HarfangLab EDR
Endpoint Detection and Response

Simplify the work of cybersecurity teams to protect endpoints, anticipate threats, and respond swiftly regardless of OS or environment – Cloud and On-Premises alike with full feature parity.

Cybersecurity alert
Detect and block threats
Cybersecurity experts
Optimize your analysis
Cybersecurity Protection
Keep your infrastructure safe and control your data

HarfangLab EDR’s advanced detection engines are embedded directly into the agents deployed on endpoints (workstations and servers), ensuring endpoint protection is as close as possible to the threat.

Both easy to install and scalable, HarfangLab EDR is engineered to maintain endpoints performance and deliver reliable protection and remediation capacities even when endpoints are disconnected from the network.

On-Premises & Cloud deployment with same functionalities
AI to detect unknown threats and enhance analysts' capabilities
Wide-ranging integrations for a perfectly tailored cyber stack
API available for close management of the working environment
Fine-tune threat intelligence, correlation engine and whitelists to efficiently reduce false positives
Access to all data for comprehensive exploitation, aggregation, correlation

An EDR (Endpoint Detection and Response) is a security solution designed to protect endpoints, such as workstations and servers, through an installed agent that detects and mitigates threats. It not only identifies suspicious files but also monitors for malicious behaviour, indicators of compromise and more. The EDR can generate alerts or block threats while providing detailed information that allows for thorough investigation of the detected security events.

The EPP (Endpoint Protection Platform) is a security tool designed to provide broad threat protection, including features like antivirus, firewall and USB port protection. It can automatically block threats when it detects malicious files, unauthorised network connections, the connection of USB devices, etc. EPPs can also alert you to abnormal activity.

An EDR (Endpoint Detection and Response), however, focuses on detecting and responding to threats in real-time as a program is executed or by analysing system behaviour. It also collects data about security events to aid in analysing the threat and taking the appropriate response.

HarfangLab EDR employs various detection engines, including behavioural analysis and Artificial Intelligence, to identify and respond to threats that aren’t found in known threat databases.

All OS are supported: Windows, Linux and macOS. Our detailed documentation is available for more information.

HarfangLab EDR can be deployed in the Cloud or On-Premises infrastructure, offering the same functionalities in either environment.

Regardless of the deployment method, agents are installed directly on the endpoints and communicate with the console to share telemetry data and receive threat detection and blocking policies.

Updates require no endpoint reboots and, for On-Premises deployments, can be managed either remotely or on site.

What our customers say

“HarfangLab gives me visibility and control over data that I don’t have with any other cybersecurity solution. Access to all the data provides me with a wealth of information that I didn’t have with our previous solutions.”

“Our sector is heavily constrained by laws and regulations specific to our business and, within this framework, HarfangLab has enabled us to harden protection on all our endpoints and remove doubt whenever necessary. It enables extremely fine-grained control of the activity of the workstations and servers to guard against attacks.”

“HarfangLab enables us to react as quickly as possible in the event of a security alert. After detecting the presence of a stealer on a workstation, we were able to remediate within just a few hours.”