Into The Weeds: How We Run Detonate
ID: d596af2b-c600-5ec0-b4b9-84f3f52a562a
STIX ID: report--d596af2b-c600-5ec0-b4b9-84f3f52a562a
Feed Name: Elastic Security Labs
This report outlines the design and operation of Elastic’s Detonate sandbox pipeline, including a FastAPI-based server with CLI/Web/UI/HTTP interfaces, SQS-backed queues, and Python workers that orchestrate detonations across Windows/Linux VMs in GCP and macOS VMs on AWS using Anka. It explains minimal-footprint VM provisioning via startup scripts, locked-down network egress with VPC routes/firewall/security groups and flow logs, and comprehensive telemetry collection using Elastic Agent in detect mode for validation and research. The team reports stable production performance (up to 1,034 detonations/day) and typical task completion under 13 minutes, with ongoing efforts to broaden OS coverage and optimize provisioning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
