Introduction
Suspecting that someone has accessed your computer without permission can be concerning, particularly when sensitive personal, financial, or business information may be involved.
From a digital forensic perspective, unauthorized access frequently leaves evidence within operating system logs, application databases, file system metadata, and network records.
Although users may attempt to conceal their activities by deleting files or clearing logs, many forms of computer activity generate multiple independent artefacts. A forensic examination aims to identify, preserve, and interpret these traces to determine:
- Whether the computer was accessed.
- When access occurred.
- How access was obtained.
- What actions were performed.
- Who may have performed those actions.
Common Signs of Unauthorized Access
Users often notice:
- Files modified unexpectedly.
- Browser history entries they do not recognize.
- Applications opening automatically.
- Changed passwords.
- New software installations.
- Missing or deleted files.
- Remote access software appearing.
- Security alerts from email or cloud services.
While these indicators can suggest unauthorized access, digital forensic evidence is required to establish what actually occurred.
Windows Login Evidence
Windows maintains several artefacts relating to user logins.
Security Event Logs
The Security event log records:
- Successful logins.
- Failed login attempts.
- Remote desktop sessions.
- Account lockouts.
- Privilege escalation events.
Important Event IDs include:
Event ID Description
4624 Successful logon
4625 Failed logon
4634 Logoff
4648 Explicit credentials used
4672 Administrative privileges assigned
Investigators examine:
- Username.
- Time and date.
- Logon type.
- Source system.
- Authentication method.
Logon Types
Windows records various logon methods:
Logon Type Meaning
2 Interactive local login
3 Network access
7 Unlocking workstation
10 Remote Desktop
11 Cached credentials
A Type 10 login may indicate remote access through Remote Desktop Protocol (RDP).
User Profile Evidence
Each Windows user account maintains a profile directory containing:
- Documents.
- Browser data.
- Recent files.
- Downloads.
- Application settings.
Investigators can determine:
- Last login times.
- Profile creation dates.
- Recently accessed documents.
- User-specific activity.
Recently Accessed Files
Windows records recent file activity through:
Jump Lists
These contain:
- Recently opened documents.
- Application usage history.
- File paths.
- Access timestamps.
Recent Files Folder
Locations include C:\Users\<User>\AppData\Roaming\Microsoft\Windows\Recent
These artefacts can demonstrate which documents were opened during a particular session.
File System Timestamps
Files contain several timestamps:
Timestamp Meaning
Created File creation time
Modified Last content change
Accessed Last access
Metadata Changed Attribute changes
If a file was accessed during a suspected intrusion period, the timestamps may support the allegation.
However, timestamps can sometimes be altered, requiring corroboration from additional evidence.
Browser Activity
Internet activity often provides strong evidence.
Investigators examine:
- Browsing history.
- Search terms.
- Download history.
- Cookies.
- Saved passwords.
- Session databases.
Examples include:
- Chrome History SQLite database.
- Edge browsing history.
- Firefox places.sqlite.
A user who accessed email, social media, or cloud accounts may leave browser artefacts.
USB Device Evidence
If someone physically accessed the computer using external devices, Windows may record:
- USB serial numbers.
- Device names.
- First connection dates.
- Last connection times.
Relevant registry locations include:
- USBSTOR
- MountedDevices
- DeviceClasses
Investigators can determine whether:
- A storage device was connected.
- When it was connected.
- Whether it had been connected previously.
Remote Access Evidence
Unauthorized access frequently occurs remotely.
Evidence may include:
- Remote Desktop
- Event logs.
- Terminal Services logs.
- RDP cache files.
Remote Access Software
Examples include:
- TeamViewer
- AnyDesk
- Chrome Remote Desktop
Artefacts may include:
- Installation records.
- Connection logs.
- Configuration files.
- Recent connection history.
Network Evidence
Network artefacts can reveal external connections.
Examples include:
- Firewall logs.
- Router logs.
- DNS cache.
- Wi-Fi connection history.
- VPN usage records.
Investigators may identify:
- External IP addresses.
- Remote servers.
- Connection times.
- Data transfers.
Malware and Remote Access Trojans
Attackers sometimes use malicious software.
Examples include:
- Remote Access Trojans (RATs).
- Keyloggers.
- Backdoors.
- Credential stealers.
Indicators include:
- Unknown startup programs.
- Suspicious network traffic.
- New user accounts.
- Disabled security software.
Memory analysis and malware examination may identify these threats.
Deleted Evidence
Individuals attempting to conceal access may:
- Delete files.
- Clear browser history.
- Remove logs.
- Uninstall software.
However, investigators may still recover evidence from:
- Unallocated space.
- Volume Shadow Copies.
- System restore points.
- Backup files.
- Journal files.
- Cloud synchronisation records.
Correlation of Evidence
No single artefact usually proves unauthorized access.
Instead, investigators correlate multiple sources:
Evidence Example
Login logs User logged in at 22:15
Browser history Email account accessed at 22:18
Recent files Confidential document opened at 22:20
USB artefacts External drive connected at 22:25
Network logs Remote IP connected at 22:30
The combined evidence can establish a timeline of activity.
Can You Identify the Person?
Determining who physically used a computer is often more difficult than proving that access occurred.
Digital evidence may identify:
- User account used.
- IP address.
- Device involved.
- Remote connection source.
- Authentication credentials.
However, if multiple individuals share a computer or account, additional evidence may be necessary.
Potential supporting evidence includes:
- CCTV footage.
- Access control records.
- Witness statements.
- Mobile phone location data.
- Cloud account activity.
Immediate Steps if You Suspect Unauthorized Access
- Do not continue using the computer unnecessarily.
- Photograph any suspicious screens or messages.
- Record dates and observations.
- Change important passwords using another device.
- Enable multi-factor authentication.
- Preserve logs and backups.
- Consider obtaining a forensic image of the system.
- Seek professional digital forensic assistance if legal proceedings are anticipated.
Conclusion
Proving that someone accessed your computer requires the examination of multiple digital artefacts. Login records, file timestamps, browser history, USB evidence, remote access logs, and network records frequently provide investigators with evidence of unauthorized activity.
While a single artefact may only indicate possible access, a properly conducted digital forensic examination can often establish when access occurred, how it happened, and what actions were performed on the system.
About Athena Forensics
For information on our computer forensic expert services or if you require any advice or assistance please contact a member of our team on 0330 123 4448 or via email on enquiries@athenaforensics.co.uk, further details are available on our contact us page.
Our client’s confidentiality is of the utmost importance. All correspondence is treated with discretion, from initial contact to conclusion of the matter.
We are fully aware of the significance and importance of the information that they encounter and we have been accredited to ISO 9001 for 14 years.
Our premises along with our security procedures have been inspected and approved by law enforcement agencies and we do not disclose personal information to other companies or suppliers.
Our team are all security cleared and we offer non-disclosure agreements if required.
Our premises along with our security procedures have been inspected and approved by law enforcement agencies.
Athena Forensics do not disclose personal information to other companies or suppliers.