---
# source: src/content/solutions/en/endpoint-security/halcyon.md
# route:  /en/solutions/endpoint-security/halcyon/
title: Halcyon
tags: [endpoint-security, security, backup-recovery]
vendors: [halcyon]
summary: Built for one attack and nothing else. It does not replace an EDR, it sits beside one and assumes the ransomware got past it.
photoNeed: A security console on screen with real alerts in it, being triaged
stub: false
draft: false
kind: product
addon: false
sourceNote: halcyon.ai platform pages, read 2026-08-30, for the capabilities, the Ransomware Operations Center and the warranty
vendorName: Halcyon Anti-Ransomware Platform
status: current
---

## What it is

Halcyon is an anti-ransomware platform, and it is worth being precise about that phrase.
It is not endpoint protection, it is not detection and response, and it is not a backup
product. It is one layer aimed at one attack, and its own argument is that it covers the
gap between an EPP and an EDR rather than replacing either.

The engine is trained on ransomware behaviour specifically: the process injections, the
encryption routines, the exfiltration patterns that ransomware operators use, rather than
on malware generally.

## The part that is genuinely different

**It assumes it will lose.** Alongside the prevention layers sits a resiliency layer that
captures the encryption keys the attacker is using while the attack is running. If files
get encrypted anyway, they can be decrypted from the captured material rather than restored
from a backup or bought back from the operator.

That is a different bet from every other product on this page. Detection assumes you catch
it; this assumes you sometimes will not.

## What else it watches

Vulnerable driver abuse, which is how attackers disable security tools from the kernel.
Tampering with the security agents themselves, Microsoft Defender and CrowdStrike and
SentinelOne and Cortex among them, on the reasoning that the first move against an endpoint
is often against its guard. Living-off-the-land activity through PowerShell and WMIC, and
volume shadow copies, which ransomware deletes before it encrypts so that the local
recovery path is gone.

And exfiltration, because double extortion means the encryption is only half the incident.

## What to check before it goes on the list

Two things, and neither is technical.

The vendor runs a Ransomware Operations Center and includes it, and offers a warranty that
its people will help you recover if an attack succeeds. Both are worth reading in the
contract rather than on the website, because what “help you recover” covers is the whole
question.

The second is overlap. This is a second agent on every endpoint next to an EDR that already
claims ransomware coverage. The case for it rests on the recovery layer being real, so that
is the part to test rather than the detection rate.
