Command library / ss
ss
Show socket connections and listening ports
The modern replacement for netstat on Linux: shows sockets — connections and listening ports. -t is TCP, -u is UDP, -l narrows to listening sockets only, -n skips slow reverse-DNS lookups, and -p shows which process owns each socket. These bundle: -tuln is one of the most common invocations on any Linux box.
Practice ssUsage
Options and flags
-tshow TCP sockets
-ushow UDP sockets
-lshow listening sockets only
-nshow numeric addresses and ports — skip reverse-DNS lookups
-pshow the process using each socket (may need root)
Examples
ss -tulnEvery TCP and UDP port this host is listening on, numeric — the classic 'what's exposed' check.
ss -tJust the active TCP connections, nothing else.
ss -tpActive TCP connections, plus which process owns each one.
Common mistakes
This drill's answer includes -n for fast numeric output — without it ss does a reverse-DNS lookup per socket, which is slower and shows hostnames instead of raw addresses.