Psminitsessionexe
It ensures that every action is fully monitored, video-recorded, and tied to keystroke logs from the exact moment of initialization.
When a user initiates an administrative connection via the CyberArk Password Vault Web Access (PVWA), PSMInitSession.exe intercepts the Remote Desktop Protocol (RDP) login shell. It prepares the sandboxed environment, registers tracking tokens, and hands control over to the correct target connection dispatcher. psminitsessionexe
The PVWA generates a dynamic Remote Desktop Protocol (.rdp) file containing encrypted session routing tokens and downloads it to the user's local machine. It ensures that every action is fully monitored,
PSMInitSession.exe is the wrapper executable that intercepts this incoming connection. Located by default in :\Program Files (x86)\CyberArk\PSM\Components\ , its core responsibility is to spin up the session architecture, enforce security parameters, and hand control over to specific connection dispatchers (such as those for RDP, SSH, Chrome, or database tools). The PVWA generates a dynamic Remote Desktop Protocol (
Because PSMInitSession.exe is essential for the secure monitoring and recording of privileged sessions, it must be protected and its integrity maintained. Do not attempt to move or rename this file.
If you have Pulse Secure/Ivanti software installed on your computer, this process is legitimate and safe. It is a helper application required to establish a secure connection to a corporate or private network.
However, malware authors sometimes name their payloads after legitimate processes. Several known malware families have used variations like psminitsession.exe , psm session.exe , or psminit.exe to hide in plain sight.