ᐅASPIDA PROJECT


Technical Brief

When an actor falls victim to ransomware, the reaction is fragmented: separate consoles for detection, forensics, backup recovery, with manual transfer of information. Business operations stop for 8-24 hours, with a re-infection rate of 15-20% (Mandiant, Sophos), lack of uniform documentation for NIS2 audits, and dependence on foreign proprietary platforms under CLOUD Act jurisdiction.

ASPIDA — Automated Security, Protection, Incident response & Disaster recovery Architecture — is an open source-first orchestration framework that consolidates the three critical cycles: Detection, Recovery, Business Continuity. It leverages mature open source tools — Wazuh for XDR detection, Velociraptor for forensic acquisition, MISP for threat intelligence with CERT-GR/ENISA compatibility, Suricata and Zeek for network monitoring, OpenCanary for early ransomware tripwires, TheHive 5 for case management — with Acronis Cyber Protect for enterprise-grade Disaster Recovery.

How it works: Canary files with “AAA_” prefix are placed in critical directories. When ransomware initiates encryption, it touches the canary files first — Wazuh FIM detects the change in less than 3 seconds. The AI Intelligence Layer calculates confidence score and automatically activates three parallel flows: immediate failover to isolated Acronis DR site so that the service can continue in minutes, automatic Velociraptor forensic acquisition on the original server that remains intact as evidence, and activation of Business Continuity playbooks with stakeholder notifications.

The core innovation is the Forensic-Validated Recovery Algorithm (FVR): it exports IoCs with first-seen timestamps, calculates the Estimated Compromise Time, filters out backup points that precede infection, and selects the recovery point with a higher integrity score — reducing the re-infection rate from 15-20% to less than 2%. The Business Impact Correlation Engine (BICE) translates technical events into real-time business impact through hierarchical service catalog, defining business-prioritized failover sequence and automatically triggering the corresponding BC processes per process.

ASPIDA adopts an open source-first architecture for complete auditability without dependence on foreign proprietary platforms. Unlike American solutions that operate under CLOUD Act jurisdiction with closed source code, ASPIDA runs on-premise in Greece. Through MISP integration, it connects directly to CERT-GR and ENISA for automatic threat intelligence sharing — receiving new IoCs and sharing findings after each incident for collective national defence.

During and after the incident, ASPIDA automatically generates the full NIS2 evidence package: immutable timeline of each action with timestamps, chain-of-custody for forensic evidence, and ready report for CERT-GR within 24 hours — covering over 95% of regulatory requirements without manual intervention.

Objectives: ransomware detection in less than 3 seconds (from 5-30 minutes), RTO less than 15 minutes (from 8-24 hours), re-infection less than 2%, auto-generated NIS2 evidence over 95%. It was designed by SOC engineers with hands-on experience in the stack.

Project Creators

Athanasios Solakidis

Fotis Tourtouras

Founder's Profile

email: info@profitapp.net

FCC Registration Number (FRN): 0030961676