Much like Volatility, Rekall has the ability to parse the memory image for network connections. The Rekall plugin sockets allow analysts to view any active connections.

Get Digital Forensics and Incident Response now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.