
Explanation:

In Microsoft Defender for Endpoint, the quickest way to enumerate running processes and their open network connections on a Windows device is to use the built-in Investigation package feature from the device page.
Collecting an investigation package executes a set of diagnostics on the endpoint and bundles artifacts- including process lists, network connections (netstat output), services, autoruns, scheduled tasks, and other forensic logs-into a ZIP file. After you trigger Collect investigation package on the device page, the job appears in the Action center; once completed, you open that action and download the package. Finally, extract the ZIP to review the CSV/TXT outputs that show active processes and network connectivity, satisfying the requirement with minimal administrative effort and without initiating a live response session or running interactive commands manually.