Solutions / Cloud transformation
Find compromised systems before they move to the cloud.
Identify attacker access, malicious code, and compromised data before carrying them into your new environment.
Investigate source systems, review findings after remediation, and identify a clean recovery copy before retiring the old environment.
Your migration project
Pursuit and Hunt investigate VMware workloads for compromise before they move to AWS or Microsoft Azure. Hunt checks on-premises files for ransomware, malware, and corruption before they reach Amazon FSx for NetApp ONTAP. After the move, analysis continues.
Continue analysis and maintain compromise and recovery evidence.
Check for compromise before migration.
An application can work while an attacker retains access. A file transfer can complete while carrying encrypted, corrupted, or malicious files into the cloud.
Analyze the source before the move and review unresolved findings before accepting the destination.
- 01 / SOURCE
Find compromise.
Analyze the systems and files in scope.
- 02 / REMEDIATION
Address findings.
Remediate affected systems and analyze again.
- 03 / DESTINATION
Assess readiness.
Review completed checks and unresolved findings.
- 04 / OPERATIONS
Continue analysis.
Continue analysis and maintain compromise and recovery evidence.
Identify attacker access in the source systems.
Pursuit investigates system copies for malicious code and evidence that an attacker has gained or retained access.
Review findings with the team responsible for remediation. Analyze the affected systems again before proceeding.
- Anchor
- 2019-10-08T18:15:37Z
- Detected
- 2026-10-04T00:25:00Z
- Report
- pursuit-EC2AMAZ-SMASCMC-20261004
Registry entries redirect magnify.exe and sethc.exe to C:\windows\system32\cmd.exe.
This creates a command-shell launch path when either accessibility program is invoked.
- Evidence reference
- E-IFEO-001
- Source
- Windows registry
- Persistence type
- IFEO debugger
- Programs
magnify.exeandsethc.exe- Debugger value
C:\windows\system32\cmd.exe- Finding references
- E-IFEO-001 · E-HOST-001 · E-TIMELINE-001
The registry evidence establishes the mechanism. Missing execution records limit confidence about whether it was used.
Check file data before it reaches FSx.
A completed transfer can include ransomware-encrypted files, malware, or corrupted data.
Hunt analyzes file data for ransomware encryption, malware, and corruption. Use the findings to identify affected files and address them during your migration to Amazon FSx for NetApp ONTAP.
Agree where analysis runs in your transfer process and review its coverage before relying on the results.
- Affected files
- 75
- Directories
- 2
- Candidate family shown
- WannaCry
- Path
- G:/file-sample_100kB.rtf.WNCRY
- Signal
- WannaCry
- Size
- 98.5 KB
- First seen
- 2026-09-13T02:32:10.264Z
The selected file has a WannaCry signal. Other files in the captured list have UNKNOWN signals; those are not relabeled as zero-day detections.
The source screen reports that a clean copy is available. Its evidence must be reviewed separately.
Review the results before accepting the environment.
Review completed analysis through the supported workflow for your destination. Use the results alongside application and infrastructure tests to decide what is ready to enter service.
Record the results for each workload or dataset, including incomplete checks and unresolved findings.
Identify a clean copy before retiring the source.
Before retiring the source environment, establish which recovery copy meets your security and recovery requirements.
Review the applicable analysis results and the age of the clean copy. Address incomplete checks or a copy that is too old while the migration team can still act.
Avoid recovery investigation during an outage.
Finding a clean recovery source during an incident can add hours while systems remain down.
Continue analysis after migration so the operations team inherits current findings and recovery evidence. Elastio starts the recovery handoff; your tooling performs the restore.
The Hunt history marks this copy clean.
The asset has 13 violations and no Pursuit run in the last 180 days. This example does not establish that all recovery requirements are met.
This is a separate asset from the Pursuit and ransomware examples above. The rows are selected from the captured history; they are not a migration sequence.
Review the required system and data checks for the same copy before establishing recovery readiness.
Plan your evaluation
Evaluate one VMware workload or file share.
Bring your source, destination, and migration schedule. Confirm where analysis runs, review the findings, and assess a recovery copy against your requirements.