Command library / Get-NetTCPConnection
Get-NetTCPConnection
List TCP connections and listening ports
PowerShell's netstat, returning objects you can filter. Each connection has a LocalAddress and LocalPort, a RemoteAddress and RemotePort, a State (Listen, Established, TimeWait…) and an OwningProcess: the PID of the program behind it, which you can hand straight to Get-Process.
Practice Get-NetTCPConnectionUsage
Options and flags
-StateSTATEonly connections in this state, e.g. Listen or Established
-LocalPortPORTonly connections on this local port
-RemotePortPORTonly connections to this remote port
-RemoteAddressIPonly connections to this remote address
-OwningProcessPIDonly connections owned by this process ID
Examples
Get-NetTCPConnection -State ListenEvery TCP port this host is listening on.
Get-NetTCPConnection -LocalPort 3389Anything using local port 3389 (Remote Desktop).
Get-NetTCPConnection -OwningProcess 4444Every connection belonging to process 4444.
Get-NetTCPConnection -State Established -RemotePort 443Open HTTPS connections from this host.
Common mistakes
The state is called Listen here, not LISTENING as netstat prints it.