Restrict service behavior
Define what service processes are expected to launch, touch, and reach so unusual behavior is no longer normal background noise.
Service containment for Windows environments
ServiceLocker constrains service behavior so compromised workloads have fewer paths to move laterally, escalate privilege, or quietly stage follow-on activity.
What it changes
Define what service processes are expected to launch, touch, and reach so unusual behavior is no longer normal background noise.
Constrain service-originated access patterns that attackers often abuse to pivot across servers and workstations.
Turn suspicious service behavior into alertable events before it becomes credential theft, persistence, or broad administrative control.