PAM Capability Design · RFP Evidence · v1.0 · June 2026

Session Monitoring,
Recording & Auditing

Management, monitoring, recording and auditing for privileged sessions - including remote RDP, SSH, and browser sessions.

Product ZenXPAM
Status Production capability
Prepared by Zenxsys
Zenxsys
ZenXPAMPAM
Section 1 · RFP Response

RFP Response Summary

Assessment requirement

Management, monitoring, recording and auditing for privileged sessions, including remote privileged sessions.

✓ Capability: Yes - Supported
FieldResponse
CoverageRemote RDP, SSH, browser PAM, RemoteApp, jump-server sessions - live view, record, audit
ApproachZenx Gateway broker + spectator mode + Zenx Gateway recording + immutable audit hash chain
AuditStart, spectate, command, terminate, recording events - tenant-scoped
Section 2 · Problem & Design Goals

Manage · Monitor · Record · Audit

Remote privileged sessions are the highest-risk PAM activity. ZenXPAM brokers every RDP, SSH, and browser path through a central console with live oversight, recording, and tamper-evident audit.

GoalDesign Choice
Remote coverageAll sessions brokered - RDP, SSH, browser, RemoteApp, jump server
Live oversightZenx Gateway spectator (shadow) - sub-second on LAN
RecordingZenx Gateway recording → local / S3 / Azure / GCS storage
Tamper evidenceaudit-service SHA-256 immutable hash chain
Supporting Links (RFP Portal)

Evidence References

#ReferencePath
1User guide - Privileged sessionsdocs/guides/user-guide/05-privileged-sessions.md
2Session access user guidedocs/guides/SESSION-ACCESS-USER-GUIDE.md
3PAM use cases (RDP, SSH, spectator)docs/guides/PAM-USE-CASES-AND-CONFIGURATION.md
4Audit chain of custodydocs/compliance/AUDIT-CHAIN-OF-CUSTODY.md
5Intent-locked sessions guidedocs/guides/INTENT-LOCKED-SESSIONS-OPERATOR-GUIDE.md
Suggested RFP comment (≤150 chars)ZenXPAM manages remote RDP/SSH/browser sessions via Zenx Gateway: live spectator, recording, command logs, terminate, and immutable audit chain for every action.
Zenxsys
ZenXPAMPAM
Sections 3–5 · Remote Sessions

Brokered Remote Privileged Sessions

Every remote session flows through Zenx Gateway - operators connect to ZenXPAM, not directly to targets with standing credentials.

RDPFull desktop
SSHTerminal
RemoteAppSSMS · PuTTY
BrowserWeb PAM
JumpDMZ bastion
1 · ConnectBrokered RDP/SSH/browser via Zenx Gateway
›
2 · MonitorLive spectator · command · keystroke capture
›
3 · RecordZenx Gateway recording → tenant storage backend
›
4 · AuditImmutable hash chain · export evidence
Live Session Viewer · Spectator Mode

Real-Time Remote Monitoring

Admin spectates active RDP/SSH session read-only via Zenx Gateway shadow mode. POST /api/connection/session/spectate - sub-second on LAN. SOC can terminate suspicious sessions with audited reason via sessions.terminate.

RecordSession Recording Pipeline

Capture during active remote session - policy-gated.

  • Zenx Gateway staging path (GUAC_RECORDINGS_PATH)
  • video-uploader processing & upload
  • Metadata linked in access-service
  • Play/download per retention policy
  • Recording size visible on session list
StoreTenant Config

Runtime storage configuration - no container restart.

  • Local · AWS S3 · Azure Blob · GCS
  • Cloud credentials stored in vault
  • /access/sessions/storage-config UI
  • Per-tenant retention policy
  • Integrity verification on playback
AuditHash Chain

Tamper-evident evidence for compliance investigations.

  • AuditLogs + ImmutableAuditLogs
  • SHA-256 linked blocks per tenant
  • Append-only API - no modify/delete
  • Export for SOC 2 · ISO 27001 evidence
  • Session lifecycle fully searchable
Audit EventSource
Session started / terminatedaccess-service · web-connector
Spectate startedweb-connector
Command blocked / alertedIntent locking · command rules
Recording uploadedSessionRecordingController

Session Management

  • Access → Active Sessions console
  • User · resource · protocol · risk score
  • Terminate with audited reason required
  • sessions.read · sessions.terminate permissions
  • Session detail - metadata, recording, commands

Monitoring Flags

  • EnableVideoRecording - video capture
  • EnableKeystrokeLogging - keystroke audit
  • EnableCommandLogging - default on
  • EnableFileTransferMonitoring - clipboard/file
  • StartMonitoringDto API per session

Command & Intent

  • Command rules - block · allow · alert
  • Intent locking - Monitor · Warn · Strict
  • AI session threat scoring (Ollama on-prem)
  • Risk tab on session detail view
  • Dangerous command alerts to SOC

Design Goals

  • Brokered remote access - no direct RDP/SSH
  • Tenant isolation on sessions & recordings
  • Terminate governance - reason required
  • Forensic replay + immutable audit chain
  • Jump-server & cloud console paths included

Forensic-ready remote sessions. Every brokered RDP, SSH, and browser session produces searchable audit events, optional video replay, and command evidence - including jump-server and cloud console paths.

Zenxsys
ZenXPAMPAM
Sections 6–8 · Workflows & API

API Surface & Security Controls

MethodEndpointPurpose
GET/api/v1/sessionsList active sessions
POST/api/v1/sessions/{id}/terminateTerminate with reason
POST/api/connection/session/spectateLive spectator view
POST/api/v1/session-monitoring/startEnable monitoring profile
POST/api/v1/sessions/{id}/recordingUpload recording metadata
MethodEndpointPurpose
GET/api/v1/auditlogsSearch session audit events
POST/api/v1/immutable-audit/appendAppend hash-chain entry
GET/api/v1/audit/exportCompliance export
Sections 9–12 · Security & Validation

Controls & PoC Checklist

ControlImplementation
Brokered remote accessNo direct RDP/SSH; vault inject server-side
Terminate governanceReason required; permission-gated
Recording retentionTenant policy; vault-stored cloud creds
Tamper-evident auditImmutable SHA-256 hash chain per tenant
ComplianceSOC 2 · ISO 27001 · PCI-DSS · HIPAA session evidence
Evaluator PoC Checklist
  • Start remote RDP or SSH session via brokered connect
  • Confirm session in Active Sessions with protocol and recording flag
  • Spectate active session in Live Session Viewer (read-only)
  • Terminate session with reason; user disconnected immediately
  • Verify start and terminate events in audit log
  • Complete session; confirm recording in storage (if policy enabled)
  • Trigger command rule block; verify audit entry
  • Export audit chain for session lifecycle
  • Configure recording storage without service restart
Version 1.0Date June 2026Author Zenxsys