netscan and sockets

As was discussed previously, incident response analysts may have identified a potentially compromised host through an alert or review for a network-based system such as a firewall or proxy server. In the event that this is the case, the analyst may be able to include or exclude a system as potentially compromised by gaining insight into the current network connections.

The plugin netscan scans the memory image for network artifacts. The plugin will find TCP and UDP endpoints and listeners as well as provide the local and foreign IP address. netscan will only work with 32- and 64-bit Windows Vista, Windows 7, and Windows 2008 Server. One key feature that is of help to incident response analysts with the netscan plugin is ...

Get Digital Forensics and Incident Response now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.