netscan and sockets

As was discussed previously, incident response analysts may have identified a potentially compromised host through an alert or review for a network-based system such as a firewall or proxy server. In the event that this is the case, the analyst may be able to include or exclude a system as potentially compromised by gaining insight into the current network connections.

The plugin netscan scans the memory image for network artifacts. The plugin will find TCP and UDP endpoints and listeners as well as provide the local and foreign IP address. netscan will only work with 32- and 64-bit Windows Vista, Windows 7, and Windows 2008 Server. One key feature that is of help to incident response analysts with the netscan plugin is ...

Get Digital Forensics and Incident Response now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.