We had an iMac stolen. The thief has upgraded the OS and deleted users, but is still using the computer. It is faithfully reporting in to the JSS every 15 minutes. How can I copy the users home directory to a location on my servers to try ti identify the bad guy?
I obviously have his IP address, but the last time we had a situation like this, Comcast told LE that it would take 3-4 weeks to identify the crook by IP. (BS)
Anyway, I was thinking that if we could copy his home folder, we could possibly identify him I have an ftp server I could copy files to. I could make a policy to copy the files and hopefully pull some incriminating info.
