
Management, monitoring, recording and auditing for privileged sessions - including remote RDP, SSH, and browser sessions.

Management, monitoring, recording and auditing for privileged sessions, including remote privileged sessions.
| Field | Response |
|---|---|
| Coverage | Remote RDP, SSH, browser PAM, RemoteApp, jump-server sessions - live view, record, audit |
| Approach | Zenx Gateway broker + spectator mode + Zenx Gateway recording + immutable audit hash chain |
| Audit | Start, spectate, command, terminate, recording events - tenant-scoped |
Remote privileged sessions are the highest-risk PAM activity. ZenXPAM brokers every RDP, SSH, and browser path through a central console with live oversight, recording, and tamper-evident audit.
| Goal | Design Choice |
|---|---|
| Remote coverage | All sessions brokered - RDP, SSH, browser, RemoteApp, jump server |
| Live oversight | Zenx Gateway spectator (shadow) - sub-second on LAN |
| Recording | Zenx Gateway recording → local / S3 / Azure / GCS storage |
| Tamper evidence | audit-service SHA-256 immutable hash chain |
| # | Reference | Path |
|---|---|---|
| 1 | User guide - Privileged sessions | docs/guides/user-guide/05-privileged-sessions.md |
| 2 | Session access user guide | docs/guides/SESSION-ACCESS-USER-GUIDE.md |
| 3 | PAM use cases (RDP, SSH, spectator) | docs/guides/PAM-USE-CASES-AND-CONFIGURATION.md |
| 4 | Audit chain of custody | docs/compliance/AUDIT-CHAIN-OF-CUSTODY.md |
| 5 | Intent-locked sessions guide | docs/guides/INTENT-LOCKED-SESSIONS-OPERATOR-GUIDE.md |

Every remote session flows through Zenx Gateway - operators connect to ZenXPAM, not directly to targets with standing credentials.
Admin spectates active RDP/SSH session read-only via Zenx Gateway shadow mode. POST /api/connection/session/spectate - sub-second on LAN. SOC can terminate suspicious sessions with audited reason via sessions.terminate.
Capture during active remote session - policy-gated.
Runtime storage configuration - no container restart.
Tamper-evident evidence for compliance investigations.
| Audit Event | Source |
|---|---|
| Session started / terminated | access-service · web-connector |
| Spectate started | web-connector |
| Command blocked / alerted | Intent locking · command rules |
| Recording uploaded | SessionRecordingController |
Forensic-ready remote sessions. Every brokered RDP, SSH, and browser session produces searchable audit events, optional video replay, and command evidence - including jump-server and cloud console paths.

| Method | Endpoint | Purpose |
|---|---|---|
| GET | /api/v1/sessions | List active sessions |
| POST | /api/v1/sessions/{id}/terminate | Terminate with reason |
| POST | /api/connection/session/spectate | Live spectator view |
| POST | /api/v1/session-monitoring/start | Enable monitoring profile |
| POST | /api/v1/sessions/{id}/recording | Upload recording metadata |
| Method | Endpoint | Purpose |
|---|---|---|
| GET | /api/v1/auditlogs | Search session audit events |
| POST | /api/v1/immutable-audit/append | Append hash-chain entry |
| GET | /api/v1/audit/export | Compliance export |
| Control | Implementation |
|---|---|
| Brokered remote access | No direct RDP/SSH; vault inject server-side |
| Terminate governance | Reason required; permission-gated |
| Recording retention | Tenant policy; vault-stored cloud creds |
| Tamper-evident audit | Immutable SHA-256 hash chain per tenant |
| Compliance | SOC 2 · ISO 27001 · PCI-DSS · HIPAA session evidence |