build 2705c453 | content blog-content@0deff18 · 338 posts | profiles 20 · corpus 309 | 0 skipped | | format
apiVersion: soultec.ch/v1kind: Solutionmetadata: name: endpoint-security/halcyon locale: en labels: vendor: Halcyon Anti-Ransomware Platform capability/endpoint-security: 2.85 capability/security: 2.01 capability/backup-recovery: 2.21 vendor/halcyon: 5.05 annotations: source: src/content/solutions/en/endpoint-security/halcyon.md route: /en/solutions/endpoint-security/halcyon/ schema: /nerd/schema/solutions.json markdown: /en/solutions/endpoint-security/halcyon.mdspec: title: Halcyon tags: [endpoint-security, security, backup-recovery] vendors: [halcyon] summary: >- Built for one attack and nothing else. It does not replace an EDR, it sits beside one and assumes the ransomware got past it. photoNeed: A security console on screen with real alerts in it, being triaged stub: false draft: false kind: product addon: false sourceNote: >- halcyon.ai platform pages, read 2026-08-30, for the capabilities, the Ransomware Operations Center and the warranty vendorName: Halcyon Anti-Ransomware Platform status: current sections: - heading:

What it is

body: | Halcyon is an anti-ransomware platform, and it is worth being precise about that phrase. It is not endpoint protection, it is not detection and response, and it is not a backup product. It is one layer aimed at one attack, and its own argument is that it covers the gap between an EPP and an EDR rather than replacing either. The engine is trained on ransomware behaviour specifically: the process injections, the encryption routines, the exfiltration patterns that ransomware operators use, rather than on malware generally. - heading:

The part that is genuinely different

body: | **It assumes it will lose.** Alongside the prevention layers sits a resiliency layer that captures the encryption keys the attacker is using while the attack is running. If files get encrypted anyway, they can be decrypted from the captured material rather than restored from a backup or bought back from the operator. That is a different bet from every other product on this page. Detection assumes you catch it; this assumes you sometimes will not. - heading:

What else it watches

body: | Vulnerable driver abuse, which is how attackers disable security tools from the kernel. Tampering with the security agents themselves, Microsoft Defender and CrowdStrike and SentinelOne and Cortex among them, on the reasoning that the first move against an endpoint is often against its guard. Living-off-the-land activity through PowerShell and WMIC, and volume shadow copies, which ransomware deletes before it encrypts so that the local recovery path is gone. And exfiltration, because double extortion means the encryption is only half the incident. - heading:

What to check before it goes on the list

body: | Two things, and neither is technical. The vendor runs a Ransomware Operations Center and includes it, and offers a warranty that its people will help you recover if an attack succeeds. Both are worth reading in the contract rather than on the website, because what “help you recover” covers is the whole question. The second is overlap. This is a second agent on every endpoint next to an EDR that already claims ransomware coverage. The case for it rests on the recovery layer being real, so that is the part to test rather than the detection rate.status: corpus: 309 services: - {ref: services/modern-workplace, score: 0.39} - {ref: services/security, score: 0.34} posts: - {ref: posts/exagrid, score: 0.57} - {ref: posts/how-to-scality-artesca, score: 0.37} - {ref: posts/icas-fs, score: 0.37} - {ref: posts/sichere-backups-mit-blocky-for-veeam, score: 0.37} - {ref: posts/veeam-und-s3-storage-mit-artesca, score: 0.37} - {ref: posts/securing-your-data-with-veeam-surebackup, score: 0.37} neighbours: - {ref: solutions/endpoint-security, score: 0.78} - {ref: solutions/igel/addon/90meter, score: 0.48} - {ref: solutions/endpoint-security/vmware-carbon-black, score: 0.48}
{ "apiVersion": "soultec.ch/v1", "kind": "Solution", "metadata": { "name": "endpoint-security/halcyon", "locale": "en", "labels": { "vendor": "Halcyon Anti-Ransomware Platform", "capability/endpoint-security": "2.85", "capability/security": "2.01", "capability/backup-recovery": "2.21", "vendor/halcyon": "5.05" }, "annotations": { "source": "src/content/solutions/en/endpoint-security/halcyon.md", "route": "/en/solutions/endpoint-security/halcyon/", "schema": "/nerd/schema/solutions.json", "markdown": "/en/solutions/endpoint-security/halcyon.md" } }, "spec": { "title": "Halcyon", "tags": [ "endpoint-security", "security", "backup-recovery" ], "vendors": [ "halcyon" ], "summary": "Built for one attack and nothing else. It does not replace an EDR, it sits beside one and assumes the ransomware got past it.", "photoNeed": "A security console on screen with real alerts in it, being triaged", "stub": false, "draft": false, "kind": "product", "addon": false, "sourceNote": "halcyon.ai platform pages, read 2026-08-30, for the capabilities, the Ransomware Operations Center and the warranty", "vendorName": "Halcyon Anti-Ransomware Platform", "status": "current" }, "sections": [ { "heading": "

