Sockets

Much like Volatility, Rekall has the ability to parse the memory image for network connections. The Rekall plugin sockets allow analysts to view any active connections.

Get Digital Forensics and Incident Response now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.