find exe, process, ...
 
Notifications
Clear all

find exe, process, that produced network traffic

3 Posts
3 Users
0 Reactions
429 Views
(@jot49)
Active Member
Joined: 18 years ago
Posts: 16
Topic starter  

All,

is it possible to determine which process, executable,… produced network traffic if you only have a image of the hdd.
I have got no memory dump and no Live Response data.
It´s a Win7 64-bit.

Thanks


   
Quote
(@joachimm)
Estimable Member
Joined: 17 years ago
Posts: 181
 

Sometimes it is possible. I would say start with making an elaborate time-line.


   
ReplyQuote
(@allend)
Active Member
Joined: 15 years ago
Posts: 17
 

You can view the executables which have a windows firewall exception policy here

HKLM\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules

I'm not sure how much that helps your situation, but that may be a place to start.


   
ReplyQuote
Share: