Detection and monitoring EU-developed

HarfangLab EDR

Endpoint detection and response software that monitors workstation and server activity, raises investigation alerts, and supports blocking and response actions.

By HarfangLab · France

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
HarfangLab
Recorded country
France
Product model
Commercial
Deployment
Self-hosted / SaaS
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Created by HarfangLab, whose founders built its EDR; HarfangLab describes its engineering and teams as Europe-based and itself as a French company.

Reported capabilities

  • Endpoint agents detect and block threats on workstations and servers.
  • Analysts can tune alerting, access telemetry and investigate via console and API.
  • Offers both cloud and on-premises console deployment.

Scope and limits

Other HarfangLab ASM, EPP and ITDR capabilities are integrated offerings and are not split here. Vendor hosting claims are not independently audited by this index. Full product license terms were not publicly verified.

Inspect the research evidence 5 source observations
  1. identity / origin / capabilities

    HarfangLab says its founders created the EDR to detect and neutralize attacks on servers and workstations, and describes its platform development as Europe-based.

    Read source
  2. country / deployment

    The company calls itself French and lists cloud, private, SecNumCloud and own-infrastructure hosting choices.

    Read source
  3. capabilities / deployment

    Product page describes endpoint agents, console investigation, alert tuning, and equivalent cloud/on-premises deployment.

    Read source
  4. maintenance

    Official newsroom has September 2026 product and company updates.

    Read source
  5. license

    The reviewed official EDR offer describes a commercial product and demo path, but does not state the customer rights or full license terms for the EDR software.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

OpenCTI Integration

The optional HarfangLab Intel connector sends OpenCTI live-stream indicators to HarfangLab. Documented requirements include OpenCTI 6.4+, HarfangLab Threat Response 2.x+ and Python 3.11; changed patterns require deletion and recreation.

STIX Capability

The optional OpenCTI HarfangLab Intel connector converts selected STIX indicator patterns into IOC rules for IP addresses, domains, URLs and file hashes. It is not a general STIX object import.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection