HarfangLab has enabled the administration to strengthen its security posture. It can now easily generate detailed workspace maps, build custom detection rules, and run automated jobs to investigate or block threats.
Using its remote shell feature, the platform is also valuable for troubleshooting issues that arise during the deployment of other solutions or software updates.
Additionally, the administration can more easily monitor Shadow IT and the use of external USB storage devices, and isolate endpoints when necessary.
“Users do not have administrator rights on their workstations, but we strive to strike the right balance between security requirements and the operational flexibility they need for their daily activities. For example, the use of external USB devices remains permitted while being monitored by HarfangLab, which allows us to detect and block suspicious behaviors such as attempts to communicate with malicious IP addresses or websites.
Furthermore, to improve our security posture against Shadow IT risks, HarfangLab’s EDR enables us to automatically generate a detailed map of the applications installed across our environment. We can thereby identify unauthorized software, block its execution, or – when the risk level justifies it – isolate the endpoints concerned. This capability also contributes to raising user awareness of cybersecurity issues when isolation is required.
Finally, thanks to the transparency of detection rules and the level of detail provided by the platform, we can precisely understand the origin of alerts and implement targeted remediation actions. The richness of the data collected also allows us to identify weak signals and efficiently trace back to the root cause of a security incident.”
Head of the Cyber Defense Team and SOC Manager
The administration continuously fine-tunes its detection rules to keep pace with evolving usage patterns and threats, pushing protection well beyond what was achievable with an antivirus solution alone.
“Beyond malicious files, user behaviors pose the primary security risks. We write a large number of Sigma rules ourselves to tailor them to our specific needs and move toward maximum, meaningful automation.”
Head of the Cyber Defense Team and SOC Manager