Field report / September 2026

Five public AMIs.
Two assessments.
Here are the results.

We tested five systems built from publicly available Amazon Machine Images (AMIs) with a vulnerability scanner and Elastio. Pursuit looked for evidence of active compromise. Hunt checked for malware and ransomware damage.

First assessment

What did the vulnerability scanner report?

We recorded its software vulnerabilities, file alerts, and cloud-configuration results for each system.

Second assessment

What evidence did Elastio find?

We investigated startup tasks, scripts, registry changes, credentials, and security settings. Hunt also examined file contents for malware and ransomware damage.

Each test shows both results and the evidence behind Elastio’s findings.

Review the exact tasks, files, registry entries, hashes, and timestamps available in the source report. Use them to see what your responders would investigate next.

An AMI is a template used to launch a server. These five Windows examples include security-training images; ransomware was deliberately run in one test. Findings describe the tested systems, not necessarily the original images as published. The scanner is anonymized.

Case 01 / Deliberate ransomware execution

Vega ransomware: identify the damaged data.

showcase-ransomware · Windows Server · Recorded September 4, 2026

Scanner results Full Elastio evidence

What the vulnerability scanner reported

Vulnerability scanner: cloud configuration checks

Vulnerability scanner Results: 19 AWS Cloud-Level Checks

7 FAIL / 12 PASS

Vulnerability scanner evaluated the machine's AWS-level settings at 2026-09-04T19:37:32Z. It flagged four items: detailed monitoring disabled, no SSM agent, a public IP, and launch with a key pair. Its output for this machine contains no malware findings and no vulnerability findings.

Not in the Vulnerability scanner Results

  • No ransomware or malware finding of any kind for this machine.
  • The 7,150 encrypted files across 528 directories.
  • The destroyed partition /dev/nvme1n1p1.

What Elastio found

Finding titles, severity labels, records, and timelines reproduced from the supplied test report.

Elastio Hunt (ransomware)

Vega Ransomware Identified, Spread of Damage Mapped

CRITICAL

Elastio inspected 192,827 filesystem entries in 6 minutes 54 seconds. It identified the strain as Vega, counted 7,150 encrypted files, and mapped the damage across 528 directories.

Detected Strain:
Vega (FileTool indicator & encrypted block characteristics)
Encrypted Files:
7,150 files mapped across user profiles and system volumes
Affected Directories:
528 directories containing encrypted files
Filesystem Damage:
Partition /dev/nvme1n1p1 flagged as unmountable
Job Timeline:
Started 2026-09-04T19:39:01Z -> Finished 2026-09-04T19:45:56Z (Job ID: j-01m1py0kfdq0hcf1xdhtdgj147)

Damaged Partition Flagged as Unmountable

HIGH

Partition /dev/nvme1n1p1 failed to mount: "Device does not contain any filesystem or this filesystem is not recognized." The partition table itself was destroyed during the attack. Restoring from this data would fail.

Security decision

Use file-level damage and readability findings to assess recovery candidates. This result alone does not identify a clean recovery copy.

Recorded scope and job

Hunt inspected 192,827 filesystem entries.

Start: 2026-09-04T19:39:01Z
Finish: 2026-09-04T19:45:56Z
Job: j-01m1py0kfdq0hcf1xdhtdgj147

Case 02 / WinHostOne

A startup task connected to credential harvesting.

Windows Server 2019 Datacenter · win-host-1.asgard.corp

Scanner results Full Elastio evidence

What the vulnerability scanner reported

Vulnerability scanner: file reputation + CVEs

Vulnerability scanner Malware Results: 6 File Alerts

1 HIGH / 5 INFO

Vulnerability scanner flagged one PowerShell script in /Sysmon/ as Malgent, three script alerts inside an uninstalled package directory (disabledefender-winconfig.nupkg), and two informational alerts on a built-in Windows modem driver (SmSerl64.sys). The report does not link these alerts to the PacketBuffer activity.

Vulnerability scanner Vulnerabilities: 6,607 CVEs

6,607 Vulnerabilities

Vulnerability scanner listed 6,607 software package CVEs (Google Chrome, Edge, runtimes), recorded on 2026-09-04 between 14:20Z and 14:36Z.

Not in the Vulnerability scanner Results

  • The PacketBuffer scheduled task, packet_buffer.ps1, and tls.js.
  • The injection of tls.js into LSASS to harvest TLS secrets, and the traffic capture.
  • The destination the capture was written to: \\10.10.200.40\pcaps.
  • The disabled Defender for Endpoint Sense service.

What Elastio found

Finding titles, severity labels, records, and timelines reproduced from the supplied test report.

