
Explanation:

In Microsoft Defender for Endpoint, the quickest way to enumerate running processes and their open network connections on a Windows device is to use the built-in Investigation package feature from the device page.
Collecting an investigation package executes a set of diagnostics on the endpoint and bundles artifacts- including process lists , network connections (netstat ou tput) , services, autoruns, scheduled tasks, and other forensic logs- into a ZIP file. After you trigger Collect investigation package on the device page , the job appears in the Action center ; once completed, you open that action and download the package. Finally, extract the ZIP to review the CSV/TXT outputs that show active processes and network connectivity, satisfying the requirement with minimal administrative effort and without initiating a live response session or running interactive commands manually.