module with no minimum | Per-endpoint subscription, typically annual |
Who should pick which?
Pick Lavawall® if…
Your team has been burned by kernel-level agents in the past: bluescreens, signing-cert renewals, RDS host crashes, or driver-update outages.
You support clients in regulated or remote environments where reliable cloud callback cannot be assumed.
You want application control bundled with patching, GRC, breach detection, helpdesk, and remote support, rather than as a standalone seven-figure category bet.
You have a heterogeneous fleet (Windows, macOS, Linux) and want one agent and one console covering all three.
You are an MSP focused on cyber-insurance readiness and audit-evidence collection rather than on building deep ringfence rule sets per client.
Pick ThreatLocker if…
You are committed to a kernel-level zero-trust ringfencing model and have the engineering bandwidth to maintain rule sets at scale.
You need ThreatLocker-specific modules (Storage Control, Elevation Control, Network Access Control) configured exactly the way ThreatLocker delivers them.
Your clients explicitly request ThreatLocker by name in their cyber-insurance questionnaires.
Frequently asked
- Why is "application control without a kernel driver" significant?
- Because it removes an entire class of failure mode: BSODs, driver-signing breakage on Microsoft updates, and RDS-host instability. Kernel-level agents have caused production outages across multiple endpoint security vendors over the past several years. Dropping the kernel driver also reduces the privileged-code attack surface. Lavawall’s approach trades some of the surface depth of ringfencing for far higher reliability.
- Does Lavawall® support pre-approving installers?
- Yes. Lavawall® elevation rules can follow the publisher’s signing certificate rather than a file hash, so vendor updates don’t silently break your rules on Patch Tuesday.
- Can I run ThreatLocker and Lavawall® together during evaluation?
- Yes. They monitor different surfaces and can coexist while you compare alert quality, policy maintenance burden, and end-user impact before deciding which to retire.
- What about elevation control?
- Lavawall® includes admin-elevation control for the cases where standard users must run a one-off action with admin rights (comparable to the AutoElevate use case) without an additional kernel-level driver.