An independent tool index for incident response teams
Detection and monitoring / EU-developed
HarfangLab EDR
Endpoint detection and response software that monitors workstation and server activity, raises investigation alerts, and supports blocking and response actions.
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
HarfangLab
Recorded country
France
Product model
Commercial
Deployment
Self-hosted / SaaS
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed
What the sources establish
Origin note
Created by HarfangLab, whose founders built its EDR; HarfangLab describes its engineering and teams as Europe-based and itself as a French company.
Reported capabilities
Endpoint agents detect and block threats on workstations and servers.
Analysts can tune alerting, access telemetry and investigate via console and API.
Offers both cloud and on-premises console deployment.
Scope and limits
Other HarfangLab ASM, EPP and ITDR capabilities are integrated offerings and are not split here. Vendor hosting claims are not independently audited by this index. Full product license terms were not publicly verified.
Inspect the research evidence 5 source observations
identity / origin / capabilities
HarfangLab says its founders created the EDR to detect and neutralize attacks on servers and workstations, and describes its platform development as Europe-based.
The reviewed official EDR offer describes a commercial product and demo path, but does not state the customer rights or full license terms for the EDR software.
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Behavioral detection evaluates endpoint events with configurable Sigma rules. The documented OpenCTI connector can forward Sigma rules, but does not parse or validate them.
Signature detection scans file content, injected threads and process memory with configurable YARA rules. The OpenCTI connector can forward rules without validating them.
The optional OpenCTI HarfangLab Intel connector converts selected STIX indicator patterns into IOC rules for IP addresses, domains, URLs and file hashes. It is not a general STIX object import.