- Snapshots · machine images
- Live data · replicas · backups
Elastio Platform | Ransomware Security
How do you stop an AI-driven attack after it gets in?
AI helps attackers find vulnerabilities and write attack code faster. Patching takes time, and a patch may not remove access an attacker has already established.
Elastio finds evidence of compromise so your team can contain and remove attackers before data theft and encryption. Pursuit and Hunt also prove which copy is clean for recovery.
Detect the attacker before data theft and encryption.
Pursuit investigates how attackers keep access, steal credentials, and move between systems. Hunt provides recovery intelligence: evidence of infection, damage, and clean recovery points.
| Attack stage | Role of the controls |
|---|---|
| 1. Initial access | Identity and preventive controls address entry through exploits or stolen credentials. |
| 2. Execution | Endpoint and runtime controls monitor code as it runs. |
| 3. Persistence | Pursuit investigates services, scheduled tasks, and startup code that preserve attacker access. |
| 4. Lateral movement | Pursuit investigates credential theft and movement between systems. |
| 5. Data theft | Pursuit finds evidence of data collection, staging, and transfer. |
| 6. Encryption | Hunt identifies ransomware damage in files and copies. |
| 7. Recovery | Pursuit and Hunt establish which copy is clean to restore. |
Detect at stages 3 and 4. Contain and remediate before stages 5 and 6. Pursuit also investigates evidence of theft when it has begun. Controls overlap; attacks can skip or repeat stages.
Pursuit finds attackers inside your systems.
Vulnerability scanners identify weaknesses attackers could exploit. Pursuit finds evidence of compromise.
It analyzes startup settings, code, and activity recorded on disk without requiring a known signature. Findings include file paths, hashes, timestamps, severity, and source evidence.
Your team uses the findings to contain the attack and remove access. Pursuit analyzes a fresh snapshot after remediation to check for remaining compromise. It also checks machine images before deployment.
A Pursuit assessment linked to its supporting evidence.
- Anchor
- 2019-10-08T18:15:37Z
- Detected
- 2026-10-04T00:25:00Z
- Report
- pursuit-EC2AMAZ-SMASCMC-20261004
Gate 3 high: two validated IFEO debugger persistence entries set magnify.exe and sethc.exe Debugger to C:\windows\system32\cmd.exe. This is an attacker-relevant accessibility-backdoor mechanism. No execution telemetry was found in the bounded process/Security sources, so operational corroboration is limited. The separate EC2 password-rotation task and startup wallpaper scripts were inspected and remain low/benign context. No suspicious user-writable loaded driver or usable offensive framework was found.
Host: EC2AMAZ-SMASCMC
Network name: EC2AMAZ-SMASCMC.ec2.internal
Severity: HIGH
Gate 3 is met by two validated IFEO debugger persistence entries:
- -
magnify.exe->C:\windows\system32\cmd.exe - -
sethc.exe->C:\windows\system32\cmd.exe
This is an attacker-relevant accessibility-backdoor mechanism. The bounded Security and process sources contain no matching execution records, which limits operational corroboration but does not invalidate the persisted mechanism.
The EC2 password-rotation scheduled tasks and Startup-folder wallpaper scripts were present and inspected. The password script retrieves a value by AWS secret identifier and calls net.exe user, but no fixed secret value was present. The startup scripts invoke the EC2 Launch Set-Wallpaper module and self-clean an initialization copy. These were classified as benign/expected low-severity context.
- - IFEO: FOUND, two debugger entries; headline finding.
- - Scheduled tasks: FOUND, EC2 administrative tasks; no malicious script content.
- - Services and service DLLs: no suspicious non-standard service persistence.
- - Autoruns: no suspicious Run/RunOnce command.
- - Startup folder: FOUND, coherent EC2 wallpaper setup scripts.
- - WMI permanent persistence: not found in bounded MOF evidence.
- - COM hijack/registration: standard installed-software paths; no deceptive loader.
- - AppInit/AppCert loader abuse: not found; AppInit_DLLs empty and LoadAppInit_DLLs=0.
- - Winlogon Shell/Userinit abuse: not found;
explorer.exeand standarduserinit.exe. - - Driver persistence: no user-writable or materially non-standard .sys path.
- - Spooler/print pipeline abuse: no attacker-relevant chain found.
- - EDR/AV bypass: Defender presence detected; no Defender-specific crash/tamper symptom.
