Halcyon Tech, Inc.: Halcyon
What its stage means
An independent assessor found the provider ready to pursue an authorization. It is not an authorization.
The provider's description
Halcyon's Anti-Ransomware Platform is an agent-based Software as a Service (SaaS) deployment that provides multiple layers of protection against ransomware attacks while complementing existing Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) solutions. The platform leverages machine learning (ML) models trained specifically to identify and disrupt ransomware activity. The solution consists of a lightweight endpoint agent that combines multiple proprietary prevention engines with ML models designed exclusively to detect ransomware throughout the attack lifecycle. The SaaS platform provides centralized policy management, security event visibility, reporting, administrative functions, and APIs, and is designed to integrate with existing security technologies and operational workflows.
Halcyon incorporates a capsule network-based machine learning architecture with the following characteristics:
Collaborative decision-making in which individual ML models communicate with one another and provide weighted decisions to improve detection accuracy. The ability to learn and make highly accurate detection decisions using less training data than traditional convolutional neural network approaches.
Telemetry collected from protected endpoints is analyzed through multiple detection engines to evaluate process behavior over time, enabling the identification of suspicious or malicious ransomware activity. The platform supports automated response actions, including endpoint isolation, to contain ransomware activity and captures ransomware encryption key material, when available, to support recovery of encrypted data.
Halcyon Data Exfiltration Protection (DXP)
The Halcyon Data Exfiltration Protection (DXP) module extends the Anti-Ransomware Platform by detecting ransomware-related data exfiltration activity associated with double-extortion attacks. DXP analyzes network communications and process behavior to identify suspicious data movement that may indicate active ransomware operations.
DXP Capabilities: -Detects ransomware-related data exfiltration activity before sensitive information is transmitted outside the environment. -Supports detection and disruption of ransomware-related data theft associated with extortion campaigns. -Provides early indication of active threat actor activity to support investigation and containment. -Analyzes process behavior to improve detection accuracy while reducing false positives. -Integrates with supported EDR and XDR platforms to enhance response and investigation workflows.
Ransomware Operations Center (ROC)
As part of the Halcyon Anti-Ransomware Platform, the Ransomware Operations Center (ROC) provides continuous monitoring and operational support for ransomware-related activity. The ROC reviews platform-generated detections, validates ransomware events, supports investigation, containment, recovery, and response coordination with authorized customer personnel. The ROC leverages telemetry generated by the Halcyon platform to support ransomware monitoring, response, and recovery operations on a 24x7x365 basis.
What FedXchange has recorded
Halcyon from Halcyon Tech, Inc. is new on the Marketplace, listed as FedRAMP Ready.