Websh session analysis

Session analysis is an AI review of a completed terminal (Websh) session that helps you assess what happened from a security standpoint. You’ll find it on a session’s detail page under Websh events.

Note: Session analysis is an experimental feature and may not be enabled in every workspace.

What it shows

The analysis assigns a risk level—Low, Medium, High, or Critical—and a summary, alongside key metrics:

  • Commands — how many commands were run.
  • Risk factors — how many risk factors were detected.
  • Confidence — the confidence of the assessment.
  • Attack chain — whether a chain of related actions was detected.

It then breaks the review into sections:

  • Activity — the executed commands and a timeline analysis.
  • Threat analysis — threat indicators such as malware tools, credential access, network artifacts, and sensitive file access.
  • Response guide — recommended actions and a verification guide.

Requesting an analysis

If a session hasn’t been analyzed yet, you can request one; the result appears once processing finishes. While it runs, the page shows that the AI is analyzing the session.

Last updated: