PAM
Privileged Sessions
SSH and RDP sessions are brokered through CoreLink with full recording and command-level policy enforcement. Users never receive direct credentials -- instead, they request JIT access, which provisions ephemeral certificates (SSH) or temporary AD accounts (RDP).
Every keystroke is recorded in TTYRec format and stored gzip-compressed. The command interceptor buffers terminal input and checks each command against the target's policy before forwarding. Eight built-in preset groups cover common restriction scenarios, and custom block rules can target specific commands or patterns.
Key Configuration
- Recording retention period
- Command policy presets (8 built-in groups)
- Session idle timeout
- Concurrent session limit