---
# source: src/content/solutions/en/endpoint-security/halcyon-anti-ransomware.md
# route:  /en/solutions/endpoint-security/halcyon-anti-ransomware/
title: Halcyon Anti-Ransomware
tags: [endpoint-security, security, backup-recovery]
vendors: [halcyon]
summary: "A platform against exactly one class of attack: ransomware. It runs beside the EDR, captures key material, and takes the leverage out of extortion."
photoNeed: A security console on screen with real alerts in it, being triaged
stub: false
draft: false
kind: product
addon: false
vendorName: Halcyon Anti-Ransomware Platform
status: current
practice: >
  We sell and implement Halcyon. With us it complements the EDR; it does not replace it.
practiceReview: false
---

## What it is

Halcyon is a platform against exactly one class of attack: ransomware. The vendor's
argument is that ransomware is its own category, with sequences an EDR was never tuned
for, and it calls its product the first defence dedicated to it. The agent runs beside
the existing EDR, not in its place.

## How it works

It watches for ransomware-typical behaviour across the stages of an attack. If
encryption starts anyway, the platform captures the key material, which is what lets
encrypted data be restored within hours. Added to that are protection against data
exfiltration, meaning the extortion built on stolen data, and a guard for the EDR
itself, so an attacker cannot simply switch it off.

Behind the product sits the vendor's Ransomware Operations Center: detection, response
and recovery, around the clock and included in the price.

## What to watch

Halcyon replaces neither the EDR nor the backup. The three layers answer different
questions: the EDR spots the attacker, Halcyon keeps an incident from becoming
extortion, and the backup remains the last line of defence. Cutting one layer because
another exists is saving in the wrong place.
