Command library / netstat
netstat
Show network connections, listening ports and their owning processes
Lists the machine's TCP/UDP connections and listening ports. In incident response, `-ano` is the classic trio: All connections, Numeric addresses (no slow DNS lookups) and the Owning process ID, which you then map to a program with tasklist. On Linux the modern replacement is `ss`.
Practice netstatUsage
Options and flags
intervalseconds between refreshes
-aall connections and listening ports
-nnumeric addresses and ports (no name resolution)
-oshow the owning process ID (PID)
-bshow the executable behind each connection (needs an elevated prompt)
-eEthernet statistics
-fshow fully qualified domain names
-pPROTOshow connections for one protocol (tcp, udp, tcpv6, udpv6)
-rdisplay the routing table
-sper-protocol statistics
Examples
netstat -anoEvery connection with numeric addresses and PIDs.
netstat -ano | findstr :4444Only lines mentioning port 4444 — e.g. a suspicious listener.
netstat -an | findstr LISTENINGWhich ports is this machine listening on?
netstat -rPrint the routing table.
Common mistakes
Without the pipe (|), findstr is just an odd argument to netstat and nothing is filtered.