Solutions / Machine image security

Your vulnerability scanner finds weaknesses. Elastio finds compromises.

A machine image can carry malicious code and attacker access into every server built from it. A vulnerability scan alone cannot establish whether it is compromised.

Image release workflow

Suggested integration into your release process. Your pipeline enforces approval; Elastio supplies analysis and evidence.

Your pipeline + Elastio analysis

  1. 01 / PREPARE

    Build or source an image

    Your pipeline produces or references a specific image version.

  2. 02 / TEST

    Analyze that version

    Run Pursuit and Hunt alongside your functional and vulnerability checks.

  3. 03 / APPROVE

    Apply your release policy

    Review completed results for this version. Retest rebuilt images before approval.

  4. 04 / RELEASE

    Distribute and deploy

    Your pipeline releases the approved version for deployment.

01 / Image approval

Check what you are about to deploy.

Check for both software weaknesses and evidence of compromise.

Pursuit examines code and system records. Hunt inspects file contents without booting the image.

Two checks for image approval

Review vulnerabilities and evidence of compromise.

DecisionVulnerability assessmentElastio
What to examineKnown software weaknesses that could be exploited.Evidence of attacker access and activity in the system image.
What the team receivesVulnerability findings to assess and remediate.Findings with supporting paths, hashes, and system records.
What to do nextPatch or mitigate the identified weaknesses.Investigate the evidence, address compromise, and reassess the image.
See the recorded comparison from Elastio’s September 2026 report

Same system: WinHostOne. The recorded vulnerability scanner results list 6,607 package CVEs and six file alerts. Pursuit reported “PacketBuffer: TLS Secret Harvesting and Traffic Capture, Set to Run at Every Startup”, tagged CRITICAL (GATE 4).

Pursuit connected the startup task, its scripts, injection into LSASS, and the remote traffic-capture share. The PacketBuffer finding is absent from the recorded vulnerability scanner results.

Source: Elastio’s recorded comparison, September 2026. Results apply to the specified jobs on WinHostOne. The marketplace-image example below is a separate investigation.

02 / Workflow and schedules

Automatically analyze new images.

Elastio checks your private catalog and images used by your instances every hour. Pursuit and Hunt automatically analyze new images and versions.

  • Hourly discovery
  • API request
  • Your schedule
IMAGE ANALYSISPursuit + Hunt
ALL FINDINGSSIEM / SOARYour integrated channels
For pre-deployment checks, invoke analysis through the API and have your pipeline wait for completed results before applying its release policy. Hourly discovery alone does not gate deployment.
03 / Inside a public marketplace image

What could this image bring into production?

A public Windows image contained a driver configured to load at every boot and records of Cobalt Strike execution. These are the kinds of findings a security team needs to investigate before approving an image.

Pursuit connected the startup configuration, files, and execution history. The evidence below shows what was present and what had run.

Another recorded image finding: AutoMailJob exfiltration

A scheduled task that moves files through Google Drive and Gmail every five minutes

high suspicionhigh confidence
Task
\AutoMailJob · HighestAvailable · Administrator
Command
powershell.exe -ExecutionPolicy Bypass -File C:\scripts\gdrive_mail.ps1
Behavior
Downloads from Google Drive and emails the file through smtp.gmail.com.
Credential
A Gmail app password was written into the script.
Recorded activity
29 runs recovered from logs and the script’s transcript.

The downloaded file present on disk was a Google Drive warning page. The report did not identify the final payload family.

What Pursuit and Hunt examine

What the analysis examines

ControlWhat it looks forEvidence to review
PursuitScheduled tasks, services, registry entries, and boot changes that preserve attacker access.The trigger, what it launches, its execution account, and the supporting system records.
PursuitMalicious or disguised scripts, credential theft, and tampered security tooling.Code behavior, file paths and hashes, configuration changes, and the recorded sequence of activity.
HuntMalware, ransomware, and corruption in the image’s file contents.Affected files, detection results, and the scope of the affected data.

Review the finding’s suspicion, confidence, and supporting evidence. A stored credential, disabled control, or security tool may have a legitimate purpose.

04 / Blast radius and recovery

See the blast radius.
Recover from a last known clean AMI.

Trace an affected image to the servers built from it and the launch settings that still use it. Identify a last known clean AMI backed by Pursuit analysis.

Image relationships and recovery

Recorded finding · Illustrative relationships

Identify the exposure

DBUtil driver and Cobalt StrikePublic marketplace Windows imagehigh suspicionhigh confidence

DBUTIL service set to auto-start. Cobalt Strike execution recorded.

  • Instance
  • Instance
  • Instance

Illustrative instance links, not recorded assets

  • Launch templates
  • Auto Scaling groups

References that could launch the affected version again

Identify the recovery image

Supported by Pursuit analysisLast known clean AMI

Elastio shows this designation only for an AMI it has analyzed with Pursuit.

  • AMI version
  • Analysis date
  • Supporting evidence
Replace through your deployment workflow

Update launch settings, replace affected instances, and validate the deployed systems.

How to use the recovery image

Review the AMI’s Pursuit analysis and suitability for the workload. Your cloud workflow updates launch templates and replaces instances. Restore application data separately where required, address the entry point, and rotate exposed credentials.

View the recorded source-image relationship

Source-image relationship / UAT example

Machine imageami-0fd48271b21c38aa5Source image recorded on the server
EC2 Instance · Windowsi-0298915cc3f975fc9At riskNo clean copy4 threats9 violations
View captured asset details
Product tab
Scope + Asset
Machine image
ami-0fd48271b21c38aa5
Attached volume
vol-0868afee52c155ed9
Volume size
30 GiB
Mount
/dev/sda1

The source screen states “Not recoverable - no proven-clean copy.” These are the captured server’s statuses, not an assessment of every server built from the image.

05 / Running systems

Detect compromise after deployment.

Pursuit and Hunt detect compromise and maintain recovery evidence.

Explore Active Compromise Detection

Machine image security

See what is inside the images you deploy.

See automatic discovery, investigation evidence, and SIEM/SOAR delivery.

Request a demo