Skip to content

Network Commands

Built-in Windows and Linux commands for checking a host's network configuration and connections.

Why It Matters

On a host under investigation, these commands answer the first network questions without installing anything: what IP the host has, what it is connected to, what is listening, and whether a destination is reachable.

Reference

Task Windows Linux
IP configuration ipconfig /all or Get-NetIPConfiguration ip a
Routing table route print ip r
ARP cache arp -a ip neigh
Traceroute tracert [host] traceroute [host]; TCP to a port: sudo traceroute -T -p 443 [host]
DNS lookup nslookup [domain] or Resolve-DnsName [domain] dig [domain]
Mail servers Resolve-DnsName [domain] -Type MX dig [domain] MX
A record only Resolve-DnsName [domain] -Type A dig [domain] A +short
SPF and DMARC records Resolve-DnsName [domain] -Type TXT dig [domain] TXT, dig _dmarc.[domain] TXT
Connections with process IDs netstat -ano or Get-NetTCPConnection ss -tunap
Listening ports with processes netstat -abno (requires administrator) ss -tulnp (or netstat -tulnp on older systems)
Protocol statistics netstat -s netstat -s or nstat
Ping ping -n 4 [host] ping -c 4 [host]
Test a TCP port Test-NetConnection [host] -Port 443 nc -zv [host] 443

How I Use It

On a suspect Windows host, netstat -ano and Get-NetTCPConnection tie connections to process IDs, which I then look up with tasklist or Get-Process. An established connection to an unfamiliar public IP from a process that should not be talking to the internet is one of the quickest leads there is. I record the output before containing the host, because isolation ends those connections.