PAM

Privileged Sessions

SSH and RDP sessions are brokered through CoreLink with full recording and command-level policy enforcement. Users never receive direct credentials -- instead, they request JIT access, which provisions ephemeral certificates (SSH) or temporary AD accounts (RDP).

Every keystroke is recorded in TTYRec format and stored gzip-compressed. The command interceptor buffers terminal input and checks each command against the target's policy before forwarding. Eight built-in preset groups cover common restriction scenarios, and custom block rules can target specific commands or patterns.

Privileged Sessions screenshot

Key Configuration

  • Recording retention period
  • Command policy presets (8 built-in groups)
  • Session idle timeout
  • Concurrent session limit
All documentation Question about this? Talk to us