netstat

TCP/IP Netstat Command

TCP/IP Netstat Command


netstat

  • C:\Windows\system32\NETSTAT.EXE /?

STDERR:


Displays protocol statistics and current TCP/IP network connections.

NETSTAT [-a] [-b] [-e] [-f] [-n] [-o] [-p proto] [-r] [-s] [-t] [-x] [-y] [interval]

  -a            Displays all connections and listening ports.
  -b            Displays the executable involved in creating each connection or
                listening port. In some cases well-known executables host
                multiple independent components, and in these cases the
                sequence of components involved in creating the connection
                or listening port is displayed. In this case the executable
                name is in [] at the bottom, on top is the component it called,
                and so forth until TCP/IP was reached. Note that this option
                can be time-consuming and will fail unless you have sufficient
                permissions.
  -e            Displays Ethernet statistics. This may be combined with the -s
                option.
  -f            Displays Fully Qualified Domain Names (FQDN) for foreign
                addresses.
  -n            Displays addresses and port numbers in numerical form.
  -o            Displays the owning process ID associated with each connection.
  -p proto      Shows connections for the protocol specified by proto; proto
                may be any of: TCP, UDP, TCPv6, or UDPv6.  If used with the -s
                option to display per-protocol statistics, proto may be any of:
                IP, IPv6, ICMP, ICMPv6, TCP, TCPv6, UDP, or UDPv6.
  -q            Displays all connections, listening ports, and bound
                nonlistening TCP ports. Bound nonlistening ports may or may not
                be associated with an active connection.
  -r            Displays the routing table.
  -s            Displays per-protocol statistics.  By default, statistics are
                shown for IP, IPv6, ICMP, ICMPv6, TCP, TCPv6, UDP, and UDPv6;
                the -p option may be used to specify a subset of the default.
  -t            Displays the current connection offload state.
  -x            Displays NetworkDirect connections, listeners, and shared
                endpoints.
  -y            Displays the TCP connection template for all connections.
                Cannot be combined with the other options.
  interval      Redisplays selected statistics, pausing interval seconds
                between each display.  Press CTRL+C to stop redisplaying
                statistics.  If omitted, netstat will print the current
                configuration information once.

Return Code: 1


C:\Windows\system32\NETSTAT.EXE
c:\>ver
Microsoft Windows [Version 10.0.19045.2075]
FileInfo
File Size39936bytes
Creation Time2019/12/07 18:09:13
LastWrite Time2019/12/07 18:09:13
ProductVersion10.0.19041.1
FileVersion10.0.19041.1 (WinBuild.160101.0800)
HashValue
MD57fddd6681ea81ce26e64452336f479e6
SHA1c038069021cea437ae40b421929e9d4d1a3440b3
SHA2248b0a58877270ff55d2971eba95125d4b6c8d434ac8c0d680cccc4624
SHA256b094e827af70241d71bed9767ec1a254fdc4164a646b2ba4c7105cd783adba0d
SHA384ff4ee704245143a96f73efd8e3d075bdda71fa140302f66adbefc68e2bce5a44c6685956f2a76903c8c2ec13e80a34b7
SHA5129a7c50e83ca4575a46d574a2e148190ccebdb6eec1f6fb21a1f31418b3be475b344f0d64e0f2efe54184bbd4efac21bdf86e7eaa462d89dbb57342e25beae4e9
Built with Hugo
Theme Stack designed by Jimmy