Skip to main content

Spectra Detect AMI Scanner — Agentless Malware Scanning for AWS

The Spectra Detect AMI Scanner analyzes AWS block-storage assets for malware without installing an agent, and without touching the workloads that use them. It works on Amazon Machine Images (AMIs), Amazon Elastic Block Store (EBS) volumes, EBS snapshots, and Kubernetes PersistentVolumes backed by EBS.

For each asset, the scanner creates its own snapshot and volume copy, attaches that copy to a dedicated scanner host, extracts the files it finds, and submits them to Spectra Detect for analysis. It then writes a report and deletes every temporary resource it created. The original asset is never mounted, never modified, and never deleted.

Scanning Without an Agent​

The scanner reads an asset's filesystem from the outside, through a snapshot copy, rather than from software running inside it. Nothing is installed on the asset, and nothing runs in the guest operating system.

This is what lets it scan assets that aren't running anything: an AMI that no instance has booted from yet, a detached volume, or a snapshot taken months ago. It also means a scan doesn't modify the running workload. When the target is an attached volume, the scanner snapshots it first and scans the snapshot, so the volume in use is never touched.

What It's Used For​

Scanning Images as They're Built​

Tag each AMI the build pipeline produces, and turn on the event-driven trigger. Every image that becomes available in the account is queued automatically, and the scan reports what Spectra Detect classified in it. With a Simple Notification Service (SNS) subscription on the results, that outcome reaches whoever needs it without polling for a report.

Sweeping the Account on a Schedule​

Turn on scheduled scanning to sweep every tagged asset on a recurring basis. A sweep re-scans assets whose contents may have changed since the last pass, and picks up assets that were tagged after their build finished.

Investigating a Suspect Instance​

Snapshot the volume of an affected instance, tag the snapshot, and queue it. The instance keeps running while its disk contents are analyzed, and the per-file verdicts name each file Spectra Detect classified as malicious or suspicious, with its path inside the scanned filesystem.

Recording What Was Scanned​

Reports are written to Amazon Simple Storage Service (S3) as JSON, with a full per-file verdict record alongside each summary. Both carry provenance - which scanner build ran, on which host, against which asset, at which time - so a report can be tied back to the scan that produced it.

How a Scan Works​

Three things can request a scan, and all three place a message on one queue: a manual request, an Amazon EventBridge rule that fires when an AMI becomes available, and a scheduled discovery run. A fleet of scanner instances drains that queue, one asset at a time per instance.

For each asset, the scanner:

  1. Checks that the asset carries the RLScan=true tag. An untagged asset is skipped without any resource being created.
  2. Confirms that the Spectra Detect endpoint is reachable and its queue isn't full.
  3. Copies the asset's snapshot, or takes a new snapshot if the asset is a volume. Assets that are already snapshots are used as they are.
  4. Creates a temporary EBS volume from that copy and attaches it to the scanner host.
  5. Mounts the temporary volume, walks its filesystem, and selects files according to the configured scan mode and filters.
  6. Hashes each selected file and submits it to Spectra Detect, then collects the verdicts.
  7. Writes a summary report and a per-file verdict record, optionally to S3, and optionally publishes a notification to SNS.
  8. Deletes everything it created - the mount, the volume, and its own snapshot - in reverse order. Cleanup runs even when the scan is cancelled or fails.

The copy is what keeps the scan safe. The asset under scan is never mounted, and a snapshot the scanner didn't create is never deleted.

note

The temporary volume is always mounted read-only, and every attempt carries nodev, nosuid and noexec. The scanner works through an ordered list of read-only option sets and takes the first the filesystem accepts, trying the variant that skips journal recovery ahead of the plain one - replaying a dirty journal would write to the filesystem being scanned. A filesystem that accepts none of them fails the scan rather than being mounted any other way.

Supported Assets​

Asset typeIdentifierNotes
AMIami-EBS-backed images. The root snapshot is what gets copied.
EBS volumevol-Attached and detached volumes alike. An attached volume is snapshotted first, so the running workload is never touched.
EBS snapshotsnap-Used as it is. The scanner creates a volume from it, and never deletes the snapshot.
Kubernetes PersistentVolumevol-Discovered through EBS Container Storage Interface (CSI) tags, and scanned as the underlying EBS volume.

Instance-store volumes, and any asset not backed by EBS, are out of scope.

What You Need​

RequirementNotes
A Spectra Detect deploymentA Worker endpoint or a Hub, reachable from the scanner's network, plus an API token.
The scanner machine imageSupplied privately by ReversingLabs. See Availability.
The deployment templatesTerraform, supplied with the scanner.
An AWS account, VPC, and subnetExisting. The templates never create a VPC.
Terraform 1.9 or newerEarlier versions reject the variable validation the templates use.

Availability​

The scanner machine image is shared privately with customers, and is not publicly available. The deployment templates and their documentation are published openly.

To request access to the scanner image for your account and region, contact ReversingLabs through your usual support channel.

Where to Next​

  • Deployment - install the stack, tag your first asset, and run a scan.
  • Configuration - scan modes, file filters, endpoints, and tags.
  • Scan Results - the report format, per-file verdicts, and notifications.
  • Security - the permission model, what runs with elevated privileges, and what leaves your account.
  • Limitations and Troubleshooting - what the scanner can't scan, and what to check when a scan doesn't behave.