User activity monitoring and fraud detection for host sessions

See what users do
and stop fraud inside legacy applications.

Zero Trust Network Access (ZTNA) limits who and which devices may reach the host. Sentinel complements that with continuous user activity monitoring and fraud detection inside the session: screens, commands, fields, and workflows—plus policy response when behavior turns risky. Not only recording and forensics.

How Sentinel complements ZTNA

ZTNA

Secure entry

Station or Portal with Director ensures limited, secure access for approved entities and devices only.

Sentinel

Secure use

After connect, Sentinel watches and governs host activity—detecting risky behavior, enforcing policy, and giving security teams the context to respond.

User activity monitoring and fraud detection

Host applications still process payments, customer records, privileged changes, and other high-value work. Sentinel watches that activity as it happens—and helps security teams detect and stop fraud before damage spreads.

User activity monitoring

Continuous visibility into host sessions

Monitor who is working, which screens and fields they touch, which commands and transactions they run, and how workflows unfold across terminal sessions—in real time, not only after an incident.

Screens and fields Commands and workflows Privileged actions Sensitive data access
Fraud detection

Spot suspicious behavior inside the application

Detect fraud patterns and high-risk actions that perimeter controls and basic application logs miss: unusual transaction paths, abnormal inquiry patterns, policy violations, and other terminal behavior that signals misuse or fraud.

Suspicious transactions Abnormal inquiry patterns Policy violations Insider misuse

Monitor. Detect. Respond. Investigate.

1

Monitor

Track user activity across terminal sessions—actions, screens, commands, and transaction context as work happens.

2

Detect

Flag fraud indicators, anomalous behavior, sensitive data access, and policy-relevant activity.

3

Respond

Escalate, require approval, block, or trigger step-up controls when fraud or high-risk workflows appear.

4

Investigate

Replay sessions and package evidence for fraud teams, audit, and incident response—when you need proof.

Modern security use cases

User activity monitoring

Know what happens after connect

Follow user behavior inside legacy applications with session-level context that basic logs cannot provide.

Fraud detection

Catch terminal fraud early

Identify suspicious transactions, misuse patterns, and insider risk before they become costly incidents.

Policy and evidence

Respond with proof

Match policy, drive approvals or blocks, and retain evidence-grade trails for audit and investigation.