Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Use netstat in Windows to inspect active connections, listening ports, process IDs, routing, and network statistics. Open Command Prompt or PowerShell and run the command that matches your question; add -n for numeric addresses, -o for process IDs, or -b to try to identify executables.

Before you run netstat

Microsoft documents netstat for Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025. Without parameters, it displays active TCP connections. With switches, it can also show listening ports, Ethernet and protocol statistics, and the IP routing table. See Microsoft’s netstat reference, updated September 8, 2026.

Run the commands in Command Prompt or PowerShell. For executable attribution with -b, open the terminal with sufficient permissions: Microsoft notes that this option can take time and can fail without them. The examples below inspect the local computer; they do not establish that a connection is malicious or that a service is reachable from outside your network.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1. List active connections and listening ports

Command

netstat -a

The -a switch displays active TCP connections and TCP and UDP ports on which the computer is listening. Use it when you need a broad view of local network activity or want to check whether a service has opened a listening port.

Look at the Proto column for the protocol, then Local address and Foreign address for the endpoints. TCP rows also show a State. A listening entry indicates a local port waiting for connections; it does not, by itself, prove that a remote machine can reach it. Firewall rules, routing, and the service’s configuration also affect reachability.

2. Show numeric addresses and process IDs

Command

netstat -n -o

-n keeps addresses and port numbers numeric rather than resolving names. This can make output easier to scan and avoids waiting on name resolution. -o adds the process ID (PID) associated with each connection. Use the PID to identify an application in Windows Task Manager: open Task Manager, select Details, and match the value in the PID column.

A PID identifies a process, not necessarily a unique application window or service. One process can own multiple connections, and a shared host process can run more than one service. Treat the PID as a lead to investigate rather than a conclusion about what a connection is doing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Map connections and ports to executables

Command

netstat -b

The -b switch attempts to show the executable involved in each connection or listening port. Choose it when a PID is not enough and you want the program name directly in the output. Microsoft cautions that executable reporting can be time-consuming and may fail without sufficient permissions.

If it fails, reopen Command Prompt or PowerShell with appropriate elevated permissions and run the command again. For a lighter first pass, use netstat -n -o to collect numeric endpoints and PIDs, then look up the PID in Task Manager.

4. Inspect the IP routing table

Command

netstat -r

This displays the IP routing table and is equivalent to route print. Use it when diagnosing which routes are present on the computer. It answers a different question from the connection list: routes describe network paths the system can use, whereas connection rows describe active TCP connections.

5. Read statistics by protocol

Command

netstat -s

The -s switch displays statistics by protocol. To focus the output, add -p and a protocol, such as netstat -p tcp, netstat -p udp, netstat -p ip, or netstat -p icmp. Microsoft also documents tcpv6, udpv6, icmpv6, and ipv6 as protocol selections.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These are aggregate protocol counters, useful when you want a broader view than individual endpoints. They are not a per-application connection list. The reference does not provide a standalone benchmark or thresholds for interpreting a counter as healthy or unhealthy.

6. Combine Ethernet and protocol statistics

Command

netstat -e -s

-e displays Ethernet statistics, including bytes and packets sent and received. Microsoft documents combining it with -s to include protocol statistics as well. Use this when you want link-level traffic counters alongside a protocol-oriented view, rather than a list of individual connections.

7. Refresh output or combine switches

Refresh at an interval

netstat -o 5

A number after the options sets the refresh interval in seconds. This example redisplays the selected information every five seconds. Press Ctrl+C to stop. Use repeated output to observe changes over time; it is not a historical log, so capture the output separately if you need a record.

Show a broad set of connection details

netstat -anobq

Microsoft documents this combined command for displaying connections, listening ports, bound non-listening TCP ports, numeric addresses, PIDs, and executables. The switches bring together several useful views: visibility (-a), numeric output (-n), executable attribution (-b), process IDs (-o), and bound non-listening TCP ports (-q). Because it includes -b, permissions and execution time may be considerations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to choose the right command

Question Command or switch What it adds
What connections and ports are active or listening? netstat -a Active TCP connections and TCP/UDP listeners
Can I avoid name resolution and see the owning PID? netstat -n -o Numeric addresses and process IDs
Which executable is involved? netstat -b Attempts to show executable names; can be slow and require sufficient permissions
What routes are configured? netstat -r IP routing table
What are the protocol counters? netstat -s or netstat -p tcp Statistics by protocol, optionally focused with -p
What Ethernet counters are available? netstat -e -s Ethernet statistics combined with protocol statistics
How is the output changing? netstat -o 5 Repeated display every five seconds in this example

Understand the output and TCP states

Microsoft defines the main connection columns as Proto, Local address, Foreign address, and State. With -n, address and port values stay numeric. The State column describes a TCP connection’s state; it is not shown as a state for UDP listeners.

  • LISTEN: a local TCP endpoint is waiting for a connection.
  • ESTABLISHED: a TCP connection is established.
  • SYN_SENT (shown in Microsoft’s reference as SYN_SEND): a connection attempt has sent a request and is awaiting a response.
  • SYN_RECEIVED: a connection request has been received and is in the handshake process.
  • FIN_WAIT_1, FIN_WAIT_2, and LAST_ACK: TCP shutdown states while endpoints close a connection.
  • CLOSE_WAIT: the remote endpoint has closed, while the local side is yet to finish closing.
  • TIME_WAIT (listed in Microsoft’s reference as TIMED_WAIT): a TCP connection is waiting before its resources are fully released.
  • CLOSED: no connection is active.

A single snapshot is only a moment in time. A transient state may disappear on the next refresh, and a PID or port alone does not identify the purpose or safety of a connection. Combine the relevant netstat view with the application and network context you are investigating.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common netstat questions

The port I expected is not listed

Use netstat -a to include listening ports, not just active connections. Check that the service is running and configured to listen on the expected interface and port. Netstat reports local state; it cannot establish from its output alone that a firewall or remote route permits access.

I see a PID but do not know the program

Use netstat -b for executable attribution, or match the PID from netstat -n -o with the PID column on Task Manager’s Details tab. If the PID belongs to a host process, more than one service may be associated with it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The executable option fails or takes too long

-b can be time-consuming and requires sufficient permissions. Run the terminal with elevated permissions if appropriate. If you only need to identify the process, use -o and look up the PID instead.

The output is difficult to read or slow to appear

Add -n to keep addresses and ports numeric and avoid name resolution. For a narrower view, select the needed switch rather than requesting executable names and every detail at once.

I need to see changes, not one snapshot

Add an interval in seconds, such as netstat -o 5, and stop the repeating display with Ctrl+C. The command redisplays current information; it does not create a durable log.

Or skip the browser setup

If your goal is to capture a website rather than inspect Windows network connections, ScreenshotNeo is a separate website screenshot API and MCP server for developers. A GET request returns a screenshot or PDF; the following cURL example saves a WebP screenshot of Stripe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for setup and options. ScreenshotNeo removes cookie banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, and failed loads are not billed. Its MCP server lets AI agents take screenshots. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Learn about ScreenshotNeo or sign up free for 1,000 screenshots a month, with no card.

Frequently Asked Questions

Does netstat show UDP connections?

It can show UDP ports on which the computer is listening with -a; UDP does not use the TCP connection states shown in the State column.

Which Windows versions does Microsoft document netstat for?

Microsoft’s reference covers Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.