← All cheat sheets

NETSTAT

Plain-text reference · 8 KB. Read it, search it (Ctrl-F) or print it.

NOTE: netstat is deprecated on Linux, prefer 'ss' command.
Still commonly used on Windows, macOS, and BSD systems.

BASIC USAGE#

netstat                             # Show all connections
netstat -a                          # All connections and listening
netstat -l                          # Listening sockets only
netstat -t                          # TCP connections only
netstat -u                          # UDP connections only
netstat -n                          # Numeric addresses (no DNS)
netstat -p                          # Show process/PID (Linux)
netstat -r                          # Routing table
netstat -i                          # Interface statistics
netstat -s                          # Protocol statistics

COMMON COMBINATIONS#

netstat -tuln                       # TCP/UDP listening, numeric
netstat -tulnp                      # + Process info (Linux, needs root)
netstat -antp                       # All TCP, numeric, with processes
netstat -an                         # All connections, numeric
netstat -rn                         # Routing table, numeric
netstat -ie                         # Interface info (like ifconfig)

LINUX-SPECIFIC OPTIONS#

netstat -p                          # Show PID/program name
netstat -c                          # Continuous output
netstat --wide                      # Don't truncate addresses
netstat -W                          # Same as --wide
netstat -o                          # Show timers
netstat -e                          # Extended info

WINDOWS-SPECIFIC OPTIONS#

netstat -b                          # Show executable name
netstat -o                          # Show owning process PID
netstat -f                          # Show FQDN for addresses
netstat -q                          # All connections & listening ports
netstat -x                          # Show NetworkDirect connections
netstat -y                          # Show TCP template for all conns
netstat -e                          # Ethernet statistics
netstat -p TCP                      # Show only TCP protocol

MACOS/BSD OPTIONS#

netstat -f inet                     # IPv4 only
netstat -f inet6                    # IPv6 only
netstat -W                          # Wide output (no truncation)
netstat -v                          # Verbose output

FIND LISTENING PORTS#

# Linux
netstat -tulnp
netstat -tlnp                       # TCP only
netstat -ulnp                       # UDP only

# macOS/BSD
netstat -an | grep LISTEN

# Windows
netstat -an | findstr LISTENING
netstat -ano | findstr LISTENING

FIND SPECIFIC PORT#

# Linux
netstat -tulnp | grep :80
netstat -anp | grep :443

# macOS
netstat -an | grep "\.80 "
lsof -i :80                         # Alternative

# Windows
netstat -ano | findstr :80
netstat -ano | findstr ":80 "

FIND CONNECTIONS BY STATE#

netstat -an | grep ESTABLISHED
netstat -an | grep TIME_WAIT
netstat -an | grep CLOSE_WAIT
netstat -an | grep SYN_SENT
netstat -an | grep SYN_RECV

CONNECTION STATES#

LISTEN                              # Waiting for connection
ESTABLISHED                         # Connection established
SYN_SENT                            # Sent SYN, waiting for SYN-ACK
SYN_RECV                            # Received SYN, sent SYN-ACK
FIN_WAIT1                           # Sent FIN, waiting for ACK
FIN_WAIT2                           # Received ACK for FIN
TIME_WAIT                           # Waiting for packets to clear
CLOSE_WAIT                          # Received FIN, waiting to close
LAST_ACK                            # Sent FIN, waiting for ACK
CLOSING                             # Both sides sent FIN
CLOSED                              # Connection closed

ROUTING TABLE#

netstat -r                          # Show routing table
netstat -rn                         # Numeric (no DNS lookups)
netstat -rne                        # Extended info

# Routing table columns
Destination                         # Target network/host
Gateway                             # Next hop address
Genmask                             # Network mask
Flags                               # Route flags
MSS                                 # Default max segment size
Window                              # Default window size
irtt                                # Initial RTT
Iface                               # Interface

# Route flags
U                                   # Route is up
G                                   # Use gateway
H                                   # Target is host
D                                   # Dynamically created
M                                   # Modified by redirect

INTERFACE STATISTICS#

netstat -i                          # Interface list
netstat -ie                         # Extended (like ifconfig)

# Interface columns
Iface                               # Interface name
MTU                                 # Maximum transmission unit
RX-OK                               # Received OK
RX-ERR                              # Receive errors
RX-DRP                              # Receive dropped
RX-OVR                              # Receive overrun
TX-OK                               # Transmitted OK
TX-ERR                              # Transmit errors
TX-DRP                              # Transmit dropped
TX-OVR                              # Transmit overrun
Flg                                 # Flags

PROTOCOL STATISTICS#

netstat -s                          # All protocol stats
netstat -st                         # TCP statistics
netstat -su                         # UDP statistics
netstat -sw                         # Raw IP statistics

PRACTICAL EXAMPLES#

# Count connections by state
netstat -an | awk '/tcp/ {print $6}' | sort | uniq -c

# Count connections per IP
netstat -an | grep ESTABLISHED | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -rn

# Find process using port (Linux)
netstat -tulnp | grep :80
# or
sudo netstat -tulnp | awk '/:80 / {print $7}'

# Find process using port (macOS)
lsof -i :80

# Find process using port (Windows)
netstat -ano | findstr :80
# Then: tasklist /FI "PID eq <pid>"

# Monitor new connections
watch -n 1 'netstat -an | grep ESTABLISHED | wc -l'

# Show top connected IPs
netstat -an | grep ESTABLISHED | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -rn | head -10

# Detect SYN flood
netstat -an | grep SYN_RECV | wc -l

# Check for TIME_WAIT accumulation
netstat -an | grep TIME_WAIT | wc -l

SS COMMAND (LINUX REPLACEMENT)#

ss                                  # All sockets
ss -t                               # TCP sockets
ss -u                               # UDP sockets
ss -l                               # Listening sockets
ss -n                               # Numeric
ss -p                               # Show process
ss -a                               # All sockets
ss -s                               # Statistics summary

# Equivalent commands
netstat -tulnp   ->   ss -tulnp
netstat -an      ->   ss -an
netstat -r       ->   ip route

# SS filtering
ss state established
ss state listening
ss 'sport = :80'
ss 'dport = :443'
ss dst 192.168.1.1

LSOF ALTERNATIVE (macOS/Linux)#

lsof -i                             # All internet connections
lsof -i :80                         # Connections on port 80
lsof -i TCP                         # TCP connections
lsof -i UDP                         # UDP connections
lsof -i @192.168.1.1                # Connections to IP
lsof -i TCP:22                      # SSH connections
lsof -nP -i                         # Numeric, no port names

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.