Halcyon is an enterprise cyber resilience platform built by Halcyon Tech, Inc. specifically to defeat ransomware. Founded in 2021 by Jon Miller and Ryan Smith, security industry veterans from firms later acquired by Blackberry and Optiv, the company built a platform dedicated entirely to ransomware rather than general malware defense.
The platform deploys a lightweight endpoint agent alongside existing EDR and EPP tools such as CrowdStrike Falcon, SentinelOne, and Microsoft Defender for Endpoint. It targets a specific weakness in traditional EDR: attackers who bypass credentials, unhook security agents, or deploy zero-day payloads before encryption completes.
Halcyon’s agent uses ransomware-specific machine learning micro-models to halt malicious execution, intercept data exfiltration, extract encryption keys from system memory, and isolate compromised endpoints in real time. Captured keys allow security teams to decrypt files without negotiating with attackers.
As of 2026, Halcyon backs the platform with a Ransomware Warranty and a 24/7 Ransomware Operations Center (ROC), providing expert-led incident response at no extra charge if an attack does bypass its defenses. The company has raised $84 million in venture funding to date, including a $44 million Series A round in 2023 and a $40 million Series B round led by Bain Capital Ventures.
Pricing
Halcyon does not publish pricing, plan tiers, or free trial details on its website. Cost is quote-based and depends on endpoint volume and deployment requirements. Organizations must contact the Halcyon sales team directly to obtain a custom quote, and there is no self-serve or free plan available.
* Disclaimer: Please note that pricing information may not be up to date. For the most accurate and current pricing details, refer to the official website.
Key Features
- ✓
Automated encryption key capture directly from memory for instant decryption
- ✓
Anti-evasion protection that prevents attackers from disabling EDR agents
- ✓
Behavior-based micro-models that block ransomware before execution begins
- ✓
Automated endpoint isolation and exfiltration blocking during active attacks
- ✓
Ransomware Warranty backed by a 24/7 Ransomware Operations Center
Use Cases
Decrypting Files Without Paying Ransom
When a ransomware strain executes, Halcyon extracts the active encryption key from memory during the attack. Security teams can reverse file encryption across affected devices without contacting or paying attackers.
Shielding EDR Agents From Evasion
Attackers often disable EDR agents before dropping ransomware payloads. Halcyon protects the underlying security stack by intercepting unhooking and tampering attempts against installed tools.
Stopping Double-Extortion Data Theft
Modern ransomware groups steal data before encrypting drives to increase leverage. Halcyon detects abnormal bulk exfiltration patterns tied to ransomware staging and cuts the connection.
Containing Active Endpoint Breaches
During an outbreak, SOC teams need immediate isolation to stop lateral spread. Halcyon automatically quarantines compromised hosts while keeping telemetry channels active for investigation.
Reducing Downtime in Critical Infrastructure
Healthcare and utility organizations face severe risk from extended outages during backup restoration. Halcyon shortens recovery time by decrypting affected volumes locally instead of re-imaging systems.
Strengths & Weaknesses
Strengths
Purpose-built architecture focused specifically on ransomware detection and recovery.
Runs alongside major EDR/EPP platforms like CrowdStrike, SentinelOne, and Microsoft Defender without agent conflicts.
Captures encryption keys in real time to enable file decryption without paying ransom.
Backed by a Ransomware Warranty and a 24/7 Ransomware Operations Center for incident response.
Has raised $84 million in venture funding, including a Series B led by Bain Capital Ventures.
Weaknesses
Public pricing, plan tiers, and trial details are not available online.
Narrowly focused on ransomware rather than serving as a full-spectrum security platform.
Vendor compatibility details for smaller third-party IT tools are not fully published.
Adds an additional endpoint agent footprint alongside existing security software.
Who Is This For?
Enterprise SOC teams needing ransomware-specific telemetry, anti-evasion alerts, and automated key management to cut manual response work.
Critical infrastructure and healthcare organizations that cannot tolerate extended outages from ransomware-driven downtime.
CISOs managing financial and insurance exposure tied to double-extortion ransomware attacks.
MSSPs and incident responders who need an add-on protection layer for rapid remediation during active breaches.
Frequently Asked Questions
Does Halcyon replace existing antivirus or EDR solutions?
No. Halcyon is designed to run alongside existing EDR and EPP platforms, filling gaps around ransomware execution, agent tampering, and key recovery.
How does Halcyon recover encrypted files without offsite backups?
Halcyon captures encryption keys directly from system memory while the ransomware process runs, enabling automated decryption of locked files.
Is Halcyon’s pricing available publicly?
No. Halcyon uses custom enterprise licensing based on endpoint count and organization requirements, quoted directly by the sales team.
Can Halcyon stop novel or zero-day ransomware strains?
Yes. Halcyon relies on behavior-based micro-models rather than signature databases, so it can flag previously unseen ransomware techniques.
Does Halcyon offer an API for SIEM or SOAR integration?
Yes, third-party listings confirm Halcyon offers an API, though the vendor does not publish a full integrations list beyond named EDR partners.
What is the Halcyon Ransomware Warranty?
If an attack bypasses Halcyon’s defenses, the company provides expert-led incident response and recovery services at no extra charge through its 24/7 Ransomware Operations Center.
How much funding has Halcyon raised?
Halcyon has raised $84 million total, including a $44 million Series A in 2023 and a $40 million Series B led by Bain Capital Ventures.
Does Halcyon block data exfiltration?
Yes. Halcyon monitors outbound data flows to detect and disrupt exfiltration attempts tied to double-extortion ransomware tactics.
Who founded Halcyon and when?
Halcyon was founded in 2021 by Jon Miller and Ryan Smith, both previously at security firms later acquired by Blackberry and Optiv.
Halcyon runs side-by-side with CrowdStrike Falcon, SentinelOne, and Microsoft Defender for Endpoint, and is listed on Microsoft Azure Marketplace. Third-party sources confirm API availability for external data export, though Halcyon does not publish a complete integrations catalog on its own site.