NETSTAT
NOTE: netstat is deprecated on Linux, prefer 'ss' command. Still commonly used on Windows, macOS, and BSD systems.
BASIC USAGE#
netstat # Show all connections netstat -a # All connections and listening netstat -l # Listening sockets only netstat -t # TCP connections only netstat -u # UDP connections only netstat -n # Numeric addresses (no DNS) netstat -p # Show process/PID (Linux) netstat -r # Routing table netstat -i # Interface statistics netstat -s # Protocol statistics
COMMON COMBINATIONS#
netstat -tuln # TCP/UDP listening, numeric netstat -tulnp # + Process info (Linux, needs root) netstat -antp # All TCP, numeric, with processes netstat -an # All connections, numeric netstat -rn # Routing table, numeric netstat -ie # Interface info (like ifconfig)
LINUX-SPECIFIC OPTIONS#
netstat -p # Show PID/program name netstat -c # Continuous output netstat --wide # Don't truncate addresses netstat -W # Same as --wide netstat -o # Show timers netstat -e # Extended info
WINDOWS-SPECIFIC OPTIONS#
netstat -b # Show executable name netstat -o # Show owning process PID netstat -f # Show FQDN for addresses netstat -q # All connections & listening ports netstat -x # Show NetworkDirect connections netstat -y # Show TCP template for all conns netstat -e # Ethernet statistics netstat -p TCP # Show only TCP protocol
MACOS/BSD OPTIONS#
netstat -f inet # IPv4 only netstat -f inet6 # IPv6 only netstat -W # Wide output (no truncation) netstat -v # Verbose output
FIND LISTENING PORTS#
# Linux netstat -tulnp netstat -tlnp # TCP only netstat -ulnp # UDP only # macOS/BSD netstat -an | grep LISTEN # Windows netstat -an | findstr LISTENING netstat -ano | findstr LISTENING
FIND SPECIFIC PORT#
# Linux netstat -tulnp | grep :80 netstat -anp | grep :443 # macOS netstat -an | grep "\.80 " lsof -i :80 # Alternative # Windows netstat -ano | findstr :80 netstat -ano | findstr ":80 "
FIND CONNECTIONS BY STATE#
netstat -an | grep ESTABLISHED netstat -an | grep TIME_WAIT netstat -an | grep CLOSE_WAIT netstat -an | grep SYN_SENT netstat -an | grep SYN_RECV
CONNECTION STATES#
LISTEN # Waiting for connection ESTABLISHED # Connection established SYN_SENT # Sent SYN, waiting for SYN-ACK SYN_RECV # Received SYN, sent SYN-ACK FIN_WAIT1 # Sent FIN, waiting for ACK FIN_WAIT2 # Received ACK for FIN TIME_WAIT # Waiting for packets to clear CLOSE_WAIT # Received FIN, waiting to close LAST_ACK # Sent FIN, waiting for ACK CLOSING # Both sides sent FIN CLOSED # Connection closed
ROUTING TABLE#
netstat -r # Show routing table netstat -rn # Numeric (no DNS lookups) netstat -rne # Extended info # Routing table columns Destination # Target network/host Gateway # Next hop address Genmask # Network mask Flags # Route flags MSS # Default max segment size Window # Default window size irtt # Initial RTT Iface # Interface # Route flags U # Route is up G # Use gateway H # Target is host D # Dynamically created M # Modified by redirect
INTERFACE STATISTICS#
netstat -i # Interface list netstat -ie # Extended (like ifconfig) # Interface columns Iface # Interface name MTU # Maximum transmission unit RX-OK # Received OK RX-ERR # Receive errors RX-DRP # Receive dropped RX-OVR # Receive overrun TX-OK # Transmitted OK TX-ERR # Transmit errors TX-DRP # Transmit dropped TX-OVR # Transmit overrun Flg # Flags
PROTOCOL STATISTICS#
netstat -s # All protocol stats netstat -st # TCP statistics netstat -su # UDP statistics netstat -sw # Raw IP statistics
PRACTICAL EXAMPLES#
# Count connections by state
netstat -an | awk '/tcp/ {print $6}' | sort | uniq -c
# Count connections per IP
netstat -an | grep ESTABLISHED | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -rn
# Find process using port (Linux)
netstat -tulnp | grep :80
# or
sudo netstat -tulnp | awk '/:80 / {print $7}'
# Find process using port (macOS)
lsof -i :80
# Find process using port (Windows)
netstat -ano | findstr :80
# Then: tasklist /FI "PID eq <pid>"
# Monitor new connections
watch -n 1 'netstat -an | grep ESTABLISHED | wc -l'
# Show top connected IPs
netstat -an | grep ESTABLISHED | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -rn | head -10
# Detect SYN flood
netstat -an | grep SYN_RECV | wc -l
# Check for TIME_WAIT accumulation
netstat -an | grep TIME_WAIT | wc -l
SS COMMAND (LINUX REPLACEMENT)#
ss # All sockets ss -t # TCP sockets ss -u # UDP sockets ss -l # Listening sockets ss -n # Numeric ss -p # Show process ss -a # All sockets ss -s # Statistics summary # Equivalent commands netstat -tulnp -> ss -tulnp netstat -an -> ss -an netstat -r -> ip route # SS filtering ss state established ss state listening ss 'sport = :80' ss 'dport = :443' ss dst 192.168.1.1
LSOF ALTERNATIVE (macOS/Linux)#
lsof -i # All internet connections lsof -i :80 # Connections on port 80 lsof -i TCP # TCP connections lsof -i UDP # UDP connections lsof -i @192.168.1.1 # Connections to IP lsof -i TCP:22 # SSH connections lsof -nP -i # Numeric, no port names
NETSTAT CHEATSHEET
==================
Source: https://cheatsheet.johlem.net
NOTE: netstat is deprecated on Linux, prefer 'ss' command.
Still commonly used on Windows, macOS, and BSD systems.
BASIC USAGE
-----------
netstat # Show all connections
netstat -a # All connections and listening
netstat -l # Listening sockets only
netstat -t # TCP connections only
netstat -u # UDP connections only
netstat -n # Numeric addresses (no DNS)
netstat -p # Show process/PID (Linux)
netstat -r # Routing table
netstat -i # Interface statistics
netstat -s # Protocol statistics
COMMON COMBINATIONS
-------------------
netstat -tuln # TCP/UDP listening, numeric
netstat -tulnp # + Process info (Linux, needs root)
netstat -antp # All TCP, numeric, with processes
netstat -an # All connections, numeric
netstat -rn # Routing table, numeric
netstat -ie # Interface info (like ifconfig)
LINUX-SPECIFIC OPTIONS
----------------------
netstat -p # Show PID/program name
netstat -c # Continuous output
netstat --wide # Don't truncate addresses
netstat -W # Same as --wide
netstat -o # Show timers
netstat -e # Extended info
WINDOWS-SPECIFIC OPTIONS
------------------------
netstat -b # Show executable name
netstat -o # Show owning process PID
netstat -f # Show FQDN for addresses
netstat -q # All connections & listening ports
netstat -x # Show NetworkDirect connections
netstat -y # Show TCP template for all conns
netstat -e # Ethernet statistics
netstat -p TCP # Show only TCP protocol
MACOS/BSD OPTIONS
-----------------
netstat -f inet # IPv4 only
netstat -f inet6 # IPv6 only
netstat -W # Wide output (no truncation)
netstat -v # Verbose output
FIND LISTENING PORTS
--------------------
# Linux
netstat -tulnp
netstat -tlnp # TCP only
netstat -ulnp # UDP only
# macOS/BSD
netstat -an | grep LISTEN
# Windows
netstat -an | findstr LISTENING
netstat -ano | findstr LISTENING
FIND SPECIFIC PORT
------------------
# Linux
netstat -tulnp | grep :80
