Follow the finding.
Inspect the evidence.

Review the 42-of-500 research result, documented public-image cases, and actual product findings. Follow each assessment to its supporting evidence and confidence limits.

Pursuit · Agentic compromise investigation

Elastio research / 2026

42 of 500Public marketplace machine images
carried malicious persistence.

Elastio’s research identified malicious persistence in 42 of 500 public marketplace machine images. The result applies to the images analyzed. An image does not need to be running to retain the mechanisms an attacker could use.

Public Windows image / High confidence

A vulnerable driver configured to load, with offensive tools on disk.

The report records a DBUTIL auto-start service pointing to a vulnerable driver in the Administrator’s Downloads folder, historical execution of beacon_x64.exe, and a Cobalt Strike client still on disk.

The service, file, and execution records support the assessment. They do not by themselves establish who placed the tools there or whether the image was running at analysis time.

View report and artifact references
Report
persistence-ami-000672e12ac745f49
Analysis cited
June 2026
Recorded activity
May 5–9, 2025
Driver
DBUtil_2_3.sys
SHA-256
0296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5

A second driver referenced by the UmPass service was missing. Its content was not validated in the supplied summary.

Public Windows image / High confidence

A scheduled task downloads files and sends them through email.

The AutoMailJob report connects an Administrator scheduled task to gdrive_mail.ps1. The supplied timeline records 29 runs and a transcript of a Google Drive download followed by an email through Gmail.

The script and recorded activity support the described transfer behavior. The historical records do not establish that the task is executing now.

View report and artifact references
Report
persistence-ami-0ee99d8a17036d6e9
Analysis cited
June 2026
Recorded activity
April 7, 2026
Script
gdrive_mail.ps1
SHA-256
52a02a32d52454dc75bb23dbeaf6145002bb042a13dc529c91c727c6e5af54e7

The workshop also records an embedded Gmail app password. No credential value is reproduced here.

01 / Registry persistence

Legitimate programs.
An unexpected registry instruction.

Windows accessibility tools point to a command shell. The configured relationship gives the security team a specific mechanism to investigate.

F-IFEO-001 · High confidence

A registry instruction changes what Windows launches.

The report identifies debugger values for sethc.exe and magnify.exe that point to C:\windows\system32\cmd.exe. This configures an accessibility bypass at the logon screen.

What the evidence supports

The persistence mechanism is present in the inspected snapshot. The report found no execution telemetry in the windows around the registry writes, so it does not establish that the mechanism was used.

02 / PacketBuffer investigation

From the startup mechanism
to the behavior it enables.

The investigation connects the scripts, recurring execution, and supporting system records. Five findings have different confidence levels, with each conclusion tied to the evidence available.

F-001 · High confidence

A startup script captures TLS secrets.

The report connects packet_buffer.ps1 in Machine Group Policy Startup to Frida, lsass.exe, and tls.js. It describes TLS-secret capture and writes to a remote share.

What the evidence supports

The finding combines inspected script content with recorded execution. It identifies the capture chain; it does not claim that a fixed password or token was recovered.

Scope and sources

Evidence with its context.

The research result and two public-image case summaries come from Elastio research. The product galleries retain their own report identifiers and analysis versions. Screens are evidence views, not additional counted images. They are not presented as customer breach accounts.

What a result means

A finding concerns the inspected image or snapshot and its available evidence. A configured persistence mechanism can matter even when an image is not running. Current activity, historical execution, and expected legitimate behavior are separate questions.

What these views establish

These views show the product’s assessments and evidence records. This page does not independently re-examine the original disk snapshots, validate the entire attack history, or compare tool detection rates.

How to evaluate a finding

Review the source image or snapshot version, analysis time, supporting artifacts, and intended system use. Read the confidence and coverage limits with the conclusion.

Review what is inside your own critical systems.

Plan your evaluation