ANOMAL service

Halcyon Anti-Ransomware: the last line of defence

Halcyon is a dedicated anti-ransomware platform that steps in where EDR, XDR and backups fall short: at the moment of encryption. It detects ransomware behaviour at the kernel, blocks encryption in real time and restores affected files if an attacker still breaks through. ANOMAL runs Halcyon embedded in the SOC service, with 24/7 response and evidence artefacts that regulator and insurer accept.

All

The gap Halcyon closes

EDR and XDR detect attacker behaviour. Backups restore data. Between the two sits the window where encryption happens, often in minutes, often outside business hours. Halcyon addresses precisely that window. It complements EDR and backup with a layer specialising in a single attack behaviour: ransomware.

Not instead of EDR, but on top

Halcyon runs alongside the existing EDR and within the SOC service. For EDR and MDR fundamentals, see [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland). For the distinction between tools and services, see [EDR vs. MDR](/en/soc/soc-siem-edr-xdr-mdr-terms).

How Halcyon works

  • Kernel-adjacent sensors detect the behavioural patterns of encryption before files are written at scale.
  • Halcyon stops suspicious processes during write operations, regardless of signatures or prior knowledge of the ransomware family.
  • If encryption still starts, Halcyon captures the attacker's encryption key material during the attack. It uses this material to decrypt affected files back to their original state.
  • All actions flow as events into the SOC playbook: isolation, investigation, customer communication, reporting.

Operated by ANOMAL

Halcyon's licence requires technology and service as a bundle, including Halcyon's own Ransomware Operations Center (ROC/RDR team). Halcyon technology is not available separately. ANOMAL acts as the intermediary: one point of contact, one contract, one escalation chain. In an incident, the Halcyon team works as a specialist unit within our SOC response.

  • ANOMAL is the customer's single point of contact. There are no two parallel contact paths to Halcyon and ANOMAL.
  • In a ransomware incident, ANOMAL integrates Halcyon's ROC into the SOC response chain. Triage, isolation and communication stay in the ANOMAL playbook.
  • Halcyon is therefore a SOC-extended add-on. ANOMAL contractually bundles licence and service into the existing SOC framework, with one contract, one escalation chain and consolidated reporting.
  • The contract defines response authority in the customer tenant (isolation, user account disabling, EDR configuration).
  • ANOMAL provides exportable detection and restoration evidence for each incident. Integration with identity, cloud and SIEM uses the existing SOC data path.
  • On top of the Halcyon licence, ANOMAL delivers one tabletop exercise per year specifically for ransomware scenarios with the customer's crisis team.

Who Halcyon is relevant for

  • Organisations whose business model does not survive a recovery window beyond 24 hours.
  • Environments with high endpoint diversity and slow backup-restore times (manufacturing, healthcare, law firms).
  • Companies under cyber-insurance requirements that expect documented response and first notification within 72 hours. Context on Cyber insurance.
  • Regulated sectors that require both backups and proof that encryption was stopped.

How this compares to EDR, XDR and backup

LayerPurposeBoundary
EDRDetection of attacker behaviour on the endpointReacts to attacker behaviour in general; encryption bursts are not its specific focus
XDRCorrelation across endpoint, identity, cloudPlatform visibility; lacks dedicated encryption blocking
BackupRecovery after data lossOnly after the fact, often with hours to days of restore time
HalcyonBlocking and decryption using captured key material at the moment of encryptionComplements backup and EDR by closing the gap between them

For criteria to compare the data coverage of a complete SOC, see SOC provider comparison.

Frequently asked questions

Does Halcyon replace our existing EDR?

Halcyon complements your existing EDR. EDR remains the base layer for detection and response across all attacker behaviour. Halcyon is a specialised layer for ransomware. Reliable protection requires both together.

Do we need Halcyon if we have immutable backups?

Immutable backups restore data after encryption has occurred. How long can the business tolerate a restore? Will the regulator or insurer accept 'we restored from backup' as the full answer?

What happens on a false positive?

Halcyon initially stops the process, and the SOC triages the alert. During onboarding, ANOMAL configures exceptions for legitimate applications requiring broad write operations, including backup agents, encryption tools and database engines. Ongoing detection tuning maintains this balance.

Is Halcyon only relevant for large environments?

Halcyon's value depends on how long the business can tolerate an outage. An SME whose production becomes critical after two days without systems benefits more than a large enterprise with a multi-day restore window.

How does Halcyon integrate with existing contracts?

Halcyon is a SOC-extended add-on. The licence and Halcyon's ROC service form a mandatory bundle, which ANOMAL contractually integrates into the existing SOC framework. The customer has one contract, one escalation chain and consolidated reporting. During a ransomware incident, Halcyon's ROC works as a specialist unit within our response. ANOMAL remains the customer's single point of contact.

Continue reading in this cluster
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
SOC, SIEM, EDR, XDR, MDR: the terms explained
SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.
SOC and cyber insurance: what Swiss insurers require
Cyber insurers in Switzerland and the EU increasingly require applicants to evidence security controls. MFA, EDR, segregated backups, a documented incident response plan and a patch process appear on nearly every proposal form. Missing 24/7 detection via a managed SOC or MDR is rarely a formal exclusion. It is a strong premium driver and, in many policies, the only realistic way to meet short policy notification deadlines.
Comparing SOC providers: the neutral selection checklist
Comparing SOC providers works via verifiable criteria, not logos: data scope, response authority inside the customer tenant, evidence artefacts, response times and contract wording. This page lists the questions used to line offers up side by side. Deliberately without vendor names, so the checklist holds up even when ANOMAL is not on the shortlist.