7 netstat Command Uses on Windows With Examples
Learn seven practical netstat commands for open ports, PIDs, routing, protocol statistics, and live connection monitoring on Windows.
Direct answer: Windows netstat shows active connections, listening ports, process IDs, executables, routing information, Ethernet counters, and protocol statistics. The seven most useful commands are netstat -a, netstat -n -o, netstat -b, netstat -r, netstat -s, netstat -e -s, and an interval command such as netstat -o 5.
Microsoft documents netstat for Windows 10, Windows 11, and supported Windows Server releases. Its reference describes active TCP connections, listening ports, Ethernet statistics, the IP routing table, and IPv4/IPv6 statistics. See the official Microsoft netstat documentation for the complete switch list.
1. Open Command Prompt correctly
- Press
Win, type Command Prompt, and open it. - Use Run as administrator when you need executable names with
-bor when access is denied. - Run a command, then press
Ctrl+Cto stop a continuously refreshing command.
Run these commands in cmd.exe. Most also work in PowerShell because PowerShell can invoke Windows command-line programs directly.
2. Use 1: list every connection and listening port
netstat -a
The -a switch displays active TCP connections plus TCP and UDP ports on which the computer is listening. This is the fastest answer to “What ports are open?”
Proto Local Address Foreign Address State
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 192.168.1.20:51544 142.250.72.14:443 ESTABLISHED
UDP 0.0.0.0:5353 *:*
A listening port is ready to accept traffic; it does not prove that an application is reachable through the firewall. UDP rows have no TCP state because UDP is connectionless.
3. Use 2: show numeric addresses and process IDs
netstat -n -o
-n prevents reverse DNS and service-name lookups, so output appears faster and keeps addresses and ports numeric. -o adds the owning process ID (PID).
To identify the process, copy the PID and run:
tasklist /FI "PID eq 1234"
You can also open Task Manager, choose Details, and match the PID. This combination is usually the best first diagnostic command because it connects a network endpoint to a process without the slower executable lookup performed by -b.
4. Use 3: map ports directly to executables
netstat -b
-b attempts to display the executable involved in each connection or listening port. Windows may take considerably longer to produce the result, and the command can fail or omit names without sufficient permissions.
Use an elevated Command Prompt when possible. For a narrower result, combine it with numeric output and process IDs:
netstat -anob
This is useful when you need the program name immediately, but netstat -n -o followed by tasklist is often quicker for a busy machine.
5. Use 4: inspect the IP routing table
netstat -r
-r displays the IPv4 and IPv6 routing tables. It is equivalent to:
route print
Look for the default route (0.0.0.0 for IPv4), its gateway, interface, and metric. A missing or incorrect default route can explain why local network access works while internet access fails. Multiple routes may be valid; Windows chooses according to route specificity and metric.
6. Use 5: read protocol statistics
netstat -s
-s reports counters grouped by protocol. To limit the report, add -p:
netstat -s -p tcp
netstat -s -p udp
netstat -s -p ip
netstat -s -p ipv6
netstat -s -p icmp
netstat -s -p tcpv6
netstat -s -p udpv6
netstat -s -p icmpv6
These are cumulative counters, not a live error rate. Save two snapshots and compare them over a known interval when investigating retransmissions, resets, or dropped traffic.
7. Use 6: combine Ethernet and protocol statistics
netstat -e -s
-e shows Ethernet statistics such as bytes and packets sent and received. Combining it with -s places link-level counters beside protocol counters, which helps separate a physical or interface problem from a TCP/IP problem.
For a quick interface-only view:
netstat -e
8. Use 7: monitor changes repeatedly
netstat -o 5
An interval at the end of the command redisplays the result every number of seconds. The example refreshes every five seconds. Stop it with Ctrl+C.
For a broad diagnostic snapshot, Microsoft documents this composite command:
netstat -anobq
It combines connections, listening ports, numeric addresses, PIDs, executables, and bound non-listening TCP ports. Because -b can be slow and permission-sensitive, use it after a narrower command if you are troubleshooting interactively.
9. How to read netstat output
| Column | Meaning |
|---|---|
| Proto | Protocol, such as TCP or UDP. |
| Local Address | Local IP address and port. 0.0.0.0 means all IPv4 interfaces; [::] means all IPv6 interfaces. |
| Foreign Address | Remote IP address and port. With -n, Windows does not resolve names. |
| State | TCP lifecycle state, such as LISTENING, ESTABLISHED, TIME_WAIT, CLOSE_WAIT, or SYN_SENT. |
| PID | Process ID shown by -o. |
Common TCP states:
- LISTENING: a socket is waiting for inbound TCP connections.
