HarfangLab EDR by HarfangLab is an Endpoint Detection and Response solution designed to protect endpoints through advanced security measures. It includes multiple detection engines such as a signature engine, IOC engine, IA engine, behavioral engine, and Ransomguard engine. HarfangLab EDR is capable of detecting malicious files based on specific signatures, setting up detection alerts on IOCs, and utilizing algorithms to detect undetectable binaries. It employs over 1,200 detection rules to identify potential new threats and has a specialized engine to counter ransomware. The solution safeguards the EDR system against unauthorized tampering, prevents the download and installation of malicious drivers, and monitors callback functions for malicious driver modifications. HarfangLab EDR allows deployment and updates without restarting endpoints, reduces RAM and CPU consumption with ultra-light agents, and uses the Rust language for enhanced security. It simplifies alert understanding, allows customization of detection rules, and gathers weak signals associated with threats. The solution is fully API-controllable for easy integration into existing processes and evolves rapidly with new features added frequently. HarfangLab EDR can send security events to various platforms for threat intelligence and correlation, and it supports multiple authentication methods including OpenID Connect, Open LDAP, and Active Directory.