Best bet would be to get yourself some third party software like a firewall that will identify the culprit. Bear in mind, not all of the addresses it gives you are the actual "hacker".
How are they logging in? If it is via IIS then look at the logs in c:\winnt\system32\logfiles
Otherwise - if you mean file shares etc - then switching auditing on for logon/logoff events and examine the event log. That will usually give a machine name - then just go to DNS server and reverse lookup the thing. If it has been cleared out of there you could always check DHCP leases - and also the WINS name lookup.
M.
Hollingside Technologies, Making Technology work for you.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.