HarfangLab provides endpoint protection software that utilizes customizable EDR rules and AI-driven detection engines to identify and neutralize cyber threats in real-time. The solution enhances analysts' capabilities by offering seamless integration with existing security tools and maintaining performance across various operating systems, ensuring robust defense against sophisticated attacks.
Funding
$26.4M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

CDFounders
Product
Problem
Organizations face increasing cyber threats targeting their endpoints, requiring robust protection to maintain business continuity and prevent data breaches. Traditional security solutions often lack the flexibility to adapt to evolving threats and may not seamlessly integrate with existing security infrastructure.
Solution
HarfangLab provides endpoint protection software designed to empower security analysts with customizable detection rules and AI-driven engines. The solution offers real-time threat identification and neutralization, ensuring robust defense against both basic and sophisticated cyberattacks. By providing a transparent, API-enabled platform, HarfangLab integrates with existing security tools, allowing organizations to build their own cyber stack. Its lightweight agents deliver consistent functionality across various operating systems and environments, whether SaaS or on-premises, without compromising system performance.
Target Audience
The primary target audience includes organizations of all sizes seeking to protect their workstations and servers against cyber threats, particularly those with existing security infrastructure looking for a flexible and integrable EDR solution.
Features
- Customizable EDR rules in open standardized formats (YARA, Sigma) for enhanced detection, investigation, and remediation
- AI-powered detection engines, including Ashley for malware identification and malicious script detection, and Kio, an AI assistant for analysts
- Lightweight agents with minimal resource consumption (~130 MB RAM, 5% CPU) and updates without rebooting
- Consistent protection capabilities in both cloud and on-premises environments, with flexible deployment options
- API-enabled solution for seamless integration with leading cyber solutions and minimal disruption of existing processes
- Real-time threat blocking powered by a continuously updated malware database
- Data hosting in Europe, ensuring data availability and compliance