Get-NetworkConnection is a PowerShell script used to return current TCP and UDP connections, originally developed by Lee Christensen (@tifkin_)
This is an edited version of the script which also includes a Timestamp for each connection.
Additional reading material on the addition of timestamps evidence to the tool, can be found in our blog - Why and How to Extract Network Connection Timestamps for DFIR Investigations.
Usage: Get-NetworkConnection
Hadar Yudovich
This project is licensed under the BSD 3-clause license - see the LICENSE file for details
Original Developers:
- Lee Christensen (@tifkin_)
- Matthew Graeber (@mattifestation)
Illusive Networks Research team members:
- Dolev Ben Shushan
- Tom Kahana
- Tom Sela