build bd3aee6f | content blog-content@66f2592 · 338 posts | profiles 20 · corpus 309 | 0 skipped | | format
apiVersion: soultec.ch/v1kind: Solutionmetadata: name: endpoint-security/halcyon-anti-ransomware locale: en labels: vendor: Halcyon Anti-Ransomware Platform capability/endpoint-security: 2.85 capability/security: 2.01 capability/backup-recovery: 2.21 vendor/halcyon: 5.05 annotations: source: src/content/solutions/en/endpoint-security/halcyon-anti-ransomware.md route: /en/solutions/endpoint-security/halcyon-anti-ransomware/ schema: /nerd/schema/solutions.json markdown: /en/solutions/endpoint-security/halcyon-anti-ransomware.mdspec: title: Halcyon Anti-Ransomware tags: [endpoint-security, security, backup-recovery] vendors: [halcyon] summary: >- A platform against exactly one class of attack: ransomware. It runs beside the EDR, captures key material, and takes the leverage out of extortion. photoNeed: A security console on screen with real alerts in it, being triaged stub: false draft: false kind: product addon: false vendorName: Halcyon Anti-Ransomware Platform status: current practice: >- We sell and implement Halcyon. With us it complements the EDR; it does not replace it. practiceReview: false sections: - heading:

What it is

body: | Halcyon is a platform against exactly one class of attack: ransomware. The vendor's argument is that ransomware is its own category, with sequences an EDR was never tuned for, and it calls its product the first defence dedicated to it. The agent runs beside the existing EDR, not in its place. - heading:

How it works

body: | It watches for ransomware-typical behaviour across the stages of an attack. If encryption starts anyway, the platform captures the key material, which is what lets encrypted data be restored within hours. Added to that are protection against data exfiltration, meaning the extortion built on stolen data, and a guard for the EDR itself, so an attacker cannot simply switch it off. Behind the product sits the vendor's Ransomware Operations Center: detection, response and recovery, around the clock and included in the price. - heading:

What to watch

body: | Halcyon replaces neither the EDR nor the backup. The three layers answer different questions: the EDR spots the attacker, Halcyon keeps an incident from becoming extortion, and the backup remains the last line of defence. Cutting one layer because another exists is saving in the wrong place.status: corpus: 309 services: - {ref: services/modern-workplace, score: 0.39} - {ref: services/security, score: 0.34} posts: - {ref: posts/exagrid, score: 0.57} - {ref: posts/how-to-scality-artesca, score: 0.37} - {ref: posts/icas-fs, score: 0.37} - {ref: posts/sichere-backups-mit-blocky-for-veeam, score: 0.37} - {ref: posts/veeam-und-s3-storage-mit-artesca, score: 0.37} - {ref: posts/securing-your-data-with-veeam-surebackup, score: 0.37} neighbours: - {ref: solutions/endpoint-security, score: 0.78} - {ref: solutions/igel/addon/90meter, score: 0.48} - {ref: solutions/endpoint-security/crowdstrike-falcon, score: 0.48}
{ "apiVersion": "soultec.ch/v1", "kind": "Solution", "metadata": { "name": "endpoint-security/halcyon-anti-ransomware", "locale": "en", "labels": { "vendor": "Halcyon Anti-Ransomware Platform", "capability/endpoint-security": "2.85", "capability/security": "2.01", "capability/backup-recovery": "2.21", "vendor/halcyon": "5.05" }, "annotations": { "source": "src/content/solutions/en/endpoint-security/halcyon-anti-ransomware.md", "route": "/en/solutions/endpoint-security/halcyon-anti-ransomware/", "schema": "/nerd/schema/solutions.json", "markdown": "/en/solutions/endpoint-security/halcyon-anti-ransomware.md" } }, "spec": { "title": "Halcyon Anti-Ransomware", "tags": [ "endpoint-security", "security", "backup-recovery" ], "vendors": [ "halcyon" ], "summary": "A platform against exactly one class of attack: ransomware. It runs beside the EDR, captures key material, and takes the leverage out of extortion.", "photoNeed": "A security console on screen with real alerts in it, being triaged", "stub": false, "draft": false, "kind": "product", "addon": false, "vendorName": "Halcyon Anti-Ransomware Platform", "status": "current", "practice": "We sell and implement Halcyon. With us it complements the EDR; it does not replace it.\n", "practiceReview": false }, "sections": [ { "heading": "

What it is

",
"body": "Halcyon is a platform against exactly one class of attack: ransomware. The vendor's\nargument is that ransomware is its own category, with sequences an EDR was never tuned\nfor, and it calls its product the first defence dedicated to it. The agent runs beside\nthe existing EDR, not in its place." }, { "heading": "

How it works

",
"body": "It watches for ransomware-typical behaviour across the stages of an attack. If\nencryption starts anyway, the platform captures the key material, which is what lets\nencrypted data be restored within hours. Added to that are protection against data\nexfiltration, meaning the extortion built on stolen data, and a guard for the EDR\nitself, so an attacker cannot simply switch it off.\n\nBehind the product sits the vendor's Ransomware Operations Center: detection, response\nand recovery, around the clock and included in the price." }, { "heading": "

