Think someone knows your computer's password and has been using it without your permission? Whether it's a roommate, coworker, or family member, it's worth checking before jumping to conclusions. Fortunately, Windows keeps various logs and activity records that can help you determine whether someone has accessed your computer without your knowledge.
Check for an Active Remote Connection
Someone doesn't need physical access to your computer to snoop on it. They could also connect remotely using Remote Desktop or third-party tools like AnyDesk or TeamViewer. Open Task Manager and check whether any remote access apps are running in the background. If you find one, open it and review its active sessions, connection history, and permission settings.
In case you don't use the app, close it or uninstall it. If you don't use remote access software, go to Settings > System > Remote Desktop and make sure Remote Desktop is turned off.

For a more thorough check, open Command Prompt, type "netstat -ano," and press Enter to view all active network connections. Note the "PID (Process ID)" of any suspicious connection, then match it with the corresponding process in Task Manager to identify which application is using it. If you find a suspicious process, investigate it further.


Best Deals: YubiKey 5 NFC Security Key
Price Trend:
Prices last scanned 1 hour and 55 minutes ago
If you believe someone is accessing your computer in person rather than remotely, continue with the remaining checks.
Review Your Sign-In or Power and Wake History
If you think someone knows your password and has signed in to your computer, reviewing your recent sign-in history can help confirm your suspicion. If you use a Microsoft account, you can check your recent sign-in activity online. It shows when and where your account was accessed, along with other useful details, helping you spot any unfamiliar sign-in attempts.
You can also check sign-in activity directly on your PC using Event Viewer. Right-click the Start button, open "Event Viewer," then go to Windows Logs > Security and look for Event ID 4624, which records successful sign-ins. Check the timestamps of these events and see if any occurred when you know you weren't using your computer.
Our Latest TweakTown Guides
- 6 Task Manager tips for troubleshooting Windows performance problems
- Six File Explorer tips every Windows user should know
- I switched my PC to encrypted DNS in Windows 11, and browsing felt more private
- Printer Not Working in Windows? How to fix detection, print queues and drivers
- The Ultimate Guide to Personalizing Your Windows 11 Taskbar

You can also review Event IDs 6005 and 6006, which are logged when the Windows Event Log service starts and stops, typically during system startup and shutdown.

Frequently Asked Questions
TweakBot answers common questions about this guide using TweakTown's own coverage from this page and related content from our archive. Tap a question to reveal the answer, or type your own below.
How can I check if Remote Desktop is enabled on my Windows PC and disable it if I don't use it?
Which Task Manager entries or remote-access apps should I look for to spot unauthorized remote connections?
How do I use netstat -ano and Task Manager together to identify suspicious network connections and their processes?
Where in Event Viewer can I find sign-in events and which Event IDs indicate successful sign-ins or system start/shutdown?
Have a question not listed here? Ask below and TweakBot will answer it.
See Which Files Were Recently Opened
If someone has used your computer, there's a good chance they opened documents, photos, spreadsheets, or other files. Unless you've disabled the feature, Windows keeps a record of recently accessed files, which can help you determine whether someone used your PC while you were away.
Open File Explorer and go to the "Home" page. Under the "Recent" section, you'll find files that were recently opened or modified. If you notice files you don't remember accessing, especially if their timestamps match the period when you suspect someone used your computer, it could be a sign of unauthorized access.

You can also check the Recent lists in apps like Microsoft Word, Excel, and other apps you use, which can provide clues if someone has been using your computer.
Check Your Browser History for Unfamiliar Activity
If someone accessed your computer, they may have used your web browser to visit websites, search for something, or sign in to an online account. Open your browser and go to the "History" page, then look for any websites you don't recognize or activity that took place while you weren't using the computer.
If you use multiple browsers, such as Microsoft Edge, Google Chrome, or Firefox, review the browsing history in each one.

Keep in mind that this isn't conclusive evidence. The person may have used Incognito or Private mode, or simply cleared the browsing history. However, if they forgot to do so, you may find useful clues. It's also worth checking your email inbox for security alerts or sign-in notifications from your online accounts, which could indicate that someone attempted to access them.
What to Do If You Confirm Someone Has Accessed Your Computer
Whether you find clear evidence of unauthorized access or not, it's a good idea to secure your computer and accounts. If your PC doesn't have a password, set one up immediately. If it already uses a password, PIN, or another sign-in method, change it. If you sign in with a Microsoft account, change your Microsoft account password as well.
You should also enable two-factor authentication (2FA) if you haven't already. Next, run a full scan with Microsoft Defender to check for malware, and review your installed apps. Remove any remote access software or other programs you don't recognize or don't remember installing. It's also worth checking your user accounts.
Go to Settings > Accounts > Other Users, and make sure there aren't any unfamiliar accounts with access to your PC. Finally, if you believe someone had physical access to your computer, avoid leaving it unlocked or unattended. Lock your PC whenever you step away and take other sensible precautions to protect your personal data from unauthorized access.

The checks above can help you determine whether someone has accessed your computer without your permission, but don't rely on a single clue. Many of these signs can have perfectly legitimate explanations. Instead, look for multiple pieces of evidence that point to the same conclusion before assuming your PC has been compromised.
Whether you find evidence of unauthorized access or not, it's always worth taking a few preventive steps to better protect your computer and personal data in the future.





