Package rekall :: Package plugins :: Package windows :: Module network
[frames] | no frames]

Module network

source code

This module extracts network information using kernel object inspection.

The netscan plugins use pool tags to scan for objects, while this file directly examines kernel data structures.


Author: Michael Cohen <scudette@google.com>

Classes
  WinNetstat
Enumerate image for connections and sockets
Variables
  __package__ = 'rekall.plugins.windows'