A practical reference for sysadmins using netstat to detect unauthorized listening services, C2 connections, and suspicious network activity on Linux servers.

What is netstat?

netstat (network statistics) is a command-line utility that displays active network connections, listening ports, routing tables, and network interface statistics. It has been a standard Linux networking tool for decades and remains widely available on production systems even as ss has become the modern replacement. For security auditing, the combination netstat -tulpn is one of the most commonly used commands: it shows all TCP and UDP listening ports with the owning process name and PID. This immediately answers the critical security question: what services are publicly accessible on this server, and what processes are running them? During incident response, netstat -an reveals all established connections, allowing you to identify active C2 channels, unauthorized connections to internal services, and botnet beaconing activity by looking for ESTABLISHED connections to non-standard ports or unexpected remote addresses.

Syntax

netstat -tulpn
netstat -an
netstat -an | grep ESTABLISHED
netstat -an | grep LISTEN
netstat -s
netstat -rn

The -tulpn combination is the standard security audit command: TCP (-t), UDP (-u), listening only (-l), with process info (-p), and numeric addresses (-n). The -an combination shows all connections in all states. The -rn flag displays the routing table, useful for detecting unexpected route injections.

Key Options and Flags

Flag / ParameterDescriptionSecurity Note
-tShow TCP connections and sockets—
-uShow UDP connections and socketsUDP is used by some C2 channels and DNS-based exfiltration tools — do not omit
-lShow only listening sockets — services waiting for incoming connectionsAny unexpected listening service is a potential attack surface — investigate immediately
-pShow the PID and program name owning each socketRequired for correlating a suspicious port with its process — must run as root to see all processes
-nShow numeric addresses and ports — no DNS or service name resolutionAvoids DNS lookups that could alert an attacker and speeds up output on busy servers
-aShow all sockets in all states, including TIME_WAIT and CLOSE_WAIT—
-sDisplay per-protocol statistics including error countsHigh TCP reset or error counts can indicate a scan or DoS attempt in progress
-rnDisplay the kernel routing table with numeric addressesCheck for unexpected routes that could redirect traffic through an attacker-controlled gateway

Common Use Cases

Audit All Listening Services and Their Owning Processes

The most important security use of netstat is establishing exactly what services are publicly accessible on a server. Every listening socket on 0.0.0.0 or :: is accessible from the internet unless blocked by a firewall. Any service you did not intentionally configure should be investigated immediately.

netstat -tulpn

Find All Established Connections to Non-Standard Ports

C2 channels frequently use high or uncommon port numbers to blend with legitimate traffic. Filtering established connections and reviewing their remote ports against a known-good baseline quickly reveals suspicious outbound activity that warrants further investigation with lsof or ss.

netstat -an | grep ESTABLISHED | awk '{print $5}' | sort | uniq -c | sort -rn

Identify Unauthorized Listening Ports Opened by Malware

Backdoors and reverse shell listeners bind to a port on the server waiting for an inbound connection. After any suspected compromise, comparing netstat -tulpn output against a known baseline of expected services will reveal any new listeners. Pay particular attention to services listening on 0.0.0.0 (all interfaces) on ports you do not recognise.

netstat -tulpn | grep -v 'sshd\|nginx\|apache\|mysql\|postgres'

Security Relevance: Detecting C2 Channels via Established Socket Audit

Command-and-control (C2) malware maintains a persistent outbound connection from the compromised server to an attacker-controlled host. This connection appears in netstat as an ESTABLISHED entry with an unfamiliar remote IP and often a non-standard port. Unlike scanning tools, netstat reports the actual live connection state rather than probing from the outside, making it more reliable for detecting active C2 channels that only connect intermittently. The process name and PID provided by the -p flag are the bridge between the network anomaly and the forensic investigation: once you know the PID, you can use lsof -p <pid> to see all its open files and ps aux to check its parent process. Combined with ss for faster output on modern systems, netstat provides the network visibility layer that complements process-level monitoring from ps aux and htop.

  • A process with an ESTABLISHED connection to an IP not in your known infrastructure list warrants immediate investigation
  • netstat -p requires root privileges to show process names for all connections — run as root or results will be incomplete
  • netstat is deprecated on modern Linux in favour of ss but remains widely available — prefer ss on systems where both are present
  • TIME_WAIT connections are normal TCP teardown state and do not indicate active connections — focus on ESTABLISHED and LISTEN states

Practical Examples

Full listening service audit with process names

netstat -tulpn

The standard security audit command. Shows every service bound to a port, the protocol, the bind address, and the owning process. Any unfamiliar entry should be cross-referenced with ps aux and lsof.

Count and rank remote IPs by number of established connections

netstat -an | grep ESTABLISHED | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -rn | head -20

Surfaces the top remote IP addresses by connection count. A single IP with an unusually high number of connections may indicate a botnet node, a DoS source, or an active data exfiltration session.

Check routing table for unexpected gateway entries

netstat -rn

Displays the kernel routing table. An unexpected default gateway or a specific route pointing to an internal IP that you did not configure can indicate ARP spoofing or a routing hijack on the local network.

Troubleshooting Common Issues

Problem: netstat -p shows '-' instead of a process name for some connections

Solution: Run netstat as root. Non-root users cannot read /proc entries for processes they do not own. Sockets owned by root or other users will show ‘-‘ in the PID/Program column when netstat is run without root privileges.

Problem: netstat command not found on the system

Solution: On modern Debian/Ubuntu and RHEL systems, netstat is part of the net-tools package which is no longer installed by default. Install with apt install net-tools or use ss -tulpn as a direct replacement with identical security utility.

Problem: Output shows many connections in TIME_WAIT state causing concern

Solution: TIME_WAIT is a normal TCP state during connection teardown and does not represent active connections. It is expected on busy web servers. If the count is extremely high (tens of thousands), it may indicate a connection exhaustion issue from a high-traffic event or a slow-loris style attack — review in context with the source IPs.

Summary

netstat remains a reliable and widely available tool for network security auditing on Linux servers. The -tulpn combination provides an immediate answer to what is listening on your server, and -an | grep ESTABLISHED surfaces active connections that may represent C2 channels or unauthorized access. On modern systems, consider using ss as a faster alternative while keeping netstat in your toolkit for systems where ss is not available.

  • Run netstat -tulpn as the first network audit command on any new or suspected-compromised server
  • Any ESTABLISHED connection to an IP outside your known infrastructure warrants investigation with lsof -p <pid>
  • netstat requires root to show process names — always run with sudo for complete output

Is Your Linux Server Monitored 24/7?

INTRAM provides managed Linux hosting with continuous security monitoring, automated alerting, and expert response — so your team focuses on building, not firefighting.

Explore Managed Hosting

Let’s assess what your business actually needs.

We will use these details only to understand your request and reply appropriately.