I think we need more information. Do you run any services on that machine that would be exposed? Do you port-forward to that box? Use a VPN or something like Tailscale?
Or perhaps a sync client like syncthing, onedrive, nextcloud, etc. could be to blame.
One option would be to log all traffic on that machine to a .pcap and feed it through some IDS analyzers.