PutImage
PutImage
Event
Creates or updates image-manifest and tag metadata. Layer blobs are uploaded separately or must already exist; PutImage is not the layer-upload operation. Tag mutability settings can prevent overwriting an existing tag. Image digests identify manifest content independently of mutable tags.
Security Context
An attacker could implant an internal image (T1525), but ordinary CI pushes use this operation. A latest tag does not force running workloads to update. Establish malicious content, an accepted tag/digest change, and consumer pull/deployment behavior before claiming compromise.
Log Source
CloudTrail management event with eventSource: ecr.amazonaws.com and eventName: PutImage. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.registryId, repositoryName, imageTag | Destination and requested tag. |
requestParameters.imageManifest | Manifest descriptors; hashes alone do not establish payload behavior. |
responseElements.image.imageId | Returned digest/tag for correlation with consumers. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Verify caller, build provenance, repository ownership, and tag mutability.
- Compare old/new digests and inspect referenced content, signatures, and scan evidence. Confirm required layers existed and the registration succeeded.
- Correlate image pulls and deployments to the exact digest; GetAuthorizationToken is not proof of an earlier stolen-token chain.
Sample Event
Synthetic scenario. Draco registers a synthetic manifest under latest. Its placeholder layer digests and sizes do not represent a tested image or prove a backdoor; the response digest is computed from the illustrative manifest.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-16T00:02:48Z", "eventSource": "ecr.amazonaws.com", "eventName": "PutImage", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "repositoryName": "occamy-pipeline-base", "imageTag": "latest", "registryId": "555123456789", "imageManifest": "{\"schemaVersion\":2,\"mediaType\":\"application/vnd.docker.distribution.manifest.v2+json\",\"config\":{\"mediaType\":\"application/vnd.docker.container.image.v1+json\",\"size\":5921,\"digest\":\"sha256:b6faab4869fdc78ac815fb2a7858f88138f2680c5fecd38de4721d5adf312319\"},\"layers\":[{\"mediaType\":\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\"size\":43252507,\"digest\":\"sha256:f7e8bcd71231a171c5b3a394faa8b85b13380b2aab86ed5b65fdb1d6c2b5f028\"},{\"mediaType\":\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\"size\":2147483,\"digest\":\"sha256:6ea371b2599069b867aa8ad5ac9ba990ca4b5a5098cad1c3400adc304f1da309\"}]}" }, "responseElements": { "image": { "repositoryName": "occamy-pipeline-base", "registryId": "555123456789", "imageId": { "imageDigest": "sha256:b21f267715b02861b8dcbd95b832859b133e3534315e22a3eca58a60111fa872", "imageTag": "latest" }, "imageManifest": "{\"schemaVersion\":2,\"mediaType\":\"application/vnd.docker.distribution.manifest.v2+json\",\"config\":{\"mediaType\":\"application/vnd.docker.container.image.v1+json\",\"size\":5921,\"digest\":\"sha256:b6faab4869fdc78ac815fb2a7858f88138f2680c5fecd38de4721d5adf312319\"},\"layers\":[{\"mediaType\":\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\"size\":43252507,\"digest\":\"sha256:f7e8bcd71231a171c5b3a394faa8b85b13380b2aab86ed5b65fdb1d6c2b5f028\"},{\"mediaType\":\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\"size\":2147483,\"digest\":\"sha256:6ea371b2599069b867aa8ad5ac9ba990ca4b5a5098cad1c3400adc304f1da309\"}]}" } }, "requestID": "90000000-0000-4000-8000-000101101110", "eventID": "90000000-0000-4000-8000-000101101111", "readOnly": false, "resources": [ { "ARN": "arn:aws:ecr:us-east-1:555123456789:repository/occamy-pipeline-base", "accountId": "555123456789" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "api.ecr.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1525 — Implant Internal Image — Adversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google Cloud Platform (GCP) Images, and Azure Images as well as popular container runtimes such as Docker...