Elevation ยท ringfencing ยท execution prevention
Take away local admin without breaking the day.
On Windows, Lavawall® makes per-application the unit of permission, not per-user, so you can remove local admin while the QuickBooks update and the AutoCAD installer still work and everything else asks first. Most ransomware doesn’t need a zero-day. It needs a user with administrator rights and a moment of distraction.
Start my free trial, no credit cardSee what’s included
Windows · signed rule set · offline approval codes · no kernel driver
Three controls that only work together
Administrator elevation
Replace UAC’s all-or-nothing prompt with a real decision. This is lightweight PAM: let a standard user perform a one-off admin action without ever giving them permanent local-admin rights. Approve a specific program by certificate, thumbprint, hash, or path, not the whole user. Certificate rules are the ones to prefer: they only match a validly signed program, and they survive routine certificate renewals. For installers, approve one specific MSI package rather than every MSI.
Execution prevention
Some tools shouldn’t run at all, whoever starts them. Execution prevention blocks named high-risk tools, the ones ransomware uses to delete shadow copies, clear logs, move between computers, and copy data out. It is a block list you choose from, not an allowlist, and it runs in audit mode first so you see what would have been blocked before anything is enforced.
Ringfencing
Stop an approved process from spawning child processes, reaching the network, or touching files it has no business touching, so a trusted app can’t be turned into a delivery vehicle.
Monitor first, then enforce
Start in audit mode, which records what would have happened without blocking anything, write rules for the obvious things, then switch to Enforce. Execution prevention won’t enforce until audit mode has run and reported back. No flag-day disaster. A user hits an elevation prompt while you’re on a job site? Approve it from the notification on your phone, or with a one-time code when the computer is offline.
No kernel driver. The agent works with Windows’ own security controls, so there is no Lavawall driver in the boot path and no driver-signing dance. It installs automatically through the Lavawall agent, with no separate enrolment code, and the rule set each computer follows is signed and verified before it is applied. Every decision (automatic, console-approved, auto-denied, or technician-approved) lands in the tamper-evident activity log.


Built to replace the kernel-driver approach
Lavawall® controls elevation and execution rather than intercepting every network, registry, and file syscall. Its administrator elevation and execution prevention need no kernel driver, and the signed rule set is enforced on the computer itself. If you are weighing it against ThreatLocker, AutoElevate, or Airlock Digital, check each vendor’s documentation for how it enforces policy.
Want help designing the rules?
ThreeShield, the CISSP/CISA team that builds Lavawall®, will baseline your environment, seed the rules that matter, and stage the move to Enforce so nothing breaks.
Common questions
- Do you install a kernel driver?
- No. Lavawall installs no kernel driver. The agent works with Windows’ own security controls instead of re-implementing them in kernel space. That means fewer crashes, faster boot and install, and a clean uninstall.
- What happens when the endpoint is offline?
- The computer keeps applying the signed rule set it already has, and decisions are logged and reach your console when the connection comes back. When a request needs a person and the computer is offline, a technician can approve it with a one-time code.
- How is this different from ThreatLocker or AutoElevate?
- It is administrator elevation built into the Lavawall agent, with no kernel driver and no separate enrolment code. You remove local admin rights, approve specific programs by certificate, thumbprint, hash, or path, ringfence what they can do, and add execution prevention for high-risk tools, rolled out in audit mode first. For how ThreatLocker and AutoElevate work, check their documentation.