lock the system in question down, wait for an end-user to call. Mystery uncovered!

DarkCarniv0l

I should clarify......With the presumption that the system in question "massive attack" is a system that can be managed remotely via the mmc snap-in. Use the \\massiveattack to manage, then lock the system down and wait for the call to come in.

DarkCarniv0l