Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Use netstat in Windows to inspect active connections, listening ports, process IDs, routing, and network statistics. Open Command Prompt or PowerShell and run the command that matches your question; add -n for numeric addresses, -o for process IDs, or -b to try to identify executables.
Before you run netstat
Microsoft documents netstat for Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025. Without parameters, it displays active TCP connections. With switches, it can also show listening ports, Ethernet and protocol statistics, and the IP routing table. See Microsoft’s netstat reference, updated September 8, 2026.
Run the commands in Command Prompt or PowerShell. For executable attribution with -b, open the terminal with sufficient permissions: Microsoft notes that this option can take time and can fail without them. The examples below inspect the local computer; they do not establish that a connection is malicious or that a service is reachable from outside your network.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
1. List active connections and listening ports
Command
netstat -a
The -a switch displays active TCP connections and TCP and UDP ports on which the computer is listening. Use it when you need a broad view of local network activity or want to check whether a service has opened a listening port.
#1 Best Overall
Look at the Proto column for the protocol, then Local address and Foreign address for the endpoints. TCP rows also show a State. A listening entry indicates a local port waiting for connections; it does not, by itself, prove that a remote machine can reach it. Firewall rules, routing, and the service’s configuration also affect reachability.
2. Show numeric addresses and process IDs
Command
netstat -n -o
-n keeps addresses and port numbers numeric rather than resolving names. This can make output easier to scan and avoids waiting on name resolution. -o adds the process ID (PID) associated with each connection. Use the PID to identify an application in Windows Task Manager: open Task Manager, select Details, and match the value in the PID column.
A PID identifies a process, not necessarily a unique application window or service. One process can own multiple connections, and a shared host process can run more than one service. Treat the PID as a lead to investigate rather than a conclusion about what a connection is doing.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →3. Map connections and ports to executables
Command
netstat -b
The -b switch attempts to show the executable involved in each connection or listening port. Choose it when a PID is not enough and you want the program name directly in the output. Microsoft cautions that executable reporting can be time-consuming and may fail without sufficient permissions.
If it fails, reopen Command Prompt or PowerShell with appropriate elevated permissions and run the command again. For a lighter first pass, use netstat -n -o to collect numeric endpoints and PIDs, then look up the PID in Task Manager.
4. Inspect the IP routing table
Command
netstat -r
This displays the IP routing table and is equivalent to route print. Use it when diagnosing which routes are present on the computer. It answers a different question from the connection list: routes describe network paths the system can use, whereas connection rows describe active TCP connections.
5. Read statistics by protocol
Command
netstat -s
The -s switch displays statistics by protocol. To focus the output, add -p and a protocol, such as netstat -p tcp, netstat -p udp, netstat -p ip, or netstat -p icmp. Microsoft also documents tcpv6, udpv6, icmpv6, and ipv6 as protocol selections.
These are aggregate protocol counters, useful when you want a broader view than individual endpoints. They are not a per-application connection list. The reference does not provide a standalone benchmark or thresholds for interpreting a counter as healthy or unhealthy.
Rank #3
6. Combine Ethernet and protocol statistics
Command
netstat -e -s
-e displays Ethernet statistics, including bytes and packets sent and received. Microsoft documents combining it with -s to include protocol statistics as well. Use this when you want link-level traffic counters alongside a protocol-oriented view, rather than a list of individual connections.
7. Refresh output or combine switches
Refresh at an interval
netstat -o 5
A number after the options sets the refresh interval in seconds. This example redisplays the selected information every five seconds. Press Ctrl+C to stop. Use repeated output to observe changes over time; it is not a historical log, so capture the output separately if you need a record.
Show a broad set of connection details
netstat -anobq
Microsoft documents this combined command for displaying connections, listening ports, bound non-listening TCP ports, numeric addresses, PIDs, and executables. The switches bring together several useful views: visibility (-a), numeric output (-n), executable attribution (-b), process IDs (-o), and bound non-listening TCP ports (-q). Because it includes -b, permissions and execution time may be considerations.
How to choose the right command
| Question | Command or switch | What it adds |
|---|---|---|
| What connections and ports are active or listening? | netstat -a |
Active TCP connections and TCP/UDP listeners |
| Can I avoid name resolution and see the owning PID? | netstat -n -o |
Numeric addresses and process IDs |
| Which executable is involved? | netstat -b |
Attempts to show executable names; can be slow and require sufficient permissions |
| What routes are configured? | netstat -r |
IP routing table |
| What are the protocol counters? | netstat -s or netstat -p tcp |
Statistics by protocol, optionally focused with -p |
| What Ethernet counters are available? | netstat -e -s |
Ethernet statistics combined with protocol statistics |
| How is the output changing? | netstat -o 5 |
Repeated display every five seconds in this example |
Understand the output and TCP states
Microsoft defines the main connection columns as Proto, Local address, Foreign address, and State. With -n, address and port values stay numeric. The State column describes a TCP connection’s state; it is not shown as a state for UDP listeners.
LISTEN: a local TCP endpoint is waiting for a connection.ESTABLISHED: a TCP connection is established.SYN_SENT(shown in Microsoft’s reference asSYN_SEND): a connection attempt has sent a request and is awaiting a response.SYN_RECEIVED: a connection request has been received and is in the handshake process.FIN_WAIT_1,FIN_WAIT_2, andLAST_ACK: TCP shutdown states while endpoints close a connection.CLOSE_WAIT: the remote endpoint has closed, while the local side is yet to finish closing.TIME_WAIT(listed in Microsoft’s reference asTIMED_WAIT): a TCP connection is waiting before its resources are fully released.CLOSED: no connection is active.
A single snapshot is only a moment in time. A transient state may disappear on the next refresh, and a PID or port alone does not identify the purpose or safety of a connection. Combine the relevant netstat view with the application and network context you are investigating.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot common netstat questions
The port I expected is not listed
Use netstat -a to include listening ports, not just active connections. Check that the service is running and configured to listen on the expected interface and port. Netstat reports local state; it cannot establish from its output alone that a firewall or remote route permits access.
I see a PID but do not know the program
Use netstat -b for executable attribution, or match the PID from netstat -n -o with the PID column on Task Manager’s Details tab. If the PID belongs to a host process, more than one service may be associated with it.
The executable option fails or takes too long
-b can be time-consuming and requires sufficient permissions. Run the terminal with elevated permissions if appropriate. If you only need to identify the process, use -o and look up the PID instead.
Best Value
- Used Book in Good Condition
The output is difficult to read or slow to appear
Add -n to keep addresses and ports numeric and avoid name resolution. For a narrower view, select the needed switch rather than requesting executable names and every detail at once.
I need to see changes, not one snapshot
Add an interval in seconds, such as netstat -o 5, and stop the repeating display with Ctrl+C. The command redisplays current information; it does not create a durable log.
Or skip the browser setup
If your goal is to capture a website rather than inspect Windows network connections, ScreenshotNeo is a separate website screenshot API and MCP server for developers. A GET request returns a screenshot or PDF; the following cURL example saves a WebP screenshot of Stripe.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for setup and options. ScreenshotNeo removes cookie banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, and failed loads are not billed. Its MCP server lets AI agents take screenshots. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Learn about ScreenshotNeo or sign up free for 1,000 screenshots a month, with no card.
Frequently Asked Questions
Does netstat show UDP connections?
It can show UDP ports on which the computer is listening with -a; UDP does not use the TCP connection states shown in the State column.
Which Windows versions does Microsoft document netstat for?
Microsoft’s reference covers Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