- - LOLBins:
cmd.exe, PowerShell,net.exe,sc.exe, andrundll32.exeobserved in administrative or IFEO contexts. Presence alone was not treated as malicious. - - Offensive payloads: no bounded Cobalt Strike, Mimikatz, Metasploit, or other usable offensive-framework traces.
Know which copy is clean before recovery.
Finding a clean copy during an incident can add hours of investigation while systems remain down. Establish the evidence before the outage so your recovery team knows which copy to use.
Hunt is the recovery intelligence layer for live data, replicas, and backups. It hunts for ransomware, malware, and corruption, then gives your team the evidence to select a clean recovery point: affected files, analysis results, copy age, and coverage.
Your infrastructure preserves the copies. Hunt establishes which are clean of ransomware. Pursuit checks the same copy for attacker activity. Together, they provide the evidence for provable recovery.
Hunt identifies affected files and clean-copy availability.
75 files identified. Recoverable, clean copy available.
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
02:32:10.264UNKNOWN
- Path
- G:/file-sample_100kB.doc
- Size
- 72.0 KB
- First seen
- 2026-09-13T02:32:10.264Z
- Signal
- UNKNOWN
Recover from a copy backed by evidence.
A copy made before encryption can still contain the attacker. A copy is proven clean when Pursuit finds no attack in the system and Hunt finds no ransomware in the data. Results record the copy, analysis time, scope, and findings.
This asset has no open threats across the displayed Hunt checks, but four violations remain. Review those violations and the Pursuit result for the same copy before establishing recovery readiness.
Elastio starts the recovery handoff to your provider console, script, or instructions. Your tooling executes the restore; your team validates the recovered applications.
Clean analysis is part of provable recovery. Posture also checks backup coverage, clean-copy age, and required protections such as immutability and isolation. Violations show where requirements are not met.
See what provable recovery requires
Hunt applies that recovery intelligence to vaulted copies through read-only analysis. Security and recovery teams can assess the clean point while existing vault controls protect the copies.
Clean asset evidence from the product
No open threats.
Checked for: Malware · Ransomware · Encryption · FS integrity
Last hunt: 2026-10-04 00:09 UTC
Last clean backup: 2026-09-02 14:18 UTC
- AWS EC2 Huntsucceeded10/04/26 12:09 AM2 modules
- AWS EC2 Huntsucceeded09/27/26 12:10 AM2 modules
- AWS EC2 Huntsucceeded09/20/26 12:11 AM2 modules
- AWS EC2 Huntsucceeded09/19/26 11:05 AM2 modules
Analyze systems and data outside the production host.
Elastio runs off-host. Pursuit investigates system evidence, and Hunt analyzes data for ransomware, malware, and corruption in a separate analysis environment.
Recurring analysis at the frequency you set keeps detection and recovery evidence current. Your security team gets findings for containment and remediation. Your recovery team gets evidence of which copy is clean.
Analysis runs in your account or an isolated Elastio-managed environment. Findings reach your teams through the console and integrations.
- Pursuit · Investigates attacker activity
- Hunt · Finds ransomware, malware and corruption
- Analysis separate from production
- Contain and remediate · Findings + source evidence
- Prove the clean copy · Pursuit + Hunt results for the same copy
Get incident response support with every license.
Every license includes incident response support with a 24-hour response commitment. The team helps you assess findings and the clean recovery point. Your security team directs containment and remediation.
AI Attack Readiness
The Resilience Program records your recovery commitments to the board. It reports assets as Proven, Unproven, or Excluded, with board packs and evidence ledgers showing which commitments are met and which need action.
Posture gives security teams the broader operational view. Get to Green prioritizes work across the estate.
The Resilience Program reports against recovery commitments.
One bar, three buckets. Proven is your number, Unproven is your work, Excluded is your record.
As of Nov 18 2026: 437 total assets: 354 in-scope and 83 excluded. 322 of the 354 in-scope assets hold a proven clean recovery point. 5 of 119 critical-class assets do not hold a clean recovery point. 118 machine images are hunted for threats and carry no recovery commitment.
Named 345 + Default 9 + Excluded 83 = 437 assets.
Not provably recoverable today. Click a class or count to drill in.
See Elastio on your systems.
Review an investigation and a clean recovery point. Agree the analysis scope, frequency, and response responsibilities.
Request a demo