What it is

",
"body": "Halcyon is an anti-ransomware platform, and it is worth being precise about that phrase.\nIt is not endpoint protection, it is not detection and response, and it is not a backup\nproduct. It is one layer aimed at one attack, and its own argument is that it covers the\ngap between an EPP and an EDR rather than replacing either.\n\nThe engine is trained on ransomware behaviour specifically: the process injections, the\nencryption routines, the exfiltration patterns that ransomware operators use, rather than\non malware generally." }, { "heading": "

The part that is genuinely different

",
"body": "**It assumes it will lose.** Alongside the prevention layers sits a resiliency layer that\ncaptures the encryption keys the attacker is using while the attack is running. If files\nget encrypted anyway, they can be decrypted from the captured material rather than restored\nfrom a backup or bought back from the operator.\n\nThat is a different bet from every other product on this page. Detection assumes you catch\nit; this assumes you sometimes will not." }, { "heading": "

What else it watches

",
"body": "Vulnerable driver abuse, which is how attackers disable security tools from the kernel.\nTampering with the security agents themselves, Microsoft Defender and CrowdStrike and\nSentinelOne and Cortex among them, on the reasoning that the first move against an endpoint\nis often against its guard. Living-off-the-land activity through PowerShell and WMIC, and\nvolume shadow copies, which ransomware deletes before it encrypts so that the local\nrecovery path is gone.\n\nAnd exfiltration, because double extortion means the encryption is only half the incident." }, { "heading": "

What to check before it goes on the list

",
"body": "Two things, and neither is technical.\n\nThe vendor runs a Ransomware Operations Center and includes it, and offers a warranty that\nits people will help you recover if an attack succeeds. Both are worth reading in the\ncontract rather than on the website, because what “help you recover” covers is the whole\nquestion.\n\nThe second is overlap. This is a second agent on every endpoint next to an EDR that already\nclaims ransomware coverage. The case for it rests on the recovery layer being real, so that\nis the part to test rather than the detection rate." } ], "status": { "corpus": 309, "services": [ { "ref": "services/modern-workplace", "score": "0.39" }, { "ref": "services/security", "score": "0.34" } ], "posts": [ { "ref": "posts/exagrid", "score": "0.57" }, { "ref": "posts/how-to-scality-artesca", "score": "0.37" }, { "ref": "posts/icas-fs", "score": "0.37" }, { "ref": "posts/sichere-backups-mit-blocky-for-veeam", "score": "0.37" }, { "ref": "posts/veeam-und-s3-storage-mit-artesca", "score": "0.37" }, { "ref": "posts/securing-your-data-with-veeam-surebackup", "score": "0.37" } ], "neighbours": [ { "ref": "solutions/endpoint-security", "score": "0.78" }, { "ref": "solutions/igel/addon/90meter", "score": "0.48" }, { "ref": "solutions/endpoint-security/vmware-carbon-black", "score": "0.48" } ] }}
apiVersion = "soultec.ch/v1"kind = "Solution"[metadata]name = "endpoint-security/halcyon"locale = "en"[metadata.labels]vendor = "Halcyon Anti-Ransomware Platform""capability/endpoint-security" = "2.85""capability/security" = "2.01""capability/backup-recovery" = "2.21""vendor/halcyon" = "5.05"[metadata.annotations]source = "src/content/solutions/en/endpoint-security/halcyon.md"route = "/en/solutions/endpoint-security/halcyon/"schema = "/nerd/schema/solutions.json"markdown = "/en/solutions/endpoint-security/halcyon.md"[spec]title = "Halcyon"tags = ["endpoint-security", "security", "backup-recovery"]vendors = ["halcyon"]summary = "Built for one attack and nothing else. It does not replace an EDR, it sits beside one and assumes the ransomware got past it."photoNeed = "A security console on screen with real alerts in it, being triaged"stub = falsedraft = falsekind = "product"addon = falsesourceNote = "halcyon.ai platform pages, read 2026-08-30, for the capabilities, the Ransomware Operations Center and the warranty"vendorName = "Halcyon Anti-Ransomware Platform"status = "current"[[sections]]heading = "

What it is

"
body = '''Halcyon is an anti-ransomware platform, and it is worth being precise about that phrase.It is not endpoint protection, it is not detection and response, and it is not a backupproduct. It is one layer aimed at one attack, and its own argument is that it covers thegap between an EPP and an EDR rather than replacing either.The engine is trained on ransomware behaviour specifically: the process injections, theencryption routines, the exfiltration patterns that ransomware operators use, rather thanon malware generally.'''[[sections]]heading = "

