Elastio Pursuit

Find attackers before they steal or encrypt your data.

Pursuit investigates systems off-host to uncover attacker access, malicious code, and credential theft. Your security team gets the evidence to contain the attack and remove what keeps the attacker inside.

See which systems need your response.

Active Intrusions brings affected hosts, severity, and first-detection times into one view. Prioritize the systems that need attention and open each host’s findings to assess the scope of the attack.

See where to investigate next. The timeline shows when compromise was first detected on each host. Use the underlying evidence to investigate whether the attacker moved between systems.

Give responders the evidence to act. Open a host’s assessment and findings to decide what to contain and remediate through your existing controls.

See response integrations

Know how the attacker got established and what to remove.

Pursuit examines code and system records without requiring a known malware signature.

Find persistent access. Uncover services, scheduled tasks, and startup code that keep attackers inside after restarts or patching.

Expose concealed activity. Identify malicious scripts, credential theft tools, and changes to security controls.

Establish the scope. Follow evidence of movement, data staging, and transfer activity to determine which systems need a response.

Read about this same finding: magnify.exe and sethc.exe → cmd.exe

Pursuit report: pursuit-EC2AMAZ-SMASCMC-20261004.

Recorded investigations

Find malicious code without a known signature.

Pursuit analyzes what the machine is configured to run and investigates the code behind it.

HIGH · WINDOWS SERVER 2022

Find the backdoor and what keeps it running.

A custom backdoor on a domain controller posed as the Windows print spooler.

Evidence fields · recorded backdoor finding

Binary
spoolserver.exe
Size
6,144 bytes, custom-compiled .NET
Launched by
Scheduled task \fakespool, At Boot
Runs as
NT AUTHORITY\SYSTEM
Behavior
Named-pipe server posing as the print spooler
  • T1053.005 · Scheduled task
  • T1036.004 · Masquerading

Responders see both the program and the task that preserves access.

CRITICAL · WINDOWS SERVER 2019

Connect the scripts to secret harvesting.

Pursuit connected a startup task, custom scripts, LSASS injection, and the traffic-capture destination.

Evidence fields · recorded script finding

Script
packet_buffer.ps1
Script
tls.js
Launched by
Scheduled task \PacketBuffer, AtStartup
Behavior
frida.exe injects tls.js into lsass.exe to harvest TLS secrets
Capture
dumpcap.exe captures traffic
  • T1055 · Process injection
  • T1040 · Network sniffing

One finding connects the startup mechanism to the code and its behavior.

Explore the recorded backdoor finding

A custom backdoor posed as the print spooler.

Pursuit connected the suspicious binary to its startup mechanism.

Recorded finding · Windows Server 2022 domain controller

Assessment
High
Binary
spoolserver.exe
Size
6,144 bytes
Type
Custom-compiled .NET
Behavior
Named-pipe server posing as the print spooler

Recorded evidence walkthrough. The steps illustrate the response decision; they do not execute actions.

Credentials

Find stolen secrets and exposed credentials.

See the code, tools, and stored credentials that could give an attacker access to other systems.

CRITICAL

TLS secrets harvested from LSASS.

The PacketBuffer finding connects frida.exe, tls.js, and dumpcap.exe to secret harvesting and traffic capture.

Secret theft behavior

HIGH

Attack tools inside nested archives.

Pursuit opened nested ZIP files and found Mimikatz and Rubeus in the recorded test set.

Concealed credential-theft tooling

MEDIUM

Administrator password in plain text.

aws-ec2-windows-password-update.ps1 passed a fixed password to net.exe user Administrator.

Credential exposure · T1552.001

Observed attacker techniques

Techniques Pursuit finds.

Pursuit connects code, startup settings, and system records to identify how attackers maintain access, weaken defenses, steal credentials, and move data. Above the waterline are nine technique examples from seven machines. Below it are the broader tactics observed across 42 malicious public marketplace images.

Found on the machines in this deck

  • Sticky Keys logon backdoorT1546.008
  • Scheduled task at bootT1053.005
  • Defender and firewall offT1562.001, T1562.004
  • Injection into LSASST1055
  • Traffic capture to a shareT1040
  • Vulnerable driver as a serviceT1543.003, T1068
  • Email out through GmailT1048
  • Credentials in scriptsT1552.001
  • Posing as the print spoolerT1036.004

Tactics found in 42 malicious images over thousands of analyses

  • Persistence
  • Privilege escalation
  • Defense evasion
  • Credential access
  • Discovery
  • Lateral movement
  • Collection
  • Command and control
  • Exfiltration
Recorded findings above the waterline. Attacker tactics observed across the malicious-image analyses below it. Source: Elastio’s 2026 workshop investigations.

