HarfangLab is adding Identity Threat Detection and Response (ITDR) to its platform. With this move,the European security provider is expanding its detection and response capabilities from endpoints and servers to user accounts and identity providers. The functionality runs on the same lightweight agent as the existing EDR solution.
ITDR transforms HarfangLab into more of a security platform than it was with endpoint security alone. The misuse of legitimate accounts and access rights is now the most common method attackers use to infiltrate and move laterally across networks. An attacker who takes over a legitimate account can bypass existing defenses and then move laterally through the environment. At first glance, that traffic appears to come from a regular user.
The launch positions HarfangLab within the company’s own Workspace Detection & Response strategy. This strategy is designed to cover endpoints, servers, identities, cloud environments, SaaS applications, and externally accessible assets from a single platform.
Sigma rules and behavioral analysis
Under the hood, ITDR combines Sigma-based detection, configurable rules, and user behavior analysis. Early use cases include detecting a domain controller connecting to a malicious server, attempts to copy data from Active Directory without proper permissions, and login attempts outside of normal working hours. Incidents, threats, and user data are consolidated into a single console.
It is often a matter of linking behavior to measurable criteria, since a single signal should not necessarily indicate a problem. It’s about the sum of anomalies that must occur frequently enough to warrant a notification, but not so frequently that false positives dominate. HarfangLab is now taking on that challenge.
A competitive market, a European profile
HarfangLab is entering a crowded segment. Microsoft and Okta have strengthened their security offerings from an identity management perspective, and CyberArk has done so from a privilege management perspective, while other security companies such as CrowdStrike are also taking a more comprehensive approach to identity protection than before.
The French company has long positioned itself as the open and European EDR option, with data remaining on the continent. Earlier this year, the EDR solution received German BSI certification, following prior recognition by France’s ANSSI.