Could remote-access software be active?¶
Yes. A live computer may be controlled or observed remotely even when no other person is physically present.
Why this matters¶
The dangerous assumption is that the person at the keyboard must be the only active user. Remote desktop, support tools, browser-based control, administration software and malware can all provide access from elsewhere.
What to record and do¶
Record visible indicators such as remote-control banners, session notifications, unusual cursors, chat panels, support windows or connected-user messages.
Capture application names, usernames, hostnames, server addresses and timestamps where visible.
Do not click inside a remote session simply to test whether someone is connected.
Avoid closing the remote-access application or disconnecting the network until the evidential and operational effect is understood.
A remote user may be able to alter or delete evidence, but disconnection may remove visibility of their activity or terminate a useful session.
Where an active incident is suspected, seek specialist support quickly.
Record any unexpected cursor movement, window change, message or session warning after first observation.
Distinguish remote access from personal attribution. A remote connection may show that another system was involved, but not automatically who controlled it.
If containment is necessary to prevent harm, use the narrowest effective action and document the reason, timing and resulting change.
Check the wider screen for signs that control may be hidden behind another window or running in the background. Record whether the connection appears attended, unattended, authorised support, administrative access or potentially malicious, but do not decide attribution from appearance alone.
Operational takeaway¶
Assume remote access is possible on a live computer, preserve visible session indicators and obtain specialist advice before closing, disconnecting or interacting.