Advantages of Agentless Remote Session Auditing and Recording Systems Over Agent-Based Technologies
The purpose of this article is to highlight the key differences between session recording systems that use agents and Shell Control Box, which offers an agentless technology.
Problems of Agentic Technologies
Agent-based applications work on the principle of installing applications called agents on target systems and tracking user activity on the target system through these applications. Although they can transmit detailed user and system activity information, they cause some fundamental problems:
Difficulty of Maintenance
It is mandatory to install an agent on all servers and devices to be monitored. Even though these installations can be automated centrally up to a point, there is no chance of monitoring a system where an agent has not been installed yet.
Devices Failing to Install Agent
There is a requirement for agents to have a separate compatible version for every type of operating system, their versions, application servers, network and security devices currently used within the institution, and this is almost impossible. For instance, agents cannot be installed on network and security devices, therefore, the control of such devices and systems cannot be fully
They cannot. Considering that today's data centers are equipped with many operating systems (Windows, Linux, Unix), architectures (32-bit, 64-bit), and devices of different brands and models, agent-based solutions hit a roadblock at this point.
As a protocol-based solution, Shell Control Box can control and record all remote connections made via SSH, RDP, VNC, ICA, HTTP(s), and Telnet protocols without requiring any agents to be installed, regardless of the operating system or device.
Compatibility Issue
Enterprise applications and their administrators do not want agents installed on their systems, to the extent that any third-party application (agent) not certified by the application vendor [can be / is prohibited from being installed on the system]
installation voids the support agreements of enterprise software vendors such as SAP, ORACLE, and IBM. Therefore, these agents must be certified by the respective manufacturers.
Shell Control Box does not make any modifications to the target systems it controls and records, and it allows you to automatically generate compliance reports within itself for standards such as PCI-DSS, ISO 27001, COBIT, and HIPAA. It is compliant with BRSA (BDDK), EPDK, and CMB (SPK) regulations, as well as the KVKK (Personal Data Protection Law).
Lack of Connection Control
Because session recording management applications that use agents do not have control over the other end of the connection made to the systems they reside on, they cannot perform an audit on the subchannels of the protocols used in these connections. For example, in connections with subchannels like RDP and SSH, they cannot prevent file transfers or port forwarding.
With Shell Control Box, you can subject users' sending or receiving of files to target systems during SSH, RDP, and similar remote connections to permission, require prior approval from a senior manager before connection, and control all sub-channels belonging to these protocols.
For example, while users who are members of the IT_ADMIN group on AD can use features such as copy-pasting, disk mapping, and printer redirection on target systems, users connecting via external VPN
You can ban all of these or allow them with senior management approval.
Decommissioning of the Agent
Agents are applications running on controlled systems. Administrator-level users connecting to these systems can disable the agent, and there is no control mechanism for this. Similarly, a user with privileges on the system can tamper with the data generated by the agent.
This situation is similar to checking the logs on the same system to track authorized user activities or an attacker's movements on a compromised system; it is unreliable. For this reason, organizations implement centralized log management and forward system logs to remote systems. The same situation applies to agents as well.
Shell Control Box Since it independently tracks all communication between the connecting user and the target system, it is impossible for any endpoint to tamper with it. Records of all operations performed on the system are digitally signed by recording the TCP packets belonging to the connection, timestamped, and stored encrypted.
Records made by Shell Control Box are of the nature of forensic evidence, [indicating] that they have not been altered Evidence is available.
Shell Control Box, is the only protocol-based solution developed to control, audit, and record all remote connections made to critical systems and devices within the organization. It can record all connections made via SSH, RDP, VNC, ICA, HTTP(s), and Telnet protocols to the systems it brings under control.
Shell Control Box, integrated with your corporate directory, allows you to apply custom policies based on users or groups via AD (LDAP) for administrative tasks or connections. It is unique with its multi-domain support. Shell Control Box can store the files sent and received by users during connections made with these protocols in its own logging center for you to review later, or send them to your log management system or
It can route to your SIEM application.
In agent-based applications, since agents cannot be installed on the devices, connections to these devices are made not from the users' own computers, but by first connecting to a terminal server. This causes issues in operations such as file transfers and copy-paste actions
causes difficulties for users. With Shell Control Box, your users' work
Habits never change. You can continue working with remote connection tools like mRemoteNG, SecureCRT, Cord, and similar.
Shell Control Box, it can be integrated into the internal network very flexibly, in different Router or RDP Proxy modes. It can be deployed within hours with almost no need for any changes on the corporate network. When Shell Control Box needs to be updated, it keeps you
It also saves you the trouble of updating all agents. Similarly, you do not experience problems such as the agent becoming inactive or compatibility issues when the operating systems of the monitored systems are updated.
Shell Control Box, you can integrate it into your corporate network with a virtual or physical server, and use flexible high availability options for crisis scenarios.
Shell Control Box can be hosted within the corporate network, at a remote location, or even in the cloud. It is sufficient for users' remote connections to pass through the Shell Control Box proxy in order to apply your recording and auditing policies.


