netstat

netstat is an operating system utility that displays active TCP connections, listening ports, and network statistics. [1]

ID: S0104
Type: TOOL
Version: 1.4
Created: 31 May 2017
Last Modified: 27 November 2024

Techniques Used

Domain ID Name Use
Enterprise T1049 System Network Connections Discovery

netstat can be used to enumerate local network connections, including active TCP connections and other network statistics.[1]

Groups That Use This Software

Campaigns

ID Name Description
C0063 2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries used netstat to conduct reconnaissance, running C:\Windows\TEMP\outlog.txt && netstat -nao.[17]

C0026 C0026

[18]

C0007 FunnyDream

[19]

C0014 Operation Wocao

During Operation Wocao, threat actors used netstat to identify specific ports.[20]

References