HarfangLab EDR/EPP Platform logo

HarfangLab EDR/EPP Platform

Endpoint ProtectionEndpoint Detection and Response (EDR)Endpoint Protection Platform (EPP)

Unified endpoint security platform combining EDR, EPP, and ASM with ANSSI certification.

Vendor Information

HarfangLab logo

HarfangLab

Paris, France

HarfangLab EDR/EPP Platform Overview

HarfangLab is a European sovereign endpoint security platform combining Endpoint Detection and Response (EDR) and Endpoint Protection Platform (EPP) with Attack Surface Management (ASM) capabilities in a unified solution. Founded in 2018 by former French Navy, Ministry of Armed Forces, and ANSSI professionals, HarfangLab is the first and only EDR to receive ANSSI Qualification (January 2025) and the first EDR certified by both ANSSI (2020) and BSI. The platform protects workstations and servers against advanced threats including malware, ransomware, fileless attacks, zero-day exploits, and targeted attacks using transparent, customizable detection rules in standardized YARA and Sigma formats.

The platform features proprietary AI models Ashley for unknown malware prediction and malicious PowerShell detection deployed directly in endpoint agents, and Kio as a natural language security assistant integrated into the console for documentation queries and investigation support. HarfangLab offers identical detection capabilities across cloud, on-premises, private cloud (SecNumCloud), and hybrid deployments with full feature parity, ensuring organizations meet sovereignty and compliance requirements without performance compromise. The EPP component (Shield) integrates IKARUS antivirus engine with continuously updated malware database, customizable firewall, and device control. The Scout feature set enhances the EDR/EPP platform with Attack Surface Management capabilities including vulnerability assessment with continuous CVE monitoring from NIST, shadow IT discovery via network probes, and correlation with EDR security events in a single console.

HarfangLab achieved top-tier performance ranking as European leader in 2023 MITRE ATT&CK Evaluations during its first participation. The platform protects 600+ customers including government agencies, CAC 40 corporations, and enterprises across highly sensitive sectors, managing 800,000+ endpoints with 50+ MSSP partners across France and Europe. All deployment options ensure data sovereignty and compliance with GDPR, NIS2, DORA, and ISO 27001 regulations through French-developed technology respecting European digital independence principles.

Key Capabilities

Standardized capabilities mapped to this product's security niche

Captures and analyzes in-memory process state to detect fileless malware, injected shellcode, and credential material that leaves no disk artifacts. Requires kernel-level agent access.

Ingests events from non-endpoint sources (firewall, identity, email, cloud) into the EDR platform for cross-signal correlation, enabling XDR-style detection without a separate XDR product.

Detects threats by modeling process behavior, memory access patterns, and inter-process relationships rather than matching file signatures. Catches novel malware and LOLBin-based attacks that have no signature.

Maintains local detection and prevention capability when the endpoint cannot reach the management console, relevant for air-gapped, traveling, or connectivity-impaired devices.

Provides a query interface over telemetry (process tree, network connections, registry events, file events), for analyst-led investigation independent of alert workflows. Differentiation is query language expressiveness and historical data retention.

Provides equivalent detection coverage, behavioral analysis depth, and response capabilities on Linux and macOS agents as on Windows. Most platforms have a material detection gap on non-Windows systems.

Integrations

Compatible tools and platforms

Active DirectoryAxians Solar SOCAzure SentinelElasticFile Analysis CentersFiligranIKARUS Antivirus EngineMicrosoft 365MISPNDRQRadarSekoia.ioSIEMSOARSplunkThreat Intelligence Platforms

Solution Details

Compliance & Certifications

Regulatory frameworks and security certifications

ANSSI CSPN

Deployment Options

Where and how this solution can be deployed

CloudHybridOn-PremisesPrivate Cloud

Support Channels

Available support and communication options

Email SupportKnowledge BasePhone Support

Pricing Model

How this solution is priced

Per EndpointSubscription

How to buy

This profile hasn’t been claimed yet. Contact the vendor directly for pricing and purchasing options.

Is this your company?

Claim Your Profile