Skip to content

IllusiveNetworks-Labs/Get-NetworkConnection

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 

Repository files navigation

Get-NetworkConnection

Get-NetworkConnection is a PowerShell script used to return current TCP and UDP connections, originally developed by Lee Christensen (@tifkin_)
This is an edited version of the script which also includes a Timestamp for each connection.

Additional reading material on the addition of timestamps evidence to the tool, can be found in our blog - Why and How to Extract Network Connection Timestamps for DFIR Investigations.

How to use

Usage: Get-NetworkConnection

Example

alt tag

Author

Hadar Yudovich

License

This project is licensed under the BSD 3-clause license - see the LICENSE file for details

Contributors

Original Developers:

  • Lee Christensen (@tifkin_)
  • Matthew Graeber (@mattifestation)

Illusive Networks Research team members:

  • Dolev Ben Shushan
  • Tom Kahana
  • Tom Sela