Skip to main content
WarnHack
WarnHack
Use case · WarnHack Terminal

SSH session recording that auditors and eng leads can read

Knowing that port 22 accepted a connection is not enough. You need who connected, which host, and what they executed. WarnHack Terminal’s CloudRelay records sessions and commands into a trail you can review and export.

See a real session trail on your own host — free tier available.

Why basic SSH logs fall short

  • auth.log shows a login — not the commands that matter in an incident
  • script / ttyrec on each host does not scale and is easy to disable
  • SIEM pipelines get noisy auth events without human session context
  • Customer questionnaires ask for privileged session monitoring — screenshots of configs do not impress
  • Shared accounts make attribution impossible even with perfect keystroke logs

What CloudRelay gives you

  • Per-user session history tied to real identities
  • Command-level visibility for investigations and coaching
  • Exportable evidence for SOC 2, ISO 27001, and security reviews
  • Works with your access model — roles, revoke, time-bound grants
  • No DIY session-recorder fleet to maintain on every box

How recording works with Terminal

  1. 1

    Access flows through CloudRelay

    Interactive sessions are mediated so recording and policy enforcement are automatic — not optional host agents per engineer.

  2. 2

    Review in the product

    Eng and security leads see activity without SSHing into a log server to reconstruct asciinema files.

  3. 3

    Feed compliance workflows

    Export or screenshot evidence for audits; pair with SIEM if you already centralize alerts.

Session recording rollout checklist

  • Define which environments require full command audit (usually prod first)
  • Enable Terminal access for the team that touches those hosts
  • Verify a test session appears with expected command detail
  • Set retention expectations with security/compliance
  • Link recording policy in your information security policy
  • Optional: forward high-level alerts to your SIEM while keeping full detail in Terminal

FAQ

Is this full video replay or command logs?

CloudRelay focuses on access and command-level audit suitable for investigations and compliance. Talk to us if you need a specific recording format for your program.

Does recording slow engineers down?

Recording is part of the access path — teams get browser SSH and roles without running local recorders. The goal is visibility without ceremony.

Can we still ship logs to a SIEM?

Yes. Many teams keep SIEM for alerts and use Terminal as the system of record for interactive sessions.

Put this use case into production

See a real session trail on your own host — free tier available.