I was looking at the forward traffic logs on our firewall and I saw one
of our administrator accounts was listed as the source for a particular
endpoint. The admin was not logged in, only one user was currently
logged in, computer has been rebooted a...