The part that is genuinely different

"
body = '''**It assumes it will lose.** Alongside the prevention layers sits a resiliency layer thatcaptures the encryption keys the attacker is using while the attack is running. If filesget encrypted anyway, they can be decrypted from the captured material rather than restoredfrom a backup or bought back from the operator.That is a different bet from every other product on this page. Detection assumes you catchit; this assumes you sometimes will not.'''[[sections]]heading = "

What else it watches

"
body = '''Vulnerable driver abuse, which is how attackers disable security tools from the kernel.Tampering with the security agents themselves, Microsoft Defender and CrowdStrike andSentinelOne and Cortex among them, on the reasoning that the first move against an endpointis often against its guard. Living-off-the-land activity through PowerShell and WMIC, andvolume shadow copies, which ransomware deletes before it encrypts so that the localrecovery path is gone.And exfiltration, because double extortion means the encryption is only half the incident.'''[[sections]]heading = "

What to check before it goes on the list

"
body = '''Two things, and neither is technical.The vendor runs a Ransomware Operations Center and includes it, and offers a warranty thatits people will help you recover if an attack succeeds. Both are worth reading in thecontract rather than on the website, because what “help you recover” covers is the wholequestion.The second is overlap. This is a second agent on every endpoint next to an EDR that alreadyclaims ransomware coverage. The case for it rests on the recovery layer being real, so thatis the part to test rather than the detection rate.'''[status]corpus = 309[[status.services]]ref = "services/modern-workplace"score = "0.39"[[status.services]]ref = "services/security"score = "0.34"[[status.posts]]ref = "posts/exagrid"score = "0.57"[[status.posts]]ref = "posts/how-to-scality-artesca"score = "0.37"[[status.posts]]ref = "posts/icas-fs"score = "0.37"[[status.posts]]ref = "posts/sichere-backups-mit-blocky-for-veeam"score = "0.37"[[status.posts]]ref = "posts/veeam-und-s3-storage-mit-artesca"score = "0.37"[[status.posts]]ref = "posts/securing-your-data-with-veeam-surebackup"score = "0.37"[[status.neighbours]]ref = "solutions/endpoint-security"score = "0.78"[[status.neighbours]]ref = "solutions/igel/addon/90meter"score = "0.48"[[status.neighbours]]ref = "solutions/endpoint-security/vmware-carbon-black"score = "0.48"
<?xml version="1.0" encoding="UTF-8"?><manifest kind="Solution"> <apiVersion>soultec.ch/v1</apiVersion> <metadata> <name>endpoint-security/halcyon</name> <locale>en</locale> <labels> <vendor>Halcyon Anti-Ransomware Platform</vendor> <entry key="capability/endpoint-security">2.85</entry> <entry key="capability/security">2.01</entry> <entry key="capability/backup-recovery">2.21</entry> <entry key="vendor/halcyon">5.05</entry> </labels> <annotations> <source>src/content/solutions/en/endpoint-security/halcyon.md</source> <route>/en/solutions/endpoint-security/halcyon/</route> <schema>/nerd/schema/solutions.json</schema> <markdown>/en/solutions/endpoint-security/halcyon.md</markdown> </annotations> </metadata> <spec> <title>Halcyon</title> <tags> <item>endpoint-security</item> <item>security</item> <item>backup-recovery</item> </tags> <vendors> <item>halcyon</item> </vendors> <summary>Built for one attack and nothing else. It does not replace an EDR, it sits beside one and assumes the ransomware got past it.</summary> <photoNeed>A security console on screen with real alerts in it, being triaged</photoNeed> <stub>false</stub> <draft>false</draft> <kind>product</kind> <addon>false</addon> <sourceNote>halcyon.ai platform pages, read 2026-08-30, for the capabilities, the Ransomware Operations Center and the warranty</sourceNote> <vendorName>Halcyon Anti-Ransomware Platform</vendorName> <status>current</status> </spec> <sections> <section> <heading>

What it is

</heading>
<body>Halcyon is an anti-ransomware platform, and it is worth being precise about that phrase.It is not endpoint protection, it is not detection and response, and it is not a backupproduct. It is one layer aimed at one attack, and its own argument is that it covers thegap between an EPP and an EDR rather than replacing either.The engine is trained on ransomware behaviour specifically: the process injections, theencryption routines, the exfiltration patterns that ransomware operators use, rather thanon malware generally. </body> </section> <section> <heading>

