Solutions / Machine image security
Your vulnerability scanner finds weaknesses. Elastio finds compromises.
A machine image can carry malicious code and attacker access into every server built from it. A vulnerability scan alone cannot establish whether it is compromised.
Image release workflow
Suggested integration into your release process. Your pipeline enforces approval; Elastio supplies analysis and evidence.
- 01 / PREPARE
Build or source an image
Your pipeline produces or references a specific image version.
- 02 / TEST
Analyze that version
Run Pursuit and Hunt alongside your functional and vulnerability checks.
- 03 / APPROVE
Apply your release policy
Review completed results for this version. Retest rebuilt images before approval.
- 04 / RELEASE
Distribute and deploy
Your pipeline releases the approved version for deployment.
Check what you are about to deploy.
Check for both software weaknesses and evidence of compromise.
Pursuit examines code and system records. Hunt inspects file contents without booting the image.
Two checks for image approval
Review vulnerabilities and evidence of compromise.
| Decision | Vulnerability assessment | Elastio |
|---|---|---|
| What to examine | Known software weaknesses that could be exploited. | Evidence of attacker access and activity in the system image. |
| What the team receives | Vulnerability findings to assess and remediate. | Findings with supporting paths, hashes, and system records. |
| What to do next | Patch or mitigate the identified weaknesses. | Investigate the evidence, address compromise, and reassess the image. |
See the recorded comparison from Elastio’s September 2026 report
Same system: WinHostOne. The recorded vulnerability scanner results list 6,607 package CVEs and six file alerts. Pursuit reported “PacketBuffer: TLS Secret Harvesting and Traffic Capture, Set to Run at Every Startup”, tagged CRITICAL (GATE 4).
Pursuit connected the startup task, its scripts, injection into LSASS, and the remote traffic-capture share. The PacketBuffer finding is absent from the recorded vulnerability scanner results.
Source: Elastio’s recorded comparison, September 2026. Results apply to the specified jobs on WinHostOne. The marketplace-image example below is a separate investigation.
Automatically analyze new images.
Elastio checks your private catalog and images used by your instances every hour. Pursuit and Hunt automatically analyze new images and versions.
- Hourly discovery
- API request
- Your schedule
What could this image bring into production?
A public Windows image contained a driver configured to load at every boot and records of Cobalt Strike execution. These are the kinds of findings a security team needs to investigate before approving an image.
Pursuit connected the startup configuration, files, and execution history. The evidence below shows what was present and what had run.
- Service
DBUTIL, auto-start- Driver
C:\Users\Administrator\Downloads\DBUtil_2_3.sys- Cobalt Strike
cobaltstrike.exe, still on disk- Other tools
- Metasploit framework v6.3.54 in Amcache; Process Hacker installed
- May 5, 2025
20:25:09 UTC - DBUtil_2_3.sys staged in the Administrator Downloads folder.
- May 5, 2025
20:26:21 UTC - DBUTIL service set to auto-start, loading the driver from Downloads.
- May 7, 2025
20:56:11 UTC - beacon_x64.exe executed, since deleted from disk.
- May 7, 2025
20:59:17 UTC - Cobalt Strike client launched from Desktop\Tools.
- May 9, 2025
12:51:38 UTC - Process Hacker run, its kernel driver service left behind.
- Driver SHA-256
0296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5- Cobalt Strike SHA-256
6aa576b6f8d1af7e76bf0ce3ce7225070ca80c7d3fd963776921c8c80b7ad88a
Another recorded image finding: AutoMailJob exfiltration
A scheduled task that moves files through Google Drive and Gmail every five minutes
- Task
\AutoMailJob· HighestAvailable · Administrator- Command
powershell.exe -ExecutionPolicy Bypass -File C:\scripts\gdrive_mail.ps1- Behavior
- Downloads from Google Drive and emails the file through
smtp.gmail.com. - Credential
- A Gmail app password was written into the script.
- Recorded activity
- 29 runs recovered from logs and the script’s transcript.
The downloaded file present on disk was a Google Drive warning page. The report did not identify the final payload family.
What Pursuit and Hunt examine
What the analysis examines
| Control | What it looks for | Evidence to review |
|---|---|---|
| Pursuit | Scheduled tasks, services, registry entries, and boot changes that preserve attacker access. | The trigger, what it launches, its execution account, and the supporting system records. |
| Pursuit | Malicious or disguised scripts, credential theft, and tampered security tooling. | Code behavior, file paths and hashes, configuration changes, and the recorded sequence of activity. |
| Hunt | Malware, ransomware, and corruption in the image’s file contents. | Affected files, detection results, and the scope of the affected data. |
Review the finding’s suspicion, confidence, and supporting evidence. A stored credential, disabled control, or security tool may have a legitimate purpose.
See the blast radius.
Recover from a last known clean AMI.
Trace an affected image to the servers built from it and the launch settings that still use it. Identify a last known clean AMI backed by Pursuit analysis.
Identify the exposure
DBUTIL service set to auto-start. Cobalt Strike execution recorded.
- Instance
- Instance
- Instance
Illustrative instance links, not recorded assets
- Launch templates
- Auto Scaling groups
References that could launch the affected version again
Identify the recovery image
Elastio shows this designation only for an AMI it has analyzed with Pursuit.
- AMI version
- Analysis date
- Supporting evidence
Update launch settings, replace affected instances, and validate the deployed systems.
How to use the recovery image
Review the AMI’s Pursuit analysis and suitability for the workload. Your cloud workflow updates launch templates and replaces instances. Restore application data separately where required, address the entry point, and rotate exposed credentials.
View the recorded source-image relationship
Source-image relationship / UAT example
ami-0fd48271b21c38aa5Source image recorded on the serveri-0298915cc3f975fc9At riskNo clean copy4 threats9 violationsView captured asset details
- Product tab
- Scope + Asset
- Machine image
ami-0fd48271b21c38aa5- Attached volume
vol-0868afee52c155ed9- Volume size
- 30 GiB
- Mount
/dev/sda1
The source screen states “Not recoverable - no proven-clean copy.” These are the captured server’s statuses, not an assessment of every server built from the image.
Detect compromise after deployment.
Pursuit and Hunt detect compromise and maintain recovery evidence.
Machine image security
See what is inside the images you deploy.
See automatic discovery, investigation evidence, and SIEM/SOAR delivery.