What to watch

",
"body": "Halcyon replaces neither the EDR nor the backup. The three layers answer different\nquestions: the EDR spots the attacker, Halcyon keeps an incident from becoming\nextortion, and the backup remains the last line of defence. Cutting one layer because\nanother exists is saving in the wrong place." } ], "status": { "corpus": 309, "services": [ { "ref": "services/modern-workplace", "score": "0.39" }, { "ref": "services/security", "score": "0.34" } ], "posts": [ { "ref": "posts/exagrid", "score": "0.57" }, { "ref": "posts/how-to-scality-artesca", "score": "0.37" }, { "ref": "posts/icas-fs", "score": "0.37" }, { "ref": "posts/sichere-backups-mit-blocky-for-veeam", "score": "0.37" }, { "ref": "posts/veeam-und-s3-storage-mit-artesca", "score": "0.37" }, { "ref": "posts/securing-your-data-with-veeam-surebackup", "score": "0.37" } ], "neighbours": [ { "ref": "solutions/endpoint-security", "score": "0.78" }, { "ref": "solutions/igel/addon/90meter", "score": "0.48" }, { "ref": "solutions/endpoint-security/crowdstrike-falcon", "score": "0.48" } ] }}
apiVersion = "soultec.ch/v1"kind = "Solution"[metadata]name = "endpoint-security/halcyon-anti-ransomware"locale = "en"[metadata.labels]vendor = "Halcyon Anti-Ransomware Platform""capability/endpoint-security" = "2.85""capability/security" = "2.01""capability/backup-recovery" = "2.21""vendor/halcyon" = "5.05"[metadata.annotations]source = "src/content/solutions/en/endpoint-security/halcyon-anti-ransomware.md"route = "/en/solutions/endpoint-security/halcyon-anti-ransomware/"schema = "/nerd/schema/solutions.json"markdown = "/en/solutions/endpoint-security/halcyon-anti-ransomware.md"[spec]title = "Halcyon Anti-Ransomware"tags = ["endpoint-security", "security", "backup-recovery"]vendors = ["halcyon"]summary = "A platform against exactly one class of attack: ransomware. It runs beside the EDR, captures key material, and takes the leverage out of extortion."photoNeed = "A security console on screen with real alerts in it, being triaged"stub = falsedraft = falsekind = "product"addon = falsevendorName = "Halcyon Anti-Ransomware Platform"status = "current"practice = '''We sell and implement Halcyon. With us it complements the EDR; it does not replace it.'''practiceReview = false[[sections]]heading = "

What it is

"
body = '''Halcyon is a platform against exactly one class of attack: ransomware. The vendor'sargument is that ransomware is its own category, with sequences an EDR was never tunedfor, and it calls its product the first defence dedicated to it. The agent runs besidethe existing EDR, not in its place.'''[[sections]]heading = "

How it works

"
body = '''It watches for ransomware-typical behaviour across the stages of an attack. Ifencryption starts anyway, the platform captures the key material, which is what letsencrypted data be restored within hours. Added to that are protection against dataexfiltration, meaning the extortion built on stolen data, and a guard for the EDRitself, so an attacker cannot simply switch it off.Behind the product sits the vendor's Ransomware Operations Center: detection, responseand recovery, around the clock and included in the price.'''[[sections]]heading = "

What to watch

"
body = '''Halcyon replaces neither the EDR nor the backup. The three layers answer differentquestions: the EDR spots the attacker, Halcyon keeps an incident from becomingextortion, and the backup remains the last line of defence. Cutting one layer becauseanother exists is saving in the wrong place.'''[status]corpus = 309[[status.services]]ref = "services/modern-workplace"score = "0.39"[[status.services]]ref = "services/security"score = "0.34"[[status.posts]]ref = "posts/exagrid"score = "0.57"[[status.posts]]ref = "posts/how-to-scality-artesca"score = "0.37"[[status.posts]]ref = "posts/icas-fs"score = "0.37"[[status.posts]]ref = "posts/sichere-backups-mit-blocky-for-veeam"score = "0.37"[[status.posts]]ref = "posts/veeam-und-s3-storage-mit-artesca"score = "0.37"[[status.posts]]ref = "posts/securing-your-data-with-veeam-surebackup"score = "0.37"[[status.neighbours]]ref = "solutions/endpoint-security"score = "0.78"[[status.neighbours]]ref = "solutions/igel/addon/90meter"score = "0.48"[[status.neighbours]]ref = "solutions/endpoint-security/crowdstrike-falcon"score = "0.48"
<?xml version="1.0" encoding="UTF-8"?><manifest kind="Solution"> <apiVersion>soultec.ch/v1</apiVersion> <metadata> <name>endpoint-security/halcyon-anti-ransomware</name> <locale>en</locale> <labels> <vendor>Halcyon Anti-Ransomware Platform</vendor> <entry key="capability/endpoint-security">2.85</entry> <entry key="capability/security">2.01</entry> <entry key="capability/backup-recovery">2.21</entry> <entry key="vendor/halcyon">5.05</entry> </labels> <annotations> <source>src/content/solutions/en/endpoint-security/halcyon-anti-ransomware.md</source> <route>/en/solutions/endpoint-security/halcyon-anti-ransomware/</route> <schema>/nerd/schema/solutions.json</schema> <markdown>/en/solutions/endpoint-security/halcyon-anti-ransomware.md</markdown> </annotations> </metadata> <spec> <title>Halcyon Anti-Ransomware</title> <tags> <item>endpoint-security</item> <item>security</item> <item>backup-recovery</item> </tags> <vendors> <item>halcyon</item> </vendors> <summary>A platform against exactly one class of attack: ransomware. It runs beside the EDR, captures key material, and takes the leverage out of extortion.</summary> <photoNeed>A security console on screen with real alerts in it, being triaged</photoNeed> <stub>false</stub> <draft>false</draft> <kind>product</kind> <addon>false</addon> <vendorName>Halcyon Anti-Ransomware Platform</vendorName> <status>current</status> <practice>We sell and implement Halcyon. With us it complements the EDR; it does not replace it. </practice> <practiceReview>false</practiceReview> </spec> <sections> <section> <heading>

