Dynamic Threat Analysis for Container Images
ID: a06fec16-4482-57fd-bf2a-7414d5a201d7
STIX ID: report--a06fec16-4482-57fd-bf2a-7414d5a201d7
Feed Name: Aqua Security Blog
Aqua Security details the risk of malicious code hidden inside container images and OSS packages that evade static scanners and activate only at runtime, giving examples including a Docker Hub crypto-miner image (jzulu/xauto) and a credential-stealing Python package ('jellyfish'). The report presents Aqua's Dynamic Threat Analysis sandbox, which runs images in isolation to observe runtime behaviors (dropped/base64-encoded binaries, network activity, TOR usage, credential reads) and assess risk before images are deployed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
