My Cousin Tried to Sabotage My Job Interview, but a Mail Server Timestamp Ruined Him – Part 3

Story code: ST-001121

Part 3: The Log Audit

According to the system log history from Vance Tech’s domain controller, the database query that Julian Miller executed at 08:30 AM did not target a general list of daily visitors. The search parameters retrieved on Sarah Jenkins’ tablet showed a targeted database query: SELECT * FROM visitor_schedule WHERE visitor_name LIKE ‘%David Miller%’. The security cameras in the main lobby record Julian standing near the glass turnstiles at that exact time, looking down at his screen as the query returned David’s lobby check-in details.

Sarah Jenkins turned the tablet screen toward Julian, her gaze flat. “A general security sweep does not target a specific candidate’s name half an hour before their scheduled interview, Julian. Why were you searching for David’s file?”

Julian’s posture shifted. He stepped back from the visitor desk, his hand dropping to his side. “It is within my administrative clearance to monitor incoming guests who present potential security risks to our database infrastructure,” he said, his voice rising in pitch. “We have a family history of academic disputes. I wanted to verify his status to protect the department from a fraudulent hire.”

David Miller remained standing, his hands folded in front of him. “If the search was a protective measure, the timeline does not support it. The reference email from Dr. Vance was not received until 08:58 AM today. Yet the audit log shows a manual intercept command was staged at 08:50 AM, ten minutes before the mail server even processed the message.”

Sarah tapped the screen, scrolling down to the mail transfer agent logs. The system recorded a manual attempt to redirect incoming traffic from the university’s domain at 08:59 AM, precisely sixty seconds after the reference email arrived. The originating IP address for the redirect command was registered to a Vance Tech terminal located in Server Room 4B.

“The override command was entered from terminal IT-ADMIN-094,” Sarah read aloud, her voice even and flat. “That terminal was logged in under your administrative token, Julian.”

Julian crossed his arms, his chest tightening. “Anyone could have used that terminal. The server room door has a shared passcode. The log doesn’t prove I entered the command. I was in the lobby preparing for a system update.”

“The server room door logs show only one badge scan during that ten-minute window,” Sarah replied. She pulled up the access control database. “The badge registered to Julian Miller scanned in at 08:45 AM and scanned out at 09:00 AM.”

A hush fell over the lobby as the other candidates watched the exchange. Julian’s eyes moved quickly between Sarah’s tablet and the lobby exit. The digital records had stripped away his justification, leaving only the server logs to reveal the exact nature of the modification. Sarah clicked the verification prompt, initiating a direct cryptographic handshake with the university’s outbound mail server to resolve the final discrepancy in the email headers.


Leave a Comment