Investigate outside the compromised system.

Attackers can enter through stolen credentials, zero-day exploits, or compromised software and machine images. To sustain an operation, they need to maintain access. Pursuit investigates the code and system changes that keep them established.

What does persistence mean?

MITRE ATT&CK describes persistence as maintaining a foothold despite disruptions such as restarts or changed credentials. It includes startup mechanisms and valid-account access; it does not always require a startup change on the target machine.

Analysis runs on a read-only snapshot outside the running system. No Pursuit agent runs on the host for an attacker to disable.

Pursuit is an agentic system. Multiple AI agents investigate in parallel. Each works through several rounds: examine evidence, follow a lead, request more detail, and check the finding against source records. Pursuit analyzes hundreds to thousands of machines concurrently. Findings and supporting evidence flow through your SIEM to incident response teams for containment and remediation.

You choose the model endpoint: Amazon Bedrock, Microsoft Foundry, or OpenAI. Pursuit’s agents use language models through that endpoint to investigate the evidence.

Pursuit uses patent-pending technology to produce evidence-backed findings.

Continuous investigation, at the frequency you set. Pursuit analyzes available snapshots on a recurring schedule, without waiting for an alert. Each run checks for evidence of compromise. Analysts can add context about approved tools and expected activity to guide future investigations.

Run Pursuit where your systems run. Windows is supported today on AWS, Azure, and VMware. GCP support is planned for November 1, 2026. Linux support is planned by January 2027.

Know what to remove and why.

Pursuit connects each finding to the code and system records behind it. Responders can review the assessment, confidence, and source evidence before deciding what to remediate.

In this recorded investigation, Windows accessibility programs magnify.exe and sethc.exe were configured to launch cmd.exe. The report identifies the backdoor mechanism and distinguishes it from expected system activity.

Use the findings to remove malicious code and access through your existing controls. Pursuit can analyze a fresh snapshot after remediation to check for remaining compromise.

About 20 minutes per host to produce investigation detail, compared with 1 to 5 days of manual collection.

This measures investigation time per host. How soon your team receives a finding also depends on snapshot availability and the analysis schedule.

The same report shown above: pursuit-EC2AMAZ-SMASCMC-20261004. High suspicion, high confidence. The configured backdoor is validated; matching execution records were not available.

Keep compromised images out of production.

Machine images are part of your software supply chain. A compromised image can give new systems attacker access from startup.

A vulnerability check identifies weaknesses attackers could exploit. Pursuit investigates whether the image already contains malicious code or attacker access. It analyzes machine images for malicious code, persistence, and exposed credentials before deployment.

42 of 500 public marketplace machine images carried malicious persistence in Elastio's 2026 QA analysis. Systems built from a compromised image can inherit the attacker's access.

If an image is compromised, trace the systems launched from it and the launch configurations that still reference it. Use each system's findings to assess the impact.

Source: supplied Hunt machine-image finding. Original node labels and statuses preserved.

Show the evidence when no attack is found.

Pursuit records what it checked and why the evidence supports its assessment. Your team can review expected system activity as well as suspicious findings.

For EC2AMAZ-897VQUN, Pursuit returned low suspicion, medium confidence. The report records expected Windows services, scheduled tasks, and startup settings. It found no validated attacker-controlled persistence.

The PowerShell entries did not have supporting evidence of a malicious command or persistence mechanism. Pursuit did not treat those entries alone as an attack. Process and Prefetch records were empty, and Amcache contained no records. Those limits matter when interpreting the result.

A copy made before encryption can still contain the attacker. A copy is proven clean when Pursuit finds no attack in the system and Hunt finds no ransomware in the data.

A low-suspicion Pursuit assessment is one part of that evidence. Review Hunt’s result for the same copy and the system’s recovery requirements.

Explore Hunt

Original report excerpt · EC2AMAZ-897VQUN · October 4, 2026. Finding titles and descriptions are unchanged.

Review a Pursuit investigation and its source evidence on your systems.

Request a demo