Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What logs may show remote access?

Remote access is usually reconstructed across application, identity, network and endpoint logs. The remote-access product's own history is important, but it may record only one part of the route.

A remote desktop connection through a VPN can generate VPN, identity-provider, gateway, operating-system and endpoint-security events. A support platform may identify its operator while the device records the local process. A web shell may appear through web requests and child processes rather than a conventional session log.

Route component Records that may help
Identity provider / VPN authentication result, account, source, MFA, session or correlation ID
Gateway / jump host external and internal route, connection time, destination
Remote-access platform operator, target device, session, chat, transfer or recording
Endpoint login/session events, processes, files, local network connections
Security tooling alerts, process lineage, network telemetry and containment actions

The useful record set depends on the route actually used.

Map the expected records from the route

First establish how the connection should have travelled. For each component, seek the native event time and time zone, account, source and destination, host or device identifier, authentication method and session ID. Commands, file transfers, reconnects and termination reasons add the activity within that session.

Shared identifiers provide the joins: a session ID can connect platform events; an account and timestamp can align authentication with an endpoint login; a source port and address can link network records. Preserve original timestamps because products may record connection, authentication and action at different moments.

Treat gaps according to coverage

Check whether logging was enabled, which licence tier applied, where records were stored and how long they were retained. A missing event is meaningful only if the source should reliably have captured and retained it.

Local records may have been deleted while provider or gateway logs survive. Conversely, a platform entry can show a connection to a relay without identifying the final controller. Record those boundaries rather than forcing several layers into a single event.

Prompt native exports preserve more detail than screenshots and reduce the risk that short retention or later enrichment changes what can be reviewed.

Key takeaway

Reconstruct remote access across the full route, correlate sources with shared identifiers, and interpret missing logs only in light of known collection and retention.

Reference: CIM-088Cyber Incidents & Offender Methods