The activity is consistent with Virtual Network Computing (VNC) remote-control sessions. VNC provides interactive graphical access to another computer, which can manifest to the local user as unexpected mouse movement, windows opening, applications launching, or terminal sessions appearing without direct user interaction.
The network evidence distinguishes VNC from the other possibilities. Nmap's official VNC detection documentation demonstrates VNC services operating on TCP port 5900 and provides NSE functionality for querying VNC protocol versions and supported security mechanisms. When traffic logs show connections consistent with VNC services and users simultaneously observe visible remote desktop activity, VNC is the strongest correlation.
An internally addressable source address establishes only where traffic originated; it does not explain interactive mouse and keyboard activity. A reverse tunnel can provide an attacker with connectivity through network restrictions, but the tunnel itself does not identify the remote-control protocol responsible for the graphical symptoms. RDP can also provide interactive remote access, but it uses a different protocol and service profile; the traffic evidence in the scenario aligns with VNC instead.
An analyst should therefore correlate endpoint symptoms with network protocol and port evidence , rather than diagnosing remote access solely from visible user-interface behavior.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit