Re: We've been compromised, now what...

From: name@company.com
Date: 05/29/02


From: name@company.com
Date: Wed, 29 May 2002 14:05:47 -0400

On Tue, 28 May 2002 20:43:42 GMT, "rr" <smrtalec@earthlink.net> wrote:

 If you wish to catch you would be attacker set up a fake pdc in a
>somewhat available portion of your network. then have a program like tekfact
>(sorry no link) that will monitor everything that happens locally. and also
>log every packet that goes to

I think you actually mean TechFacts from Dean Software and you can
find it here:
http://www.winutils.com/

Tekfacts was the abreviated file name given to an earlier version, I
think.