The part that is genuinely different

</heading>
<body>**It assumes it will lose.** Alongside the prevention layers sits a resiliency layer thatcaptures the encryption keys the attacker is using while the attack is running. If filesget encrypted anyway, they can be decrypted from the captured material rather than restoredfrom a backup or bought back from the operator.That is a different bet from every other product on this page. Detection assumes you catchit; this assumes you sometimes will not. </body> </section> <section> <heading>

What else it watches

</heading>
<body>Vulnerable driver abuse, which is how attackers disable security tools from the kernel.Tampering with the security agents themselves, Microsoft Defender and CrowdStrike andSentinelOne and Cortex among them, on the reasoning that the first move against an endpointis often against its guard. Living-off-the-land activity through PowerShell and WMIC, andvolume shadow copies, which ransomware deletes before it encrypts so that the localrecovery path is gone.And exfiltration, because double extortion means the encryption is only half the incident. </body> </section> <section> <heading>

What to check before it goes on the list

</heading>
<body>Two things, and neither is technical.The vendor runs a Ransomware Operations Center and includes it, and offers a warranty thatits people will help you recover if an attack succeeds. Both are worth reading in thecontract rather than on the website, because what “help you recover” covers is the wholequestion.The second is overlap. This is a second agent on every endpoint next to an EDR that alreadyclaims ransomware coverage. The case for it rests on the recovery layer being real, so thatis the part to test rather than the detection rate. </body> </section> </sections> <status> <corpus>309</corpus> <services> <item> <ref>services/modern-workplace</ref> <score>0.39</score> </item> <item> <ref>services/security</ref> <score>0.34</score> </item> </services> <posts> <item> <ref>posts/exagrid</ref> <score>0.57</score> </item> <item> <ref>posts/how-to-scality-artesca</ref> <score>0.37</score> </item> <item> <ref>posts/icas-fs</ref> <score>0.37</score> </item> <item> <ref>posts/sichere-backups-mit-blocky-for-veeam</ref> <score>0.37</score> </item> <item> <ref>posts/veeam-und-s3-storage-mit-artesca</ref> <score>0.37</score> </item> <item> <ref>posts/securing-your-data-with-veeam-surebackup</ref> <score>0.37</score> </item> </posts> <neighbours> <item> <ref>solutions/endpoint-security</ref> <score>0.78</score> </item> <item> <ref>solutions/igel/addon/90meter</ref> <score>0.48</score> </item> <item> <ref>solutions/endpoint-security/vmware-carbon-black</ref> <score>0.48</score> </item> </neighbours> </status></manifest>
Solution · Halcyon

Halcyon

The vendor calls it: Halcyon Anti-Ransomware Platform

Built for one attack and nothing else. It does not replace an EDR, it sits beside one and assumes the ransomware got past it.

Topics Endpoint Security 2.85 Security 2.01 Backup and Recovery 2.21
Vendors Halcyon 5.05
02Services
06Posts
03Capabilities
309Corpus

What it is

Halcyon is an anti-ransomware platform, and it is worth being precise about that phrase. It is not endpoint protection, it is not detection and response, and it is not a backup product. It is one layer aimed at one attack, and its own argument is that it covers the gap between an EPP and an EDR rather than replacing either.

The engine is trained on ransomware behaviour specifically: the process injections, the encryption routines, the exfiltration patterns that ransomware operators use, rather than on malware generally.

The part that is genuinely different

It assumes it will lose. Alongside the prevention layers sits a resiliency layer that captures the encryption keys the attacker is using while the attack is running. If files get encrypted anyway, they can be decrypted from the captured material rather than restored from a backup or bought back from the operator.

That is a different bet from every other product on this page. Detection assumes you catch it; this assumes you sometimes will not.

What else it watches

Vulnerable driver abuse, which is how attackers disable security tools from the kernel. Tampering with the security agents themselves, Microsoft Defender and CrowdStrike and SentinelOne and Cortex among them, on the reasoning that the first move against an endpoint is often against its guard. Living-off-the-land activity through PowerShell and WMIC, and volume shadow copies, which ransomware deletes before it encrypts so that the local recovery path is gone.

And exfiltration, because double extortion means the encryption is only half the incident.

What to check before it goes on the list

Two things, and neither is technical.

The vendor runs a Ransomware Operations Center and includes it, and offers a warranty that its people will help you recover if an attack succeeds. Both are worth reading in the contract rather than on the website, because what “help you recover” covers is the whole question.

The second is overlap. This is a second agent on every endpoint next to an EDR that already claims ransomware coverage. The case for it rests on the recovery layer being real, so that is the part to test rather than the detection rate.

Posts about it

Who works with it

Do you work with this? Take a look at our open roles.