What it is

</heading>
<body>Halcyon is a platform against exactly one class of attack: ransomware. The vendor'sargument is that ransomware is its own category, with sequences an EDR was never tunedfor, and it calls its product the first defence dedicated to it. The agent runs besidethe existing EDR, not in its place. </body> </section> <section> <heading>

How it works

</heading>
<body>It watches for ransomware-typical behaviour across the stages of an attack. Ifencryption starts anyway, the platform captures the key material, which is what letsencrypted data be restored within hours. Added to that are protection against dataexfiltration, meaning the extortion built on stolen data, and a guard for the EDRitself, so an attacker cannot simply switch it off.Behind the product sits the vendor's Ransomware Operations Center: detection, responseand recovery, around the clock and included in the price. </body> </section> <section> <heading>

What to watch

</heading>
<body>Halcyon replaces neither the EDR nor the backup. The three layers answer differentquestions: the EDR spots the attacker, Halcyon keeps an incident from becomingextortion, and the backup remains the last line of defence. Cutting one layer becauseanother exists is saving in the wrong place. </body> </section> </sections> <status> <corpus>309</corpus> <services> <item> <ref>services/modern-workplace</ref> <score>0.39</score> </item> <item> <ref>services/security</ref> <score>0.34</score> </item> </services> <posts> <item> <ref>posts/exagrid</ref> <score>0.57</score> </item> <item> <ref>posts/how-to-scality-artesca</ref> <score>0.37</score> </item> <item> <ref>posts/icas-fs</ref> <score>0.37</score> </item> <item> <ref>posts/sichere-backups-mit-blocky-for-veeam</ref> <score>0.37</score> </item> <item> <ref>posts/veeam-und-s3-storage-mit-artesca</ref> <score>0.37</score> </item> <item> <ref>posts/securing-your-data-with-veeam-surebackup</ref> <score>0.37</score> </item> </posts> <neighbours> <item> <ref>solutions/endpoint-security</ref> <score>0.78</score> </item> <item> <ref>solutions/igel/addon/90meter</ref> <score>0.48</score> </item> <item> <ref>solutions/endpoint-security/crowdstrike-falcon</ref> <score>0.48</score> </item> </neighbours> </status></manifest>
Solution · Halcyon

Halcyon Anti-Ransomware

The vendor calls it: Halcyon Anti-Ransomware Platform

A platform against exactly one class of attack: ransomware. It runs beside the EDR, captures key material, and takes the leverage out of extortion.

Topics Endpoint Security 2.85 Security 2.01 Backup and Recovery 2.21
Vendors Halcyon 5.05
02Services
06Posts
03Capabilities
309Corpus

What it is

Halcyon is a platform against exactly one class of attack: ransomware. The vendor’s argument is that ransomware is its own category, with sequences an EDR was never tuned for, and it calls its product the first defence dedicated to it. The agent runs beside the existing EDR, not in its place.

How it works

It watches for ransomware-typical behaviour across the stages of an attack. If encryption starts anyway, the platform captures the key material, which is what lets encrypted data be restored within hours. Added to that are protection against data exfiltration, meaning the extortion built on stolen data, and a guard for the EDR itself, so an attacker cannot simply switch it off.

Behind the product sits the vendor’s Ransomware Operations Center: detection, response and recovery, around the clock and included in the price.

What to watch

Halcyon replaces neither the EDR nor the backup. The three layers answer different questions: the EDR spots the attacker, Halcyon keeps an incident from becoming extortion, and the backup remains the last line of defence. Cutting one layer because another exists is saving in the wrong place.

What we do with it

We sell and implement Halcyon. With us it complements the EDR; it does not replace it.

Posts about it

Who works with it

Do you work with this? Take a look at our open roles.