HarfangLab, the European leader in Workspace Detection and Response, today announced the launch of its ITDR solution, Identity Threat Detection and Response. The new capability extends the HarfangLab platform’s detection and response capabilities to identities and identity providers, helping organizations prevent account compromise, lateral movement, and privilege escalation, which are now common elements of cyberattacks.
With ITDR, HarfangLab is continuing to expand beyond the protection of workstations and servers provided by its EDR, EPP, and ASM solutions, toward an extended approach to securing the digital environments in which organizations operate. This marks a further step in the development of a Workspace Detection & Response strategy, designed to secure the full range of digital assets used by employees, including endpoints, servers, identities, cloud environments, SaaS applications, and exposed assets through a single, unified platform.
Identities: a critical new frontier for business continuity
In recent years, organizations’ attack surfaces have expanded exponentially. In addition to traditional entry points such as endpoints and servers, they now encompass identities and email systems. At the same time, the threat landscape is evolving rapidly, with attackers constantly looking for new ways to gain access and compromise systems, while leveraging AI. Identities have become a critical attack vector: compromising a legitimate account can enable an attacker to bypass traditional defenses, access sensitive resources, and move laterally within the IT environment.
HarfangLab’s 2026 State of Cybersecurity Report found that:
- 73% of European business leaders believe a cyberattack could severely disrupt their operations and revenue
- 48% say their revenue could be affected from the first day of an attack
recovering from a disruption takes an average of 4.32 days, rising to more than six days in France;
Against this backdrop, identity protection can no longer be treated as a standalone issue or as a responsibility limited to IT administration. It is now central to an organization’s ability to detect attacks quickly, contain their spread, and keep its business running.
An additional layer of protection alongside endpoint security
HarfangLab’s ITDR is built on the same lightweight agent as its EDR solution. Using detection mechanisms similar to those already deployed on endpoints, it provides dedicated visibility into identities as an attack surface. Security events, threats, users, and related entities are unified in a single console, simplifying incident triage and investigation.
Initial use cases include:
- detecting attempts to coerce a domain controller into authenticating to a malicious server
- detecting attempts to fraudulently replicate Active Directory secrets from a server that should not have the required privileges
- identifying logins outside an employee’s usual working hours
- spotting anomalous or suspicious behavior associated with accounts and identities.
ITDR combines Sigma-based detection engines, configurable rules, and user behavior analytics. These capabilities allow organizations to tailor detection to their own context and reconstruct attacks end to end.
“Today, every digital asset used by an organization can be targeted by a cyberattack. With ITDR, we are extending our detection and response capabilities to one of the most critical parts of the IT environment: identities. Our ambition is to help organizations connect endpoint protection, identity security, and attack surface management within a single cybersecurity strategy, strengthening their ability to maintain business continuity.” Guillaume Ruty, Chief Product Officer at HarfangLab.
Workspace Detection and Response: evolving in response to operational needs
Since it was founded in 2018, HarfangLab has developed technologies that help organizations detect, investigate, and neutralize cyberattacks. Its solution portfolio now includes:
- ASM and vulnerability management, to improve visibility into assets, identify vulnerabilities, and reduce the attack surface
- EPP, with next-generation antivirus, firewall, and device-control capabilities
- EDR, to detect, investigate, and respond to attacks on endpoints
- ITDR, to detect and respond to identity-based threats
- Email security, to protect inboxes, combat spam and phishing, secure email traffic, and enable email encryption
This evolution is driving HarfangLab to expand its offering into a Workspace Detection & Response platform. The mission is to give organizations the flexibility of a modular approach tailored to their needs, while progressively bringing detection, investigation, and remediation together in a single operational experience. This builds on HarfangLab’s expertise in detection and response, together with its development of an advanced security agent.
Availability
HarfangLab’s ITDR offering is available from September 2026. As with all HarfangLab offerings, it is available with the same functionality via the cloud or on-premises, including deployment via the company’s MSSP and distribution partners.