Skip to content

PutImage

AWS

PutImage

service: AWS - ECR
tactics:
techniques:

Event

Creates or updates image-manifest and tag metadata. Layer blobs are uploaded separately or must already exist; PutImage is not the layer-upload operation. Tag mutability settings can prevent overwriting an existing tag. Image digests identify manifest content independently of mutable tags.

Security Context

An attacker could implant an internal image (T1525), but ordinary CI pushes use this operation. A latest tag does not force running workloads to update. Establish malicious content, an accepted tag/digest change, and consumer pull/deployment behavior before claiming compromise.

Log Source

CloudTrail management event with eventSource: ecr.amazonaws.com and eventName: PutImage. Check errors and resulting resource state; a null response does not by itself indicate failure.

Key Fields

FieldInvestigation value
requestParameters.registryId, repositoryName, imageTagDestination and requested tag.
requestParameters.imageManifestManifest descriptors; hashes alone do not establish payload behavior.
responseElements.image.imageIdReturned digest/tag for correlation with consumers.
eventTime, awsRegion, recipientAccountId, eventIDTimeline, service Region, account, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Verify caller, build provenance, repository ownership, and tag mutability.
  3. Compare old/new digests and inspect referenced content, signatures, and scan evidence. Confirm required layers existed and the registration succeeded.
  4. Correlate image pulls and deployments to the exact digest; GetAuthorizationToken is not proof of an earlier stolen-token chain.

Sample Event

Synthetic scenario. Draco registers a synthetic manifest under latest. Its placeholder layer digests and sizes do not represent a tested image or prove a backdoor; the response digest is computed from the illustrative manifest.

Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-16T00:02:48Z",
"eventSource": "ecr.amazonaws.com",
"eventName": "PutImage",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"repositoryName": "occamy-pipeline-base",
"imageTag": "latest",
"registryId": "555123456789",
"imageManifest": "{\"schemaVersion\":2,\"mediaType\":\"application/vnd.docker.distribution.manifest.v2+json\",\"config\":{\"mediaType\":\"application/vnd.docker.container.image.v1+json\",\"size\":5921,\"digest\":\"sha256:b6faab4869fdc78ac815fb2a7858f88138f2680c5fecd38de4721d5adf312319\"},\"layers\":[{\"mediaType\":\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\"size\":43252507,\"digest\":\"sha256:f7e8bcd71231a171c5b3a394faa8b85b13380b2aab86ed5b65fdb1d6c2b5f028\"},{\"mediaType\":\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\"size\":2147483,\"digest\":\"sha256:6ea371b2599069b867aa8ad5ac9ba990ca4b5a5098cad1c3400adc304f1da309\"}]}"
},
"responseElements": {
"image": {
"repositoryName": "occamy-pipeline-base",
"registryId": "555123456789",
"imageId": {
"imageDigest": "sha256:b21f267715b02861b8dcbd95b832859b133e3534315e22a3eca58a60111fa872",
"imageTag": "latest"
},
"imageManifest": "{\"schemaVersion\":2,\"mediaType\":\"application/vnd.docker.distribution.manifest.v2+json\",\"config\":{\"mediaType\":\"application/vnd.docker.container.image.v1+json\",\"size\":5921,\"digest\":\"sha256:b6faab4869fdc78ac815fb2a7858f88138f2680c5fecd38de4721d5adf312319\"},\"layers\":[{\"mediaType\":\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\"size\":43252507,\"digest\":\"sha256:f7e8bcd71231a171c5b3a394faa8b85b13380b2aab86ed5b65fdb1d6c2b5f028\"},{\"mediaType\":\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\"size\":2147483,\"digest\":\"sha256:6ea371b2599069b867aa8ad5ac9ba990ca4b5a5098cad1c3400adc304f1da309\"}]}"
}
},
"requestID": "90000000-0000-4000-8000-000101101110",
"eventID": "90000000-0000-4000-8000-000101101111",
"readOnly": false,
"resources": [
{
"ARN": "arn:aws:ecr:us-east-1:555123456789:repository/occamy-pipeline-base",
"accountId": "555123456789"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "api.ecr.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1525 — Implant Internal Image — Adversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google Cloud Platform (GCP) Images, and Azure Images as well as popular container runtimes such as Docker...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.