Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / DFI / MEMORY / DUMP / VOLATILITY / Network

connections (legacy)

Walks Linked list of connections

Misses:

  • Unlinked sockets

Commands

# List TCP connections (Vol2, XP/2003 only)  
vol.py -f <mem> --profile=<profile> connections