AI Detects. Blockchain Recovers.
A decentralized daemon that monitors file entropy in real-time, freezes
ransomware mid-attack, and recovers from an immutable IPFS blockchain vault.
A decentralized daemon that monitors file entropy in real-time, freezes
ransomware mid-attack, and recovers from an immutable IPFS blockchain vault.
Real-time sub-millisecond telemetry, process isolation kill switch, and IPFS recovery status.
Generate automated high-entropy ransomware files or upload/drop suspicious files to trigger the AI Brain kill switch & recovery alert.
Click below to automatically create a high-entropy encrypted test file (ransomware_payload.locked) with random XOR byte noise ($H(X) \ge 7.92$).
Drag any file here or click to browse to test automated detection.
Type plain text below to calculate entropy live. Click Encrypt with Ransomware XOR to simulate an encryption loop and watch entropy jump from ~3.4 to ~7.95+!
H(X) = - ∑ P(xᵢ) · log₂ P(xᵢ)
Shannon entropy measures byte randomness in a file. Plain text possesses structured byte distributions (~3.0–4.5). Encrypted ransomware files exhibit uniform random byte frequencies, driving entropy to ~7.9+.
Explore the smart contract logic and trigger on-chain emergency state transitions on Polygon Amoy testnet.
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;
contract AutoVaultRecovery {
string public latestCleanCID;
address public authorizedAgent;
bool public isCompromised;
event LockdownTriggered(string cid, uint256 timestamp);
constructor(string memory _initialCID) {
latestCleanCID = _initialCID;
authorizedAgent = msg.sender;
isCompromised = false;
}
function triggerEmergencyLockdown() external {
require(msg.sender == authorizedAgent, "Unauthorized");
isCompromised = true;
emit LockdownTriggered(latestCleanCID, block.timestamp);
}
function restoreSystem() external {
require(msg.sender == authorizedAgent, "Unauthorized");
isCompromised = false;
}
}
Test on-chain state execution directly from the web dashboard. Emits smart contract events and pins clean recovery hashes to IPFS.
Understand how AutoVault detects, isolates, and recovers from ransomware step-by-step.
Ransomware encrypts your files and demands money. AutoVault is an intelligent background daemon that monitors file randomness (entropy), stops ransomware in under 200 milliseconds, and restores clean file snapshots from the blockchain.
Normal text and files are structured and predictable (Entropy ~ 3.5). Encrypted ransomware files convert content into random noise (Entropy ~ 7.9+). AutoVault detects this sudden jump instantly!
Humans modify a few files per minute. Ransomware attempts to modify hundreds of files per second. AutoVault monitors file write operations per second to catch rapid encryption loops.
When an attack is flagged, AutoVault calls Windows SuspendThread to freeze the ransomware process mid-encryption and enforces Windows Firewall rules to block network connections.
Normal cloud backups can be deleted if a hacker gains admin privileges. AutoVault stores encrypted clean file snapshots on IPFS and Polygon Smart Contracts. Because blockchain is immutable, no hacker can delete your recovery point!