I just read this facinating article titled:

Forensic Analysis Without an IDS: A Detailed Account of Blind Incident Response

It describes how the author investigated and identifed a sophisticated hacker breaking into a military webserver.

http://www.fatelabs.com/papers/broken-walls.pdf