Ransomware, Encryption

New file resilience tool stops ransomware before files are encrypted

key on monitor screen, cybersecurity concept

Halcyon has launched File Resilience, a new capability that stops ransomware encryption before files are modified. Operating at the Windows kernel level, it monitors the sequence of actions ransomware must take to encrypt data and terminates the process as the attack begins. Halcyon said the approach is designed to work against known ransomware variants as well as previously unseen attacks that may not have an existing signature. Once an encryption attempt is blocked, the company’s 24/7 Ransomware Operations Center investigates the incident, contains the threat, and works to remove the attacker from the environment.

Moving ransomware defense ahead of recovery

File Resilience adds a preventive layer to Halcyon’s existing ransomware recovery capabilities. The company’s rollback technology captures encryption key material during an attack and uses it to decrypt affected files directly, rather than relying on backups or shadow copies that attackers may delete.

Seth Geftic, Halcyon Head of Marketing at Halycon told MSSP Alert, “Halcyon’s existing rollback doesn’t use backups. It captures the ransomware’s encryption key material during the attack and uses it to decrypt files directly. But it’s still reactive. Recovery happens after encryption, and without eviction, the attackers are still on the network and can simply re-encrypt the device.”

File Resilience is designed to act earlier in the attack. According to Halcyon, it serves as the first layer in a three-part approach that stops encryption, limits the blast radius, and captures key material for recovery.

“File Resilience sits earlier, with kernel-level, real-time detection that stops encryption as it happens,” Geftic said. “Key capture and decryption remain the safety net behind it, with no backups required either way.”

The shift matters because encryption is often the point where a ransomware incident turns into a business disruption. Stopping that process can keep systems and files available while responders investigate how the attacker entered the environment and what access remains.

Microsoft integrations bring response into existing workflows

Halcyon also announced native macOS support, scheduled for general availability in August, along with expanded integrations for Microsoft Defender and Microsoft Sentinel. The Microsoft integrations are available now and are designed to bring Halcyon alerts and response activity into security workflows that customers already use.

For Microsoft Defender customers, Halcyon continuously monitors the health and integrity of the endpoint security platform, including attempts to disable or bypass it. Halcyon can also trigger Defender response actions, such as isolating a compromised host.

“Halcyon backstops Defender itself,” Geftic said. “If Defender is tampered with or disabled, Halcyon keeps detecting and blocking ransomware independently.”

The Defender integration also allows analysts in Halcyon’s Ransomware Operations Center to isolate Defender-managed assets directly from the Halcyon console during an active incident. That can reduce the need to move between separate security tools while an attack is underway.

The Sentinel integration sends Halcyon events and alerts into Microsoft Sentinel in near real time. The data is mapped to Microsoft’s Advanced Security Information Model, allowing security teams to query it using Kusto Query Language and incorporate it into existing investigations, analytics and response workflows.

The integrations allow customers to add Halcyon without replacing their Microsoft security tools. Halcyon can operate alongside Defender and Sentinel while adding controls focused specifically on ransomware encryption, recovery, and response.

Blocking encryption does not end the attack

Preventing file encryption addresses one part of a ransomware incident. Attackers may still have stolen data, gained privileged access, or established persistence elsewhere in the network.

Halcyon said its Data Exfiltration Protection capability operates continuously to detect and stop potential data theft, including activity identified through DNS and volumetric monitoring.

“Once encryption is blocked, the attacker may still have stolen data or gained privileged access,” Geftic said. “Our Data Exfiltration Protection runs 24/7 to identify and halt potential exfiltration, with an immediate investigation when suspicious activity is detected.”

Halcyon’s eviction workflows run alongside forensic investigations and are designed specifically for ransomware incidents. The company said the workflows automate containment tasks, allowing responders to spend more time examining the cause of the breach, identifying affected systems and removing the attacker’s access.

“The Halcyon ROC investigates and disrupts the attack, leads recovery and works to fully evict the attacker,” Geftic said. “That includes decrypting affected data using captured key material when files have already been encrypted.”

By pairing kernel-level blocking with Microsoft integrations, data exfiltration monitoring and human-led response, Halcyon is trying to reduce both the operational damage of ransomware and the time required to remove an attacker from the environment. However, the broader value of File Resilience will depend on whether it can stop encryption without disrupting legitimate activity and whether security teams can move quickly from prevention to full containment.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds