I have a situation where a person has mapped a drive and has run an application they were not suppose to. I know the Windows7 Desktop they were on and the time of the incident. I also The application that was run. The person has admitted that they have made a mistake. I want proof from the Windows system logs as proof that the incedent happened at the person said it did. How and what do I need to collect and collate to prove this?
Service is Windows 2003, Desktop is Windows7 it is an enterprise domain.