Forgive me as I am just excited over the fact that I was able to catch a student that possibly stole 16 laptops from one of my High Schools.
It all started when I received alerts for iMesh being run on one of our computers connected to the network. At first I thought nothing of it and called over to the school and asked the local tech to ghost the laptop because it looked like the program just may have gotten installed. Well he tells me that the laptop has been missing since last spring when a bunch were stolen. Well obviously it is still on our network somewhere so I decided to play detective. I assigned it a static IP using a DHCP reservation so it would always get the same IP and make it easy for me to know when the laptop was online. When it would come online I would get a response alert and I then would go through my cisco switches searching the mac address tables to trace down what part of the network it was connected on. Since it was on the wireless I could only get what access point it was using so I only got a general area. I did this for a couple days and a pattern was noticed. So with the help of the tech staff in that building we scheduled a couple stake outs and sure enough it connected and they looked and saw a student using a laptop. This made me happy that we were able to catch this kid with a stolen laptop, but what made me even more happy is when the police got there they discovered he had 15 more laptops in his possession. He claims he and his father bought them off ebay so the police are gathering the information so we can cross reference serial numbers, but 16 is the number of laptops that were taken from that school. So hopefully with the help of the police and eBay (if they were infact purchased off there) we can track down the original thief it does not turn out to be this kid himself.
Why I got excited was is because originally my boss felt I was wasting my time on looking for this one laptop and now that it turns out we may be able to recover all 16 of them he is glad that I spent a little time doing what I did.