Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What does an interactive remote session prove?

An interactive remote session can show real-time control in which activity responds to the system's current state. It may support an inference of human decision-making, but it does not identify the person at the keyboard.

Sequential commands, mouse or keyboard events, changing windows, chat, screen control and responses to unexpected output can distinguish manual navigation from a fully pre-planned automated task. A remote desktop session is one common source of this kind of evidence. Session recordings may make that interaction particularly clear.

Interactive sessionActivity reacts to what happens nextChanging windows, correcting errors or responding to prompts can support real-time decision-making.
Automated taskPredefined activity runs without live responseA script or scheduled job can issue many actions without a person controlling each step at that moment.

Preserve the session as a connected record

Capture the session identifier, operator and device accounts, source connection, start and end times, commands, transfers and any recording. Some platforms distinguish the support operator from the local account; retaining both prevents those roles being collapsed.

Confirm what a recording contains. It may start late, omit privileged screens or capture only one display. Recording metadata and product configuration help explain those limitations.

Interactivity can support narrow conclusions about timing and response. For example, an operator who changes course after an error was likely reacting to the system. Typing style or tool preference, however, is weak personal identification without wider evidence.

The operator may still be remote from the source

A session can be controlled through a shared or compromised account, a jump host, cloud desktop, proxy or another victim's device. One person may establish access while another directs the actions. Infrastructure ownership and physical location therefore remain separate questions.

Correlate platform authentication, source-device evidence, communications and seized-device material before naming a controller. State what the session demonstrates - manual control, particular actions or responsive decisions - without extending it beyond the records.

Key takeaway

Interactive-session evidence can demonstrate responsive, real-time control; it cannot by itself prove the controller's identity or physical location.

Reference: CIM-086Cyber Incidents & Offender Methods