logo

Dynamic Threat Analysis for Container Images

ID: a06fec16-4482-57fd-bf2a-7414d5a201d7

STIX ID: report--a06fec16-4482-57fd-bf2a-7414d5a201d7

Feed Name: Aqua Security Blog

Threat Score
75/100

Date Published: 2020-04-22

Date Updated: 2026-04-26

...
...

Aqua Security details the risk of malicious code hidden inside container images and OSS packages that evade static scanners and activate only at runtime, giving examples including a Docker Hub crypto-miner image (jzulu/xauto) and a credential-stealing Python package ('jellyfish'). The report presents Aqua's Dynamic Threat Analysis sandbox, which runs images in isolation to observe runtime behaviors (dropped/base64-encoded binaries, network activity, TOR usage, credential reads) and assess risk before images are deployed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.