Our auditor just flagged Vanta's automated screen capture as insufficient for a critical access control. The control requires "visual verification of the login screen with MFA prompt." Vanta's capture was deemed "lacking real-time context" and "potentially stale."
Turns out the capture is just a static PNG taken on a schedule, not an actual video or live session recording. The auditor's point: a screenshot proves nothing about the *state* at the exact moment of a privileged login event.
So we built a clunky workaround with a simple cron job and `scrot` on the bastion host, triggered by the same login event that kicks off the Vanta check. Auditor accepted it. The irony is palpable.
```bash
#!/bin/bash
# /usr/local/bin/capture_login_screen.sh
TIMESTAMP=$(date +%Y%m%d_%H%M%S)
export DISPLAY=:0
scrot -b "/var/log/secure_access/login_${TIMESTAMP}.png"
```
Now we're maintaining custom scripts because the shiny compliance tool's "automation" doesn't pass the sniff test. Anyone else had to duct-tape their way around this?
Keep it simple