What logs may show remote access?¶
Remote access is usually reconstructed across application, identity, network and endpoint logs. The remote-access product's own history is important, but it may record only one part of the route.
A remote desktop connection through a VPN can generate VPN, identity-provider, gateway, operating-system and endpoint-security events. A support platform may identify its operator while the device records the local process. A web shell may appear through web requests and child processes rather than a conventional session log.
| Route component | Records that may help |
|---|---|
| Identity provider / VPN | authentication result, account, source, MFA, session or correlation ID |
| Gateway / jump host | external and internal route, connection time, destination |
| Remote-access platform | operator, target device, session, chat, transfer or recording |
| Endpoint | login/session events, processes, files, local network connections |
| Security tooling | alerts, process lineage, network telemetry and containment actions |
The useful record set depends on the route actually used.
Map the expected records from the route¶
First establish how the connection should have travelled. For each component, seek the native event time and time zone, account, source and destination, host or device identifier, authentication method and session ID. Commands, file transfers, reconnects and termination reasons add the activity within that session.
Shared identifiers provide the joins: a session ID can connect platform events; an account and timestamp can align authentication with an endpoint login; a source port and address can link network records. Preserve original timestamps because products may record connection, authentication and action at different moments.
Treat gaps according to coverage¶
Check whether logging was enabled, which licence tier applied, where records were stored and how long they were retained. A missing event is meaningful only if the source should reliably have captured and retained it.
Local records may have been deleted while provider or gateway logs survive. Conversely, a platform entry can show a connection to a relay without identifying the final controller. Record those boundaries rather than forcing several layers into a single event.
Prompt native exports preserve more detail than screenshots and reduce the risk that short retention or later enrichment changes what can be reviewed.
Key takeaway
Reconstruct remote access across the full route, correlate sources with shared identifiers, and interpret missing logs only in light of known collection and retention.