Session Recordings & Session Intelligence
Session Recordings
Cyolo records remote sessions to support audit, compliance, and incident investigation. The recording format and captured data vary by protocol:
| Protocol | Keystrokes Captured | Notes |
|---|---|---|
| RDP | Yes | Full keystroke and mouse recording; required for AI transcription |
| VNC | No | Single display only; no keystroke capture |
| SSH | Yes (text stream) | Text-based; fully searchable without video playback |
| Telnet | No | No keystroke capture |
Recordings are stored securely on the IDAC and are accessible to authorized auditors from the Recordings application.
Session Intelligence
Session Intelligence is a premium Cyolo add-on that transforms recorded sessions into human-readable summaries and searchable transcripts. It enables teams to quickly understand what happened during remote access sessions—without replaying lengthy recordings.
Why Session Intelligence
Instead of reviewing hours of recordings, teams get immediate, actionable insights:
- Accelerate incident response with clear, human-readable session summaries
- Reduce investigation time, MTTR, and review workload
- Identify user actions automatically and present them in a concise format
What It Produces
Session Intelligence analyzes recorded sessions and converts them into structured, searchable data:
- Human-readable summaries of user activity
- Searchable transcripts for fast investigation
- Clear visibility into actions performed during sessions
Who It's For
Session Intelligence supports a wide range of stakeholders:
- Cybersecurity Analysts – Investigate incidents faster
- OT Engineers – Validate actions and troubleshoot issues
- Plant Managers – Gain visibility into remote operations
- Auditors – Access clear, reviewable session records
How It Works
Session Intelligence operates within Cyolo's remote access workflows:
- Supports web-based RDP sessions
- Captures video recordings, keystrokes, and mouse movements from the session recording
- Processes session data to generate summaries and transcripts
Security and Privacy
Cyolo designed Session Intelligence to align with strict OT security and data governance requirements:
- Processing occurs entirely within the Cyolo environment
- Data is purged after processing
- Customer data is never used to train AI models
- Passwords, API keys, and other secrets are removed from the transcript
For more information on data processing, refer to the AI Addendum in your Cyolo EULA agreement.
Data Flow
To create a summary and transcript, Session Intelligence sends session data from your tenant to Cyolo's environment for processing. The following steps occur:
-
Upload. Your Cyolo tenant (IDAC) uploads the raw session recording. This file contains screen video, keyboard, and mouse activity.
-
Cloud storage. The recording is operated by Cyolo exclusively for this feature. Each tenant's files are stored in a separate folder.
-
AI processing. Each active video chunk, along with matching keystrokes and mouse actions as text, is sent to the AI model running in Cyolo's own cloud project.
-
Delivery to IDAC. When the transcript is ready, IDAC reads it and displays it in the UI.
-
Cleanup. Working files created during processing are removed as soon as they are no longer needed.
Enabling Session Intelligence
Session Intelligence is a licensed premium feature that must be activated by an administrator.
To enable it:
- In the Admin Portal, go to Configuration > Global Settings.
- Locate the Recordings section and toggle the Enable recording transcription option.
- Choose the operation mode:
- Auto mode – Automatically analyze all sessions
- On-demand mode – Analyze sessions only when needed
In addition, make sure the Record session toggle is enabled in the action policy of the sessions you want to record and transcribe.
Once enabled:
- In Auto mode, every new recording is automatically transcribed when the session ends. The Show Transcript action then becomes available on the recording row.
- In On-demand mode, the Generate Transcript action becomes available on each recording row, allowing you to trigger transcription manually.
Viewing a Transcript
Transcripts are accessed from the Recordings application. Each recording row includes the following actions:
- Generate Transcript – Submits the session for processing. Use this in on-demand mode, or to manually trigger analysis for a specific session.
- Show Transcript – Opens the generated transcript once processing is complete. The transcript displays a human-readable summary of activity that occurred during the session. From the transcript view you can:
- Browse the User Activity Timeline — a chronological breakdown of actions taken during the session
- Copy the transcript to clipboard for use in reports or incident tickets
SIEM and SOC Integration
Transcripts can be fetched programmatically via the Cyolo API, enabling integration with SIEM and SOC platforms. This allows security teams to ingest session transcripts into their existing workflows for correlation, alerting, and long-term retention.
Known Limitations
- Multi-user sessions – When multiple users join the same session, the transcript does not distinguish between them. All activity is attributed to a single session without identifying which user performed each action.
- Transcription applies to all recordings – Once Session Intelligence is enabled, transcription is applied globally to all eligible recordings. There is currently no option to enable or disable transcription per session or access policy. A per-policy control in the action policy is planned for a future release.
Getting Started
Session Intelligence is a premium feature available as an add-on subscription. To enable the feature or learn more, contact your Cyolo Customer Success manager or Sales representative.
Updated 7 days ago