Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a remote-access tool?

A remote-access tool is software or a service that lets a user view, control or administer another device from elsewhere. Its presence is common in legitimate support and system administration, so the useful question is whether a particular installation and session were authorised.

Depending on the product and configuration, a remote user may view the screen, control input, execute commands, transfer files, install software or establish unattended access. The available capabilities do not prove that each one was used.

Explain the route into the device

Identify the product, version and installation time, then establish how access was configured. Relevant material may include:

  • local and service-side account identifiers;
  • session start, end and reconnection records;
  • source addresses and connecting device names;
  • authentication and approval events;
  • unattended-access settings and saved credentials;
  • file-transfer, chat or command history; and
  • session recordings or administrative audit logs.

Licensing, subscription and organisational records can help show who controlled the service account and whether the installation had a recognised business purpose. Device records can then show what happened during the session.

Keep capability, session and controller distinct

Installed but inactive software establishes no remote session. A session record establishes a connection but may not show every action taken. The account named in that record may also be shared or compromised, and a source address may belong to a gateway or intermediary rather than the operator's own device.

Remote access can explain activity on a device while its owner is elsewhere, weakening any simple inference from physical possession. Conversely, a device owner may knowingly participate in a legitimate support session. Compare remote-access records with local input, authentication, process, file and communication evidence before drawing a conclusion about control.

Key takeaway

A remote-access tool is a channel with legitimate and malicious uses; establish its authority, configuration, actual sessions and resulting actions before attributing control.

Reference: CIM-080Cyber Incidents & Offender Methods