Halcyon Anti-Ransomware: the last line of defence
Halcyon is a dedicated anti-ransomware platform that steps in where EDR, XDR and backups fall short: at the moment of encryption. It detects ransomware behaviour at the kernel, blocks encryption in real time and restores affected files if an attacker still breaks through. ANOMAL runs Halcyon embedded in the SOC service, with 24/7 response and evidence artefacts that regulator and insurer accept.
The gap Halcyon closes
EDR and XDR detect attacker behaviour. Backups restore data. Between the two sits the window where encryption happens, often in minutes, often outside business hours. Halcyon addresses precisely that window. It complements EDR and backup with a layer specialising in a single attack behaviour: ransomware.
Halcyon runs alongside the existing EDR and within the SOC service. For EDR and MDR fundamentals, see [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland). For the distinction between tools and services, see [EDR vs. MDR](/en/soc/soc-siem-edr-xdr-mdr-terms).
How Halcyon works
- Kernel-adjacent sensors detect the behavioural patterns of encryption before files are written at scale.
- Halcyon stops suspicious processes during write operations, regardless of signatures or prior knowledge of the ransomware family.
- If encryption still starts, Halcyon captures the attacker's encryption key material during the attack. It uses this material to decrypt affected files back to their original state.
- All actions flow as events into the SOC playbook: isolation, investigation, customer communication, reporting.
Operated by ANOMAL
Halcyon's licence requires technology and service as a bundle, including Halcyon's own Ransomware Operations Center (ROC/RDR team). Halcyon technology is not available separately. ANOMAL acts as the intermediary: one point of contact, one contract, one escalation chain. In an incident, the Halcyon team works as a specialist unit within our SOC response.
- ANOMAL is the customer's single point of contact. There are no two parallel contact paths to Halcyon and ANOMAL.
- In a ransomware incident, ANOMAL integrates Halcyon's ROC into the SOC response chain. Triage, isolation and communication stay in the ANOMAL playbook.
- Halcyon is therefore a SOC-extended add-on. ANOMAL contractually bundles licence and service into the existing SOC framework, with one contract, one escalation chain and consolidated reporting.
- The contract defines response authority in the customer tenant (isolation, user account disabling, EDR configuration).
- ANOMAL provides exportable detection and restoration evidence for each incident. Integration with identity, cloud and SIEM uses the existing SOC data path.
- On top of the Halcyon licence, ANOMAL delivers one tabletop exercise per year specifically for ransomware scenarios with the customer's crisis team.
Who Halcyon is relevant for
- Organisations whose business model does not survive a recovery window beyond 24 hours.
- Environments with high endpoint diversity and slow backup-restore times (manufacturing, healthcare, law firms).
- Companies under cyber-insurance requirements that expect documented response and first notification within 72 hours. Context on Cyber insurance.
- Regulated sectors that require both backups and proof that encryption was stopped.
How this compares to EDR, XDR and backup
| Layer | Purpose | Boundary |
|---|---|---|
| EDR | Detection of attacker behaviour on the endpoint | Reacts to attacker behaviour in general; encryption bursts are not its specific focus |
| XDR | Correlation across endpoint, identity, cloud | Platform visibility; lacks dedicated encryption blocking |
| Backup | Recovery after data loss | Only after the fact, often with hours to days of restore time |
| Halcyon | Blocking and decryption using captured key material at the moment of encryption | Complements backup and EDR by closing the gap between them |
For criteria to compare the data coverage of a complete SOC, see SOC provider comparison.
Frequently asked questions
Does Halcyon replace our existing EDR?
Halcyon complements your existing EDR. EDR remains the base layer for detection and response across all attacker behaviour. Halcyon is a specialised layer for ransomware. Reliable protection requires both together.
Do we need Halcyon if we have immutable backups?
Immutable backups restore data after encryption has occurred. How long can the business tolerate a restore? Will the regulator or insurer accept 'we restored from backup' as the full answer?
What happens on a false positive?
Halcyon initially stops the process, and the SOC triages the alert. During onboarding, ANOMAL configures exceptions for legitimate applications requiring broad write operations, including backup agents, encryption tools and database engines. Ongoing detection tuning maintains this balance.
Is Halcyon only relevant for large environments?
Halcyon's value depends on how long the business can tolerate an outage. An SME whose production becomes critical after two days without systems benefits more than a large enterprise with a multi-day restore window.
How does Halcyon integrate with existing contracts?
Halcyon is a SOC-extended add-on. The licence and Halcyon's ROC service form a mandatory bundle, which ANOMAL contractually integrates into the existing SOC framework. The customer has one contract, one escalation chain and consolidated reporting. During a ransomware incident, Halcyon's ROC works as a specialist unit within our response. ANOMAL remains the customer's single point of contact.
Related terms
- Ransomware Ransomware is malicious software that encrypts data and demands a ransom for decryption.
- Incident Response Incident Response is the structured process of containing, eradicating, and recovering from a security incident.
- EDR Endpoint Detection and Response (EDR) monitors activities on devices like laptops and servers, enabling intervention during attacks.
- Malware Malware is the umbrella term for malicious software such as ransomware, Trojans or infostealers that damage systems or steal data.