Engine: Elastio Pursuit (Gate 4)

PacketBuffer: TLS Secret Harvesting and Traffic Capture, Set to Run at Every Startup

CRITICAL (GATE 4)

Elastio confirmed the full chain. A scheduled task named PacketBuffer runs at every machine startup and launches packet_buffer.ps1 and tls.js. frida.exe injects tls.js into LSASS to harvest TLS secrets, and dumpcap.exe captures traffic. The capture is written to a share on another machine.

Scheduled Trigger:
Task \PacketBuffer (AtStartup trigger, enabled)
Hooking Script:
packet_buffer.ps1 (MD5: 1c80e6cdb3ca6e7147e04748ea33df4d, SHA-256: e9776adb64a83154e447d9f359338997825a92d25b86f1a94f02cbdeb3b71ba7)
TLS Interceptor:
tls.js (MD5: d96a6e6a8a663e5b8a3ec03bc7e9ea4d, SHA-256: 9fd39e27ee523a7a583d26190b0c3feb3e7668611d21055c9f32ab7970c1df6a)
Exfiltration Target:
Remote staging share \\10.10.200.40\pcaps
Target APIs:
LSASS credential memory dumping, TLS session key interception

Microsoft Defender Weakened, EDR Service Disabled

MEDIUM (GATE 2)

Four Defender protection settings were turned off in the registry, and the Microsoft Defender for Endpoint Sense service, the EDR component, was set to disabled.

Registry Key:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender
EDR Tampering:
Microsoft Defender for Endpoint Sense service set to Disabled
Last Modified:
2023-04-21T14:34:29Z

The Attack, Event by Event, Found by Elastio

  1. 2023-01-12T16:07:34ZScheduled job PacketBuffer registered with AtStartup trigger.
  2. 2023-01-12T16:17:34Zpacket_buffer.ps1 written to disk (hooks LSASS & TLS APIs).
  3. 2023-04-21T14:34:29ZDefender Real-Time Protection registry key modified; Sense service disabled.
  4. 2023-04-21T14:41:49Ztls.js written to disk; data staged to \\10.10.200.40\pcaps.

Security decision

Investigate the scheduled task, scripts, credential access, and capture destination while addressing the vulnerability backlog.

Evidence chain and SHA-256 hashes
  1. \PacketBuffer is enabled with an AtStartup trigger.
  2. frida.exe injects tls.js into LSASS.
  3. dumpcap.exe captures traffic to \\10.10.200.40\pcaps.

packet_buffer.ps1
e9776adb64a83154e447d9f359338997825a92d25b86f1a94f02cbdeb3b71ba7

tls.js
9fd39e27ee523a7a583d26190b0c3feb3e7668611d21055c9f32ab7970c1df6a

Case 03 / Windows-Development-EC2

Legitimate programs connected by a malicious registry change.

Windows Server 2019 Datacenter · EC2AMAZ-SMASCMC

Scanner results Full Elastio evidence

What the vulnerability scanner reported

Vulnerability scanner: file reputation + CVEs

Vulnerability scanner Malware Results: 2 Driver Notes

2 INFORMATIONAL

Vulnerability scanner reported two informational alerts on SmSerl64.sys, a built-in Windows modem driver, classified as a "LOLDriver".

Vulnerability scanner Vulnerabilities: 14,353 CVEs

14,353 Vulnerabilities

Vulnerability scanner listed 14,353 package CVEs across the software installed on the machine.

Not in the Vulnerability scanner Results

  • The sethc.exe and magnify.exe logon backdoor redirects.
  • The Administrator password sitting in plain text in a script.
  • The registry policy that turned Defender anti-spyware off.

What Elastio found

Finding titles, severity labels, records, and timelines reproduced from the supplied test report.

Engine: Elastio Pursuit (Gate 3)

Sticky Keys Logon Backdoor (Registry Redirect)

HIGH (GATE 3)

Two Windows accessibility programs, sethc.exe (Sticky Keys) and magnify.exe (Magnifier), were redirected in the registry to launch cmd.exe instead. The effect: anyone standing at the login screen, with no password, can press Shift five times and get a command window with full SYSTEM rights.

Registry Key 1:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe (Debugger=cmd.exe)
Registry Key 2:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\magnify.exe (Debugger=cmd.exe)
Observation:
In-box cmd.exe hash-checked; persistence mechanism present at machine scope

Administrator Password Stored in Plain Text

MEDIUM (GATE 2)

Inside aws-ec2-windows-password-update.ps1, Elastio found a fixed password passed directly to net.exe user Administrator <password>. Anyone who can read the script can read the password.

