Join Us!

find exe, process, ...
 
Notifications
Clear all

find exe, process, that produced network traffic  

  RSS
jot49
(@jot49)
New Member

All,

is it possible to determine which process, executable,… produced network traffic if you only have a image of the hdd.
I have got no memory dump and no Live Response data.
It´s a Win7 64-bit.

Thanks

Quote
Posted : 16/11/2010 7:21 pm
joachimm
(@joachimm)
Active Member

Sometimes it is possible. I would say start with making an elaborate time-line.

ReplyQuote
Posted : 16/11/2010 7:27 pm
allend
(@allend)
New Member

You can view the executables which have a windows firewall exception policy here

HKLM\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules

I'm not sure how much that helps your situation, but that may be a place to start.

ReplyQuote
Posted : 16/11/2010 8:15 pm
Share: