> ## Documentation Index
> Fetch the complete documentation index at: https://p-bitm-2269ecee.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Live sessions

> Understand VNC and Selkies live-session behavior and troubleshooting.

The **Victim** detail view exposes live browser controls only after an
authorized target has established a campaign session.

<Frame>
  <img src="https://mintcdn.com/p-bitm-2269ecee/9BS4YJCQtZV5PBjE/assets/screenshots/user-guide/live-sessions-viewer.png?fit=max&auto=format&n=9BS4YJCQtZV5PBjE&q=85&s=95a3aa70d9b670347440518255dc56b0" alt="Victim detail view with Live Control, screenshot gallery, and live keylog panels" width="2828" height="1570" data-path="assets/screenshots/user-guide/live-sessions-viewer.png" />
</Frame>

## Video demo

The recording uses a synthetic, authorized target to show the operator-facing
session view and evidence panels.

<Frame>
  <video alt="Operator view of a synthetic live session and evidence panels" controls playsInline preload="metadata" className="w-full rounded-xl" src="https://mintcdn.com/p-bitm-2269ecee/rZ_ctlIxJ7DPKLJt/assets/videos/getting_started/victim_dashboard.mp4?fit=max&auto=format&n=rZ_ctlIxJ7DPKLJt&q=85&s=cc9df870ee973a929f5e4024bb25e00c" data-path="assets/videos/getting_started/victim_dashboard.mp4" />
</Frame>

## Protocols

* **VNC** uses the VNC browser image and a proxied live view.
* **Selkies** (default) uses the Selkies image and exposes additional streaming-quality
  settings in the campaign wizard.

## Session behavior

Each victim session receives a dedicated browser container. The admin backend
validates campaign and victim ownership before returning stream access or
performing runtime actions.

If a stream does not become ready within the configured startup timeout, check
the campaign and target-session logs before recreating the session.

## Screenshots

Screenshots are captured only when an authenticated operator requests one.
They are taken inside the browser container and stored in the standard
campaign storage, and then shown in the victim gallery.

## Keylogger

Empty records are not intended to appear as copyable keylog blocks. Session
and timestamp markers provide context, while only actual key content is
copyable.
