Terminal Dojo
Help العربية Sign inGet started

Command library / netstat

netstat

CMDDraft — pending expert review4 practice missions

Show network connections, listening ports and their owning processes

Lists the machine's TCP/UDP connections and listening ports. In incident response, `-ano` is the classic trio: All connections, Numeric addresses (no slow DNS lookups) and the Owning process ID, which you then map to a program with tasklist. On Linux the modern replacement is `ss`.

Practice netstat

Usage

netstat [-a] [-n] [-o] [-b] [-p proto] [-r] [-s] [interval]

Options and flags

Examples

Common mistakes

netstat -ano findstr :4444 netstat -ano | findstr :4444

Without the pipe (|), findstr is just an odd argument to netstat and nothing is filtered.

Related commands

findstrping