What did the vulnerability scanner report?
We recorded its software vulnerabilities, file alerts, and cloud-configuration results for each system.
We tested five systems built from publicly available Amazon Machine Images (AMIs) with a vulnerability scanner and Elastio. Pursuit looked for evidence of active compromise. Hunt checked for malware and ransomware damage.
We recorded its software vulnerabilities, file alerts, and cloud-configuration results for each system.
We investigated startup tasks, scripts, registry changes, credentials, and security settings. Hunt also examined file contents for malware and ransomware damage.
Each test shows both results and the evidence behind Elastio’s findings.
Review the exact tasks, files, registry entries, hashes, and timestamps available in the source report. Use them to see what your responders would investigate next.
An AMI is a template used to launch a server. These five Windows examples include security-training images; ransomware was deliberately run in one test. Findings describe the tested systems, not necessarily the original images as published. The scanner is anonymized.
showcase-ransomware · Windows Server · Recorded September 4, 2026
Vulnerability scanner evaluated the machine's AWS-level settings at 2026-09-04T19:37:32Z. It flagged four items: detailed monitoring disabled, no SSM agent, a public IP, and launch with a key pair. Its output for this machine contains no malware findings and no vulnerability findings.
/dev/nvme1n1p1.Finding titles, severity labels, records, and timelines reproduced from the supplied test report.
Elastio Hunt (ransomware)Elastio inspected 192,827 filesystem entries in 6 minutes 54 seconds. It identified the strain as Vega, counted 7,150 encrypted files, and mapped the damage across 528 directories.
Partition /dev/nvme1n1p1 failed to mount: "Device does not contain any filesystem or this filesystem is not recognized." The partition table itself was destroyed during the attack. Restoring from this data would fail.
Security decision
Use file-level damage and readability findings to assess recovery candidates. This result alone does not identify a clean recovery copy.
Hunt inspected 192,827 filesystem entries.
Start: 2026-09-04T19:39:01Z
Finish: 2026-09-04T19:45:56Z
Job: j-01m1py0kfdq0hcf1xdhtdgj147
Windows Server 2019 Datacenter · win-host-1.asgard.corp
Vulnerability scanner flagged one PowerShell script in /Sysmon/ as Malgent, three script alerts inside an uninstalled package directory (disabledefender-winconfig.nupkg), and two informational alerts on a built-in Windows modem driver (SmSerl64.sys). The report does not link these alerts to the PacketBuffer activity.
Vulnerability scanner listed 6,607 software package CVEs (Google Chrome, Edge, runtimes), recorded on 2026-09-04 between 14:20Z and 14:36Z.
packet_buffer.ps1, and tls.js.\\10.10.200.40\pcaps.Finding titles, severity labels, records, and timelines reproduced from the supplied test report.
Engine: Elastio Pursuit (Gate 4)Elastio confirmed the full chain. A scheduled task named PacketBuffer runs at every machine startup and launches packet_buffer.ps1 and tls.js. frida.exe injects tls.js into LSASS to harvest TLS secrets, and dumpcap.exe captures traffic. The capture is written to a share on another machine.
Four Defender protection settings were turned off in the registry, and the Microsoft Defender for Endpoint Sense service, the EDR component, was set to disabled.
packet_buffer.ps1 written to disk (hooks LSASS & TLS APIs).tls.js written to disk; data staged to \\10.10.200.40\pcaps.Security decision
Investigate the scheduled task, scripts, credential access, and capture destination while addressing the vulnerability backlog.
\PacketBuffer is enabled with an AtStartup trigger.frida.exe injects tls.js into LSASS.dumpcap.exe captures traffic to \\10.10.200.40\pcaps.packet_buffer.ps1e9776adb64a83154e447d9f359338997825a92d25b86f1a94f02cbdeb3b71ba7
tls.js9fd39e27ee523a7a583d26190b0c3feb3e7668611d21055c9f32ab7970c1df6a
Windows Server 2019 Datacenter · EC2AMAZ-SMASCMC
Vulnerability scanner reported two informational alerts on SmSerl64.sys, a built-in Windows modem driver, classified as a "LOLDriver".
Vulnerability scanner listed 14,353 package CVEs across the software installed on the machine.
sethc.exe and magnify.exe logon backdoor redirects.Finding titles, severity labels, records, and timelines reproduced from the supplied test report.
Engine: Elastio Pursuit (Gate 3)Two Windows accessibility programs, sethc.exe (Sticky Keys) and magnify.exe (Magnifier), were redirected in the registry to launch cmd.exe instead. The effect: anyone standing at the login screen, with no password, can press Shift five times and get a command window with full SYSTEM rights.
Inside aws-ec2-windows-password-update.ps1, Elastio found a fixed password passed directly to net.exe user Administrator <password>. Anyone who can read the script can read the password.
The registry policy SOFTWARE\Policies\Microsoft\Windows Defender\DisableAntiSpyware=1 was written on 2019-11-22T15:55:39Z and has suppressed that protection since.
Security decision
Investigate the registry redirects and exposed credential. A legitimate file signature does not establish that the system is configured safely.
Registry location:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
The sethc.exe and magnify.exe subkeys contain a Debugger value pointing to cmd.exe.
aws-ec2-windows-password-update.ps1 contains a fixed password passed to an Administrator password-update command. No credential value is reproduced here.
This is the September comparison run.
