Could an attacker remain connected to the network?¶
Yes. An attacker may remain connected through remote access, malware, compromised accounts, wireless access, VPNs or another device on the network.
Avoid this assumption: Finding and disconnecting one suspicious device ends the intrusion. The attacker may have several sessions, accounts, persistence methods or routes into the environment.
Record visible active sessions, connected devices, remote-access tools, VPN entries, unusual accounts, security alerts and network connections.
Capture source and destination addresses, ports, times, device names and session identifiers where visible.
Do not start clicking through systems merely to hunt for the attacker. Uncontrolled activity may alter evidence, expose the investigation or trigger destructive action.
Likewise, do not assume every unfamiliar session is hostile. Administrators, service providers, automated tools and legitimate remote workers may appear unusual.
Where ongoing access is suspected, involve incident-response and network specialists quickly.
Containment may require more than unplugging one cable. Credentials, cloud sessions, remote-management tools, wireless networks and linked systems may all need assessment.
If immediate harm is occurring, use the narrowest effective measure and preserve the visible state where this can be done without unacceptable delay.
Record any cursor movement, new alert, session change, account activity or traffic pattern after first observation.
Keep technical access separate from personal attribution. A compromised account or device does not automatically identify the human operator.
Preserve any indication that the session is automated or persistent.
Operational takeaway¶
Assume an attacker may retain several access routes, preserve active sessions and network indicators, and use coordinated specialist containment rather than relying on one disconnection.