The Elastio platform
Investigate compromise. Make recovery decisions with evidence.
Elastio AI examines system copies and data outside the production host. Security teams get evidence to investigate. Recovery teams get a clearer basis for choosing what to restore.
Agentic compromise investigation.
Pursuit examines Windows machine images and snapshots for persistence mechanisms, exposed credentials, and signs of attacker activity. No agent is installed on the inspected host.
AI agents follow leads through files, code, configuration, and recorded activity. Findings explain the assessment, confidence, and source evidence, with paths, hashes, and timestamps where available.
Persistence investigationHigh confidence
This finding establishes a configured persistence mechanism. The examined windows did not establish execution.
- Anchor
- 2019-10-08T18:15:37Z
- Detected
- 2026-10-04T00:25:00Z
- Report
- pursuit-EC2AMAZ-SMASCMC-20261004
Gate 3 high: two validated IFEO debugger persistence entries set magnify.exe and sethc.exe Debugger to C:\windows\system32\cmd.exe. This is an attacker-relevant accessibility-backdoor mechanism. No execution telemetry was found in the bounded process/Security sources, so operational corroboration is limited. The separate EC2 password-rotation task and startup wallpaper scripts were inspected and remain low/benign context. No suspicious user-writable loaded driver or usable offensive framework was found.
- F-IFEO-001HIGHIFEO debugger persistence for accessibility binaries
- F-STARTUP-001LOWAmazon EC2 startup-folder scripts validated as expected
- F-TASK-001LOWAWS password-reset scheduled tasks
Gate 3: registry-backed Image File Execution Options Debugger values for magnify.exe and sethc.exe both redirect execution to C:\windows\system32\cmd.exe. This is attacker-relevant IFEO persistence and an accessibility/logon bypass mechanism. The target is a system command interpreter; no execution telemetry was recovered in the bounded windows around the writes.
- category
- ifeo_persistence
- persistence_type
- IFEO debugger
- assessment
- abused
- name
cmd.exe- reason
cmd.exeis the IFEO debugger target formagnify.exeandsethc.exe.
An operator could obtain a command shell through accessibility binaries at the logon screen.
- During operation
Investigate critical systems.
Analyze snapshots on your chosen schedule. Review the evidence and direct containment or remediation.
- Before deployment
Inspect the image itself.
Review Windows machine images, including AMIs, without starting them. Investigate findings before approving a new version.
- After remediation
Check the new snapshot.
Reanalyze a supported system copy to look for remaining evidence of compromise.
Understand the damage. Assess the recovery copy.
Hunt inspects live data, replicated data, and backups for ransomware, malware, and corruption. Findings identify affected files and help your team assess candidate recovery points.
A copy from before encryption may still contain persistence. Combine Hunt results with a Pursuit investigation of the same supported system copy.
75 files identified. Recoverable, clean copy available.
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
- Path
- G:/file-sample_100kB.doc
- Size
- 72.0 KB
- First seen
- 2026-09-13T02:32:10.264Z
- Signal
- UNKNOWN
Your recovery review
- 01
Review the analysis.
Check the copy, time, scope, and findings. A result applies to what was examined.
- 02
Check the recovery requirements.
Review copy age, backup coverage, immutability, isolation, and open violations.
- 03
Hand off to your recovery tools.
Your provider or tooling performs the restore. Your team validates the recovered applications.
Separate analysis. Connected to your workflow.
- 01 / Connect & scope
Choose what matters.
Define systems, data sources, permissions, and analysis frequency.
- 02 / Analyze
Examine the evidence.
Pursuit investigates system copies. Hunt inspects data in a separate analysis environment.
- 03 / Review & act
Work from the findings.
Review results in the console or through integrations. Assign response and recovery actions.
Where does analysis run?
Deployment options include your account and an isolated Elastio-managed environment. Confirm the data flow, access permissions, retention, and supported sources for your deployment during evaluation.
What does “no host agent” mean?
Pursuit examines a Windows image or snapshot without installing an agent on the inspected host. It can use historical activity recorded in the copy, such as system event logs. An AMI does not need to run for analysis.
How are cyber vaults covered?
Hunt analyzes vaulted copies read-only. Review its results with copy age, analysis scope, and the Pursuit assessment for supported system copies, while your existing vault controls protect the data.
Extend your workflow
Take the evidence to leadership.
The Resilience Program reports recovery commitments as Proven, Unproven, or Excluded. Evidence ledgers and board packs show the basis for each result. Posture and Get to Green help teams prioritize the remaining work.
One bar, three buckets. Proven is your number, Unproven is your work, Excluded is your record.
As of Nov 18 2026: 437 total assets: 354 in-scope and 83 excluded. 322 of the 354 in-scope assets hold a proven clean recovery point. 5 of 119 critical-class assets do not hold a clean recovery point. 118 machine images are hunted for threats and carry no recovery commitment.
Named 345 + Default 9 + Excluded 83 = 437 assets.
Not provably recoverable today. Click a class or count to drill in.
Incident response support
Help interpreting the findings.
Incident response support is included with every license. Get help assessing findings and recovery options while your security team directs containment and remediation.
Start with the critical estate
See what the evidence reveals on your systems.
Agree the systems, access, and analysis scope. Review findings and recovery requirements with your team.