HarfangLab
French endpoint detection, certified by ANSSI - European alternative based in France
Quick Overview
| Company | HarfangLab |
|---|---|
| Category | SIEM & Security Monitoring |
| Headquarters | Paris, France |
| EU/European | Yes - France |
| GDPR Compliant | Yes |
| Main Features | ANSSI-certified EDR, On-premises or SecNumCloud, Open detection rules |
| Pricing | Per endpoint, per year |
| Best For | Organisations that need endpoint telemetry under French or EU control |
| Replaces | CrowdStrike, SentinelOne, Microsoft Defender for Endpoint |
Detailed Review
HarfangLab is a Paris endpoint detection and response vendor and one of the few EDR products certified by ANSSI, the French national cybersecurity agency — a qualification the American incumbents do not hold.
What Makes HarfangLab Stand Out
EDR is the most invasive software an organisation installs: an agent with kernel access on every machine, streaming process telemetry to the vendor. HarfangLab can be deployed entirely on-premises with detection rules you can read and modify, which changes that relationship from trust to inspection.
What the Platform Covers
Endpoint agents for Windows, Linux and macOS with process, network and file telemetry, detection engines including YARA and Sigma rules, threat hunting, response actions, and integration into SIEM and SOC tooling.
European Jurisdiction and NIS2
HarfangLab is French, ANSSI-certified, and deployable on-premises or on SecNumCloud-qualified infrastructure. For an operator of essential services under NIS2, that combination is often the requirement rather than the preference.
Security logs describe an organisation's defences, its blind spots and its incidents. Under NIS2, in-scope organisations across energy, transport, health, digital infrastructure and public administration now have reporting duties and supply chain obligations that make the origin of the security stack part of the compliance question rather than a preference.
Pricing
Per endpoint per year, with the on-premises deployment licensed the same way as the hosted one rather than at an enterprise premium.
HarfangLab vs Splunk and Microsoft Sentinel
Against CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, the two European arguments are cost model and jurisdiction. Volume-based pricing turns every new log source into a budget decision, which is how SIEM deployments end up blind in exactly the places that matter; and security telemetry is the last data set most European public bodies want under foreign jurisdiction.
Who Should Use HarfangLab
HarfangLab suits public bodies, critical infrastructure operators and enterprises who need endpoint detection without sending their telemetry outside Europe.
Pros and Cons
Pros
- ANSSI-certified, which the US incumbents are not
- Deployable fully on-premises or on SecNumCloud
- Detection rules in YARA and Sigma you can read and edit
- Windows, Linux and macOS agents
- Integrates into existing SIEM and SOC tooling
Cons
- EDR rather than a SIEM — it feeds one
- On-premises deployment needs someone to run it
- Smaller threat intelligence footprint than CrowdStrike
- Priced per endpoint, so large estates add up
Alternatives to HarfangLab
Looking for other European security monitoring platforms? Here are the alternatives worth comparing:
Frequently Asked Questions
HarfangLab is based in France and operates under European data-protection rules including the GDPR. Security logs contain personal data — usernames, IP addresses, access times — so this is a processing question as well as a security one.
HarfangLab is based in France. Security telemetry describes an organisation's defences and its failures, which is why the vendor's jurisdiction carries unusual weight here.
Endpoint agents for Windows, Linux and macOS with process, network and file telemetry, detection engines including YARA and Sigma rules, threat hunting, response actions, and integration into SIEM and SOC tooling.
Per endpoint per year, with the on-premises deployment licensed the same way as the hosted one rather than at an enterprise premium.
HarfangLab is a European alternative to CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, generally with a cost model that does not scale directly with log volume.
Detection and logging are foundational to the NIS2 obligations around incident handling and reporting, and this category is where most of that capability sits. No product delivers compliance on its own — the directive covers governance, supply chain and reporting timelines too — but you cannot report an incident within the deadline if nothing detected it.