MRI
MRI India Journals Vol. 14 No. 3s (2025): Special Issue: AIDCON-2025

AAROS (Aegis Active Response Operating System)

Authors

  • Heena Farheen Ansari Assistant Professor, Department of CSE (Cyber-Security), St. Vincent Pallotti College of Engineering & Technology, Nagpur, Maharashtra, India- 441108
  • Aayushi Salbarde Student, Department of CSE (Cyber-Security), St. Vincent Pallotti College of Engineering & Technology, Nagpur, Maharashtra, India- 441108
  • Ayush Benny Student, Department of CSE (Cyber-Security), St. Vincent Pallotti College of Engineering & Technology, Nagpur, Maharashtra, India- 441108
  • Rohit Nandanwar Student, Department of CSE (Cyber-Security), St. Vincent Pallotti College of Engineering & Technology, Nagpur, Maharashtra, India- 441108
  • Onkar Sinha Student, Department of CSE (Cyber-Security), St. Vincent Pallotti College of Engineering & Technology, Nagpur, Maharashtra, India- 441108
  • Shruti Bhande Student, Department of CSE (Cyber-Security), St. Vincent Pallotti College of Engineering & Technology, Nagpur, Maharashtra, India- 441108

DOI:

https://doi.org/10.65521/intjournalrecadvengtech.v14i3s.1653

Keywords:

Command and Control (C2) Sliver Framework AES Encryption Raspberry Pi Automation Adversary Emulation

Abstract

An AAROS (Aegis Active Response Operating System), a novel retaliatory red teaming tool designed to address the limitations of passive defensive security measures. The persistent threat of unauthorized access to sensitive data often leaves organizations with reactive, post-incident forensic analysis rather than proactive countermeasures. AAROS proposes a new paradigm by employing a low-cost Raspberry Pi, configured as a Human Interface Device (HID), to serve as a decoy system. The device hosts a sensitive data folder secured with strong cryptography, requiring correct credentials for access. The core functionality of AAROS is its retaliatory mechanism: upon the detection of failed credential attempts or unauthorized access, the HID automatically executes a pre-configured C2 (Command and Control) malware payload on the attacker's system. This action not only deters malicious actors but also establishes a connection to the attacker's machine, allowing for immediate control and intelligence gathering. Our methodology details the system architecture, hardware and software components, and the cryptographic and payload deployment mechanisms. The results demonstrate the viability of this approach in controlled test environments, confirming the device's ability to reliably detect unauthorized access and successfully deploy a C2 payload to gain control over the attacker's machine. AAROS provides a unique and effective strategy for red teaming, offering a proactive, real-time response that moves beyond traditional perimeter defenses and static detection systems.

Downloads

Download data is not yet available.

Downloads

Published

2025-12-23

How to Cite

Ansari, H. F., Salbarde, A., Benny, A., Nandanwar, R., Sinha, O., & Bhande, S. (2025). AAROS (Aegis Active Response Operating System). International Journal of Recent Advances in Engineering and Technology, 14(3s), 25–30. https://doi.org/10.65521/intjournalrecadvengtech.v14i3s.1653

Similar Articles

1 2 3 4 5 6 7 8 9 10 > >> 

You may also start an advanced similarity search for this article.