HarfangLab

French endpoint detection, certified by ANSSI - European alternative based in France

Quick Overview

Company HarfangLab
Category SIEM & Security Monitoring
Headquarters Paris, France
EU/European Yes - France
GDPR Compliant Yes
Main Features ANSSI-certified EDR, On-premises or SecNumCloud, Open detection rules
Pricing Per endpoint, per year
Best For Organisations that need endpoint telemetry under French or EU control
Replaces CrowdStrike, SentinelOne, Microsoft Defender for Endpoint

Detailed Review

Pros and Cons

Pros

  • ANSSI-certified, which the US incumbents are not
  • Deployable fully on-premises or on SecNumCloud
  • Detection rules in YARA and Sigma you can read and edit
  • Windows, Linux and macOS agents
  • Integrates into existing SIEM and SOC tooling

Cons

  • EDR rather than a SIEM — it feeds one
  • On-premises deployment needs someone to run it
  • Smaller threat intelligence footprint than CrowdStrike
  • Priced per endpoint, so large estates add up

Alternatives to HarfangLab

Looking for other European security monitoring platforms? Here are the alternatives worth comparing:

Frequently Asked Questions

HarfangLab is based in France and operates under European data-protection rules including the GDPR. Security logs contain personal data — usernames, IP addresses, access times — so this is a processing question as well as a security one.

HarfangLab is based in France. Security telemetry describes an organisation's defences and its failures, which is why the vendor's jurisdiction carries unusual weight here.

Endpoint agents for Windows, Linux and macOS with process, network and file telemetry, detection engines including YARA and Sigma rules, threat hunting, response actions, and integration into SIEM and SOC tooling.

Per endpoint per year, with the on-premises deployment licensed the same way as the hosted one rather than at an enterprise premium.

HarfangLab is a European alternative to CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, generally with a cost model that does not scale directly with log volume.

Detection and logging are foundational to the NIS2 obligations around incident handling and reporting, and this category is where most of that capability sits. No product delivers compliance on its own — the directive covers governance, supply chain and reporting timelines too — but you cannot report an incident within the deadline if nothing detected it.

Who worked on this review

Three people touch every tool page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's own documentation.

Sebastiaan Smits
Written by

Sebastiaan Smits

Founder & Editor · Netherlands

Selects the tools, writes the reviews, and checks where each company is actually established.

Daniel Brandt
Edited by

Daniel Brandt

Privacy & Compliance Researcher · Berlin, Germany

Checks the compliance claims: where the company is established, where the data sits, and what the DPA actually says.

Marta Kowalczyk
Fact-checked by

Marta Kowalczyk

Senior Analyst, Infrastructure & Developer Tools · Warsaw, Poland

Covers hosting, developer tooling and the practical side of moving workloads to European providers.

Read our editorial process for how we source, verify and update these pages — and how we keep affiliate income separate from what we recommend.

Go to HarfangLab