Skip to content
Skip to main content
First Response & Preservation Technical Explainer

Could remote-access software be active?

Yes. A computer may be viewed or controlled from elsewhere through a remote-access tool such as Remote Desktop, Quick Assist, AnyDesk or TeamViewer, or through malicious software.

That route can be highly useful evidence. It may explain unexpected cursor movement, applications opening without local input, file transfer or commands apparently issued while nobody was at the keyboard.

Look for the route, not just the product name

Remote control normally involves several parts:

ControllerRemote computer or mobile deviceThe device from which somebody operates the session.
RouteProvider relay, gateway, VPN or direct serviceMay hold account, connection or session records.
Local clientRemote-access process or serviceMay show a banner, session code, account, process and network connection.
ActivityScreen, files, commands and applicationsShows what happened through the access route.

A single product label does not show whether the use was legitimate support, routine administration, access by an authorised user or hostile control. Preserve the whole route and the activity carried through it.

Record what is already visible

Useful indicators include:

  • session banners, codes or connection status;
  • product and process names;
  • account or operator labels;
  • remote hostnames, addresses or device names;
  • chat panels, file-transfer windows and permission prompts;
  • unexpected pointer movement, typing or window changes;
  • connection start, elapsed time and displayed time zone; and
  • local alerts or endpoint-security detections.

Record a baseline first, then note later remote changes with their time. That sequence can distinguish what was present when the computer was found from activity that continued afterwards.

Disconnection protects and destroys at the same time

A remote user may still be able to alter evidence or continue harm. Ending the connection may be necessary. It can also terminate a valuable session, remove visible operator details and change local, provider and gateway records.

Do not type into the session, close the software or disconnect merely to test whether somebody is there. Where action is required, use the narrowest effective containment and record the authority, reason, method, time and result.

The remote-access route can establish that technical control was available and show what a session did. Account labels and source addresses still need corroboration before they identify the person controlling it.

Reference: FRP-086First Response & Preservation