I have noticed a propfind notation in my IIS 4.0 log file for the last few days. It references the propfind command, gives the name of the user, a path to the C$ share, and a netlogon notation.
I do not work with IIS very much and am wondering what this means. Is it detrimental to run the propfind command on a regular basis? Is this an outside hacker, or is the user (who claims innocence) up to no good?