HarfangLab EDR (v1.2.5)

This connector allows to fetch security events and/or threats from a HarfangLab EDR Manager and manage the incident response.

Author
HarfangLab
Support
partner
URL
https://support.harfanglab.fr
Categories
Endpoint

Incident fields (9)

Integrations (1)

Layouts (2)

Playbooks (24)

README

HarfangLab EDR

This connector allows to fetch security events from a HarfangLab EDR Manager and manage the incident response.

It is shipped with:

The alert management playbook illustrates several steps of a typical incident response with forensics activities:

  1. Endpoint isolation
  2. Forensics data collection
  3. Raw artifacts collection
  4. Agent reconnection
  5. Case closing