netstat -anp | grep :443
# macOS
netstat -an | grep "\.80 "
lsof -i :80 # Alternative
# Windows
netstat -ano | findstr :80
netstat -ano | findstr ":80 "
FIND CONNECTIONS BY STATE
-------------------------
netstat -an | grep ESTABLISHED
netstat -an | grep TIME_WAIT
netstat -an | grep CLOSE_WAIT
netstat -an | grep SYN_SENT
netstat -an | grep SYN_RECV
CONNECTION STATES
-----------------
LISTEN # Waiting for connection
ESTABLISHED # Connection established
SYN_SENT # Sent SYN, waiting for SYN-ACK
SYN_RECV # Received SYN, sent SYN-ACK
FIN_WAIT1 # Sent FIN, waiting for ACK
FIN_WAIT2 # Received ACK for FIN
TIME_WAIT # Waiting for packets to clear
CLOSE_WAIT # Received FIN, waiting to close
LAST_ACK # Sent FIN, waiting for ACK
CLOSING # Both sides sent FIN
CLOSED # Connection closed
ROUTING TABLE
-------------
netstat -r # Show routing table
netstat -rn # Numeric (no DNS lookups)
netstat -rne # Extended info
# Routing table columns
Destination # Target network/host
Gateway # Next hop address
Genmask # Network mask
Flags # Route flags
MSS # Default max segment size
Window # Default window size
irtt # Initial RTT
Iface # Interface
# Route flags
U # Route is up
G # Use gateway
H # Target is host
D # Dynamically created
M # Modified by redirect
INTERFACE STATISTICS
--------------------
netstat -i # Interface list
netstat -ie # Extended (like ifconfig)
# Interface columns
Iface # Interface name
MTU # Maximum transmission unit
RX-OK # Received OK
RX-ERR # Receive errors
RX-DRP # Receive dropped
RX-OVR # Receive overrun
TX-OK # Transmitted OK
TX-ERR # Transmit errors
TX-DRP # Transmit dropped
TX-OVR # Transmit overrun
Flg # Flags
PROTOCOL STATISTICS
-------------------
netstat -s # All protocol stats
netstat -st # TCP statistics
netstat -su # UDP statistics
netstat -sw # Raw IP statistics
PRACTICAL EXAMPLES
------------------
# Count connections by state
netstat -an | awk '/tcp/ {print $6}' | sort | uniq -c
# Count connections per IP
netstat -an | grep ESTABLISHED | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -rn
# Find process using port (Linux)
netstat -tulnp | grep :80
# or
sudo netstat -tulnp | awk '/:80 / {print $7}'
# Find process using port (macOS)
lsof -i :80
# Find process using port (Windows)
netstat -ano | findstr :80
# Then: tasklist /FI "PID eq <pid>"
# Monitor new connections
watch -n 1 'netstat -an | grep ESTABLISHED | wc -l'
# Show top connected IPs
netstat -an | grep ESTABLISHED | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -rn | head -10
# Detect SYN flood
netstat -an | grep SYN_RECV | wc -l
# Check for TIME_WAIT accumulation
netstat -an | grep TIME_WAIT | wc -l
SS COMMAND (LINUX REPLACEMENT)
------------------------------
ss # All sockets
ss -t # TCP sockets
ss -u # UDP sockets
ss -l # Listening sockets
ss -n # Numeric
ss -p # Show process
ss -a # All sockets
ss -s # Statistics summary
# Equivalent commands
netstat -tulnp -> ss -tulnp
netstat -an -> ss -an
netstat -r -> ip route
# SS filtering
ss state established
ss state listening
ss 'sport = :80'
ss 'dport = :443'
ss dst 192.168.1.1
LSOF ALTERNATIVE (macOS/Linux)
------------------------------
lsof -i # All internet connections
lsof -i :80 # Connections on port 80
lsof -i TCP # TCP connections
lsof -i UDP # UDP connections
lsof -i @192.168.1.1 # Connections to IP
lsof -i TCP:22 # SSH connections
lsof -nP -i # Numeric, no port names
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.