Indicator of Compromise Detection Engine
IOC

A detection engine based on Indicators of Compromise to generate alerts on indicators associated with known threats.

IOC Engine can be configured to scan executables as soon as they are written to disk.

The IOC Engine can generate alerts, among other things, on:

IP
Hash
URL
DNS
Indicator of Compromise
check
Enhanced IOCs for continuous threat response

IOCs can be enriched by users to extend the detection or investigation capabilities of the EDR according to their needs and their threat landscape.

YARA Rules
check
An engine that connects with third-party tools

IOCs have a short lifespan. To ensure optimal, ongoing protection, an EDR needs to be able to easily connect with third-party solutions to enrich IOCs and evolve them over time.

 

HarfangLab’s EDR can be connected to Threat Intelligence solutions such as OpenCTI, the IOC knowledge base.

 

This connector enables OpenCTI IOCs to be integrated into HarfangLab, and HarfangLab Security Events and Threats to be retrieved and integrated into OpenCTI.

 

This enables analysts to centralize data and structure information on threats and attacker groups to improve their knowledge about the context.