Hacker News new | ask | show | jobs
Show HN: Simple Technique to Audit/Replay All SSH Sessions (github.com)
1 points by cloudposse 3382 days ago
1 comments

The `sudo` command that ships with most Linux distributions has the native ability to record and replay entire sessions (both interactive and non-interactive). The `sudoreplay` command can replay those sessions (even sessions inside of `vim`).

Using the `sudosh` command as a user's login shell, you can force all sessions to be recorded. This is especially useful for bastion hosts or production systems.