SANS SEC565 domain-controller training image · Windows Server 2022 Datacenter
Vulnerability scanner flagged SmSerl64.sys, the same built-in modem driver, as a "LOLDriver" in two system folders.
A package vulnerability list across the software installed on the domain controller.
spoolserver.exe.\fakespool launching it at boot as SYSTEM.Finding titles, severity labels, records, and timelines reproduced from the supplied test report.
Engine: Elastio Pursuit (Gate 3)Elastio identified spoolserver.exe, a small custom-built program (6,144 bytes) that pretends to be the Windows print spooler. A scheduled task named \fakespool launches it at every boot with SYSTEM rights, the highest privilege level on the machine.
Defender Tamper Protection, anti-spyware, and real-time monitoring were turned off in the registry, one after another. All three Windows firewall profiles (Domain, Public, Standard) were then disabled.
spoolserver.exe written to disk and linked to \fakespool boot task.Security decision
Review startup behavior before image approval. Intent matters: this is a training image, so the presence of attack code does not establish an unauthorized compromise of its publisher.
The report also identified disabled Defender settings and all three Windows firewall profiles, rated MEDIUM (GATE 2).
The executable was recorded on 2025-01-17T21:29:26Z. This report preserves the September assessment. A later run may differ.
SANS SEC699 penetration-testing workstation · Windows 10 Enterprise
Vulnerability scanner reported 4,474 malware rows. Of those, 3,983 (89%) point at documentation, HTML proof-of-concept pages, and exploit-db text files inside one unused folder (/ProgramData/chocolatey/lib/wsl-kalilinux/). These files cannot run.
Finding titles, severity labels, records, and timelines reproduced from the supplied test report.
Elastio Hunt + PursuitElastio inspected 790,605 files, opening zip archives layer by layer. Inside /Users/student/Downloads/attacking-trust-assets.zip, it unpacked and confirmed three working attack tools:
• mimikatz.exe (Generic.Trojan.Mimikatz)
• Rubeus.exe (Generic.Trojan.Rubbie)
• SpoolSample.exe (Generic.ShellCode.RDI)
Elastio's ransomware hunt identified 137 files with encryption damage inside testing directories.
Four Defender protection settings were off, and the Domain and Standard Windows firewall profiles were set to EnableFirewall=0.
Security decision
Review whether tools and configuration match the image’s intended use. Expected testing artifacts should not be presented as proof of a real-world intrusion.
790,605 files inspected. Archive: /Users/student/Downloads/attacking-trust-assets.zip.
Malware hunt: 2026-09-02T14:21:15Z to 15:54:56Z
Job: j-01m1h7k9w73fsdnj7tvb91knft.
Ransomware hunt: 2026-09-02T14:21:15Z to 15:10:53Z.
“Not reported” refers only to the supplied scanner results for these test systems.
| System | Vulnerability scanner | Additional Elastio evidence | Decision supported |
|---|---|---|---|
| Ransomware test | Cloud-configuration checks; no malware findings | Vega, affected files and directories, unmountable partition | Assess data damage |
| WinHostOne | CVEs and file alerts | Startup task, credential harvesting, traffic-capture destination | Investigate active compromise |
| Windows development | CVEs and driver notes | Registry redirects and exposed Administrator credential | Remove access and address secrets |
| PWNZONE training image | CVEs and driver notes | Custom executable tied to a SYSTEM boot task | Assess intended image behavior |
| CommandoVM training image | CVEs and malware alerts, including reference files | Archived tools, encryption damage, host-defense settings | Review artifacts in context |
Use both assessments in image approval.
Review vulnerabilities for patching and mitigation. Review compromise evidence to decide whether the image is suitable for deployment and whether existing systems need investigation.
Automatically discover images, analyze their contents, and route findings to the team responsible.
Elastio checks your private catalog and all images attached to instances for new images and versions.
Investigate system activity and inspect file contents. You can also invoke analysis through your workflow or a schedule.
Review the evidence and intended configuration before deciding whether to release, remediate, or rebuild.
If the image is already deployed
Review the servers launched from it, plus launch templates and scaling groups still pointing to it. Update the source and launch settings so replacement servers do not inherit the same problem.
Hourly is the discovery interval, not an analysis-completion guarantee. Your release process controls deployment. Source-image relationships do not by themselves prove compromise of every linked system.
Elastio-recorded comparison, September 2026. The underlying report is the source of these findings.
| System | Source image | Scanner timestamp (UTC) |
|---|---|---|
| Ransomware test | ami-04fca11ec6cc2ddab | 2026-09-04 19:37:32 |
| WinHostOne | ami-0f9c47f65b1138527 | 2026-09-04 14:47:22 |
| Windows development | ami-0c8d6702203cbdf7f | 2026-09-01 20:13:35 |
| PWNZONE | ami-0fd48271b21c38aa5 | 2026-09-01 20:13:35 |
| CommandoVM | ami-0b9c9327c8f68e2be | 2026-09-01 20:13:35 |
Pursuit reports were generated between 2026-09-03T21:52:23Z and 2026-09-04T02:06:49Z. Source report IDs: persistence-mt-int-2 / persistence-mt-int-2-integrated; session: pursuit_deterministic_closure. Case pages retain the available Hunt job identifiers.
Source: recorded-results report embedded in the supplied Elastio security-workshop presentation.