What it is
Halcyon is an anti-ransomware platform, and it is worth being precise about that phrase. It is not endpoint protection, it is not detection and response, and it is not a backup product. It is one layer aimed at one attack, and its own argument is that it covers the gap between an EPP and an EDR rather than replacing either.
The engine is trained on ransomware behaviour specifically: the process injections, the encryption routines, the exfiltration patterns that ransomware operators use, rather than on malware generally.
The part that is genuinely different
It assumes it will lose. Alongside the prevention layers sits a resiliency layer that captures the encryption keys the attacker is using while the attack is running. If files get encrypted anyway, they can be decrypted from the captured material rather than restored from a backup or bought back from the operator.
That is a different bet from every other product on this page. Detection assumes you catch it; this assumes you sometimes will not.
What else it watches
Vulnerable driver abuse, which is how attackers disable security tools from the kernel. Tampering with the security agents themselves, Microsoft Defender and CrowdStrike and SentinelOne and Cortex among them, on the reasoning that the first move against an endpoint is often against its guard. Living-off-the-land activity through PowerShell and WMIC, and volume shadow copies, which ransomware deletes before it encrypts so that the local recovery path is gone.
And exfiltration, because double extortion means the encryption is only half the incident.
What to check before it goes on the list
Two things, and neither is technical.
The vendor runs a Ransomware Operations Center and includes it, and offers a warranty that its people will help you recover if an attack succeeds. Both are worth reading in the contract rather than on the website, because what “help you recover” covers is the whole question.
The second is overlap. This is a second agent on every endpoint next to an EDR that already claims ransomware coverage. The case for it rests on the recovery layer being real, so that is the part to test rather than the detection rate.