What it is
Halcyon is a platform against exactly one class of attack: ransomware. The vendor’s argument is that ransomware is its own category, with sequences an EDR was never tuned for, and it calls its product the first defence dedicated to it. The agent runs beside the existing EDR, not in its place.
How it works
It watches for ransomware-typical behaviour across the stages of an attack. If encryption starts anyway, the platform captures the key material, which is what lets encrypted data be restored within hours. Added to that are protection against data exfiltration, meaning the extortion built on stolen data, and a guard for the EDR itself, so an attacker cannot simply switch it off.
Behind the product sits the vendor’s Ransomware Operations Center: detection, response and recovery, around the clock and included in the price.
What to watch
Halcyon replaces neither the EDR nor the backup. The three layers answer different questions: the EDR spots the attacker, Halcyon keeps an incident from becoming extortion, and the backup remains the last line of defence. Cutting one layer because another exists is saving in the wrong place.