- ESTABLISHED: the connection is active.
- TIME_WAIT: the local endpoint is waiting before fully releasing a recently closed connection; short-lived entries can be normal.
- CLOSE_WAIT: the peer closed its side and the local process has not finished closing; many persistent entries can indicate an application issue.
- SYN_SENT: the client sent a connection request but has not completed the handshake.
- SYN_RECEIVED: the server received a request and is waiting for the final handshake step.
10. Useful filters and combinations
Pipe output to Windows filtering tools when the full report is large:
netstat -ano | findstr LISTENING
netstat -ano | findstr ":443"
netstat -ano | findstr "ESTABLISHED"
netstat -ano | findstr "1234"
Redirect a report to a file for later comparison:
netstat -ano > "%USERPROFILE%\Desktop\netstat-report.txt"
Use -4 or -6 to restrict output to IPv4 or IPv6 when those switches are available in your Windows version:
netstat -ano -4
netstat -ano -6
11. Troubleshooting common problems
| Symptom | Cause | Fix |
|---|---|---|
-b is denied or shows no executable |
Command Prompt lacks elevation, or the process cannot be inspected. | Open Command Prompt as administrator, then run netstat -anob. Fall back to netstat -ano and tasklist. |
| The command appears slow | Name resolution or executable inspection is taking time. | Add -n; avoid -b until you have narrowed the result. |
| A port is listening but unreachable remotely | Firewall rules, binding address, NAT, or upstream filtering can block access. | Check whether it listens on 0.0.0.0/[::] or only 127.0.0.1/::1, then inspect Windows Firewall and network controls. |
| Many TIME_WAIT entries | Recently closed TCP connections remain in cleanup. | Check whether the count grows continuously and correlate it with the application and request pattern; a few entries are normal. |
| Many CLOSE_WAIT entries | An application may not be closing sockets after the peer disconnects. | Map entries to a PID with -o, identify the application, and inspect its connection-handling logs or configuration. |
| Names differ between runs | DNS or service-name resolution changes the display. | Use -n for stable numeric output. |
| UDP has no state | UDP does not establish TCP-style sessions. | Use local/foreign addresses, PID, and protocol counters instead of a State value. |
12. Performance, reliability, and cost notes
- Performance: Prefer
-nduring incidents because it avoids name lookups. Narrow output withfindstror inspect a PID rather than repeatedly running-b. - Reliability: A single snapshot is evidence of a moment in time. Use an interval or repeated redirected snapshots for intermittent failures, and compare counters over a defined period.
- Scope:
netstatreports sockets and counters visible to Windows. It does not replace firewall logs, packet captures, DNS diagnostics, or application logs. - Cost:
netstatis included with Windows and has no separate usage charge. It can consume CPU and time when executable lookup or frequent refreshes are used.
13. Or skip the browser setup
If your next step is publishing a screenshot of a web page, you can use ScreenshotNeo instead of maintaining browser automation. It accepts one GET request and returns PNG, JPEG, WebP, or PDF. Cookie banners, newsletter popups, and chat widgets are removed before capture; bot checks, blank pages, failed loads, timeouts, and cache hits are not billed. Its MCP server gives AI agents tools for screenshots, page information, and PDFs.
See the ScreenshotNeo API documentation for all options.
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
The free plan includes 1,000 screenshots each month with no card. Paid plans start at $5 for 3,000 screenshots, and every feature is included on every plan. Create a free ScreenshotNeo account.
14. FAQ
What is the best first netstat command?
Use netstat -ano. It gives numeric endpoints and PIDs without the slower executable inspection of -b.
How do I find what uses port 8080?
Run netstat -ano | findstr ":8080", copy the PID, then run tasklist /FI "PID eq PID_NUMBER".
Does netstat show firewall rules?
No. It shows sockets, connections, routes, and counters. Use Windows Firewall tools and logs to inspect filtering rules.
Can netstat prove that a remote service is healthy?
No. An ESTABLISHED row proves a TCP session exists at that moment, not that the application protocol or remote service is functioning correctly.
What replaced netstat?
Windows still includes netstat. PowerShell also provides newer networking cmdlets, but netstat remains useful for quick, familiar command-line inspection.


