Websh session analysis
Session analysis is an AI review of a completed terminal (Websh) session that helps you assess what happened from a security standpoint. You’ll find it on a session’s detail page under Websh events.
Note: Session analysis is an experimental feature and may not be enabled in every workspace.
What it shows
The analysis assigns a risk level—Low, Medium, High, or Critical—and a summary, alongside key metrics:
- Commands — how many commands were run.
- Risk factors — how many risk factors were detected.
- Confidence — the confidence of the assessment.
- Attack chain — whether a chain of related actions was detected.
It then breaks the review into sections:
- Activity — the executed commands and a timeline analysis.
- Threat analysis — threat indicators such as malware tools, credential access, network artifacts, and sensitive file access.
- Response guide — recommended actions and a verification guide.
Requesting an analysis
If a session hasn’t been analyzed yet, you can request one; the result appears once processing finishes. While it runs, the page shows that the AI is analyzing the session.