Defender Anti-Spyware Turned Off by Policy

MEDIUM (GATE 2)

The registry policy SOFTWARE\Policies\Microsoft\Windows Defender\DisableAntiSpyware=1 was written on 2019-11-22T15:55:39Z and has suppressed that protection since.

Security decision

Investigate the registry redirects and exposed credential. A legitimate file signature does not establish that the system is configured safely.

Registry and script evidence

Registry location:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\

The sethc.exe and magnify.exe subkeys contain a Debugger value pointing to cmd.exe.

aws-ec2-windows-password-update.ps1 contains a fixed password passed to an Administrator password-update command. No credential value is reproduced here.

This is the September comparison run.

Case 04 / PWNZONE-v0.1

Inspect what the image is configured to launch.

SANS SEC565 domain-controller training image · Windows Server 2022 Datacenter

Scanner results Full Elastio evidence

What the vulnerability scanner reported

Vulnerability scanner: file reputation + CVEs

Vulnerability scanner Malware Results: 2 Driver Notes

2 INFORMATIONAL

Vulnerability scanner flagged SmSerl64.sys, the same built-in modem driver, as a "LOLDriver" in two system folders.

Vulnerability scanner Vulnerabilities: 6,308 CVEs

6,308 Vulnerabilities

A package vulnerability list across the software installed on the domain controller.

Not in the Vulnerability scanner Results

  • The custom backdoor spoolserver.exe.
  • The scheduled task \fakespool launching it at boot as SYSTEM.
  • The disabled Windows firewall and Defender Tamper Protection.

What Elastio found

Finding titles, severity labels, records, and timelines reproduced from the supplied test report.

Engine: Elastio Pursuit (Gate 3)

Custom Backdoor Runs at Every Boot With SYSTEM Rights

HIGH (GATE 3)

Elastio identified spoolserver.exe, a small custom-built program (6,144 bytes) that pretends to be the Windows print spooler. A scheduled task named \fakespool launches it at every boot with SYSTEM rights, the highest privilege level on the machine.

Custom Binary:
spoolserver.exe (6,144 bytes, custom compiled .NET payload)
Scheduled Task:
\fakespool (Trigger: At Boot, Principal: NT AUTHORITY\SYSTEM)
Payload Capabilities:
Named-pipe server, Print Spooler impersonation

Defender and Windows Firewall Turned Off

MEDIUM (GATE 2)

Defender Tamper Protection, anti-spyware, and real-time monitoring were turned off in the registry, one after another. All three Windows firewall profiles (Domain, Public, Standard) were then disabled.

The Attack, Event by Event, Found by Elastio

  1. 2025-01-17T20:17:30ZDefender TamperProtection disabled via registry.
  2. 2025-01-17T20:23:25ZDefender DisableAntiSpyware policy set to 1.
  3. 2025-01-17T20:23:55ZDefender DisableRealtimeMonitoring set to 1.
  4. 2025-01-17T20:38:00ZDomain, Public, and Standard Windows Firewall profiles disabled (EnableFirewall=0).
  5. 2025-01-17T21:29:26Zspoolserver.exe written to disk and linked to \fakespool boot task.

Security decision

Review startup behavior before image approval. Intent matters: this is a training image, so the presence of attack code does not establish an unauthorized compromise of its publisher.

Additional recorded findings

The report also identified disabled Defender settings and all three Windows firewall profiles, rated MEDIUM (GATE 2).

The executable was recorded on 2025-01-17T21:29:26Z. This report preserves the September assessment. A later run may differ.

Case 05 / CommandoVM-v1.1

Separate reference material from executable tools.

SANS SEC699 penetration-testing workstation · Windows 10 Enterprise

Scanner results Full Elastio evidence

What the vulnerability scanner reported

Vulnerability scanner: file reputation + CVEs

Vulnerability scanner Results: 4,474 Malware Alerts and 13,582 CVEs

High volume

Vulnerability scanner reported 4,474 malware rows. Of those, 3,983 (89%) point at documentation, HTML proof-of-concept pages, and exploit-db text files inside one unused folder (/ProgramData/chocolatey/lib/wsl-kalilinux/). These files cannot run.

Not in the Vulnerability scanner Results

  • The disabled Windows firewall.
  • The disabled Defender real-time protection.
  • Any prioritized signal: this one machine produced over 18,000 alerts, most pointing at files that cannot execute.

What Elastio found

Finding titles, severity labels, records, and timelines reproduced from the supplied test report.

Elastio Hunt + Pursuit

Real Attack Tools Found Inside Nested Zip Archives

DEEP FILE INSPECTION

Elastio inspected 790,605 files, opening zip archives layer by layer. Inside /Users/student/Downloads/attacking-trust-assets.zip, it unpacked and confirmed three working attack tools:
• mimikatz.exe (Generic.Trojan.Mimikatz)
• Rubeus.exe (Generic.Trojan.Rubbie)
• SpoolSample.exe (Generic.ShellCode.RDI)

Encryption Damage Found on 137 Files

RANSOMWARE HUNT

Elastio's ransomware hunt identified 137 files with encryption damage inside testing directories.

Host Defenses Confirmed Off Here Too

MEDIUM (GATE 2)

Four Defender protection settings were off, and the Domain and Standard Windows firewall profiles were set to EnableFirewall=0.

Security decision

Review whether tools and configuration match the image’s intended use. Expected testing artifacts should not be presented as proof of a real-world intrusion.

Scope and jobs

790,605 files inspected. Archive: /Users/student/Downloads/attacking-trust-assets.zip.

Malware hunt: 2026-09-02T14:21:15Z to 15:54:56Z
Job: j-01m1h7k9w73fsdnj7tvb91knft.

Ransomware hunt: 2026-09-02T14:21:15Z to 15:10:53Z.

Results / Recorded output

Different evidence supports different decisions.

“Not reported” refers only to the supplied scanner results for these test systems.

SystemVulnerability scannerAdditional Elastio evidenceDecision supported
Ransomware testCloud-configuration checks; no malware findingsVega, affected files and directories, unmountable partitionAssess data damage
WinHostOneCVEs and file alertsStartup task, credential harvesting, traffic-capture destinationInvestigate active compromise
Windows developmentCVEs and driver notesRegistry redirects and exposed Administrator credentialRemove access and address secrets
PWNZONE training imageCVEs and driver notesCustom executable tied to a SYSTEM boot taskAssess intended image behavior
CommandoVM training imageCVEs and malware alerts, including reference filesArchived tools, encryption damage, host-defense settingsReview artifacts in context

Use both assessments in image approval.

Review vulnerabilities for patching and mitigation. Review compromise evidence to decide whether the image is suitable for deployment and whether existing systems need investigation.

Application / Machine image security

Put the evidence into your release workflow.

Automatically discover images, analyze their contents, and route findings to the team responsible.

  1. 01 / DISCOVER

    Check every hour.

    Elastio checks your private catalog and all images attached to instances for new images and versions.

  2. 02 / ANALYZE

    Run Pursuit and Hunt.

    Investigate system activity and inspect file contents. You can also invoke analysis through your workflow or a schedule.

  3. 03 / RESPOND

    Send findings to SIEM and SOAR.

    Review the evidence and intended configuration before deciding whether to release, remediate, or rebuild.

If the image is already deployed

Review the servers launched from it, plus launch templates and scaling groups still pointing to it. Update the source and launch settings so replacement servers do not inherit the same problem.

Hourly is the discovery interval, not an analysis-completion guarantee. Your release process controls deployment. Source-image relationships do not by themselves prove compromise of every linked system.

Methods / Scope and traceability

Read the results within the test scope.

Elastio-recorded comparison, September 2026. The underlying report is the source of these findings.

Test conditions

  • Five selected Windows systems sourced from community and marketplace images.
  • Included security-training images and deliberate ransomware execution.
  • Scanner configuration included agentless snapshot analysis, vulnerability results, file-reputation feeds, and cloud-configuration checks.
  • Elastio used Hunt and Pursuit. The source lists a signature database current as of September 1, 2026.

Interpretation limits

  • This is not an independent or statistically representative benchmark.
  • Jobs ran at different times. The supplied report does not establish identical snapshots for every paired run.
  • Missing findings describe recorded output, not all capabilities of the scanner or scanner category.
  • Comparable product-version and complete configuration details are not supplied.
  • The results do not establish AI attribution, prevention, or a clean recovery point.
Source images and recorded execution times
SystemSource imageScanner timestamp (UTC)
Ransomware testami-04fca11ec6cc2ddab2026-09-04 19:37:32
WinHostOneami-0f9c47f65b11385272026-09-04 14:47:22
Windows developmentami-0c8d6702203cbdf7f2026-09-01 20:13:35
PWNZONEami-0fd48271b21c38aa52026-09-01 20:13:35
CommandoVMami-0b9c9327c8f68e2be2026-09-01 20:13:35

Pursuit reports were generated between 2026-09-03T21:52:23Z and 2026-09-04T02:06:49Z. Source report IDs: persistence-mt-int-2 / persistence-mt-int-2-integrated; session: pursuit_deterministic_closure. Case pages retain the available Hunt job identifiers.

Source: recorded-results report embedded in the supplied Elastio security-workshop presentation.