netstat
MITRE ATT&CK: S0104 View on attack.mitre.org
Aliases: netstat
- Profile updated
- 2026-07-07 15:32:17
Context
netstat is an operating system utility that displays active TCP connections, listening ports, and network statistics.
Detection coverage
- 7 Sigma rules
Malware & tools used
- System Network Connections Discovery (attack-pattern)
Used by threat actors
- Operation Wocao (campaign)
- C0026 (campaign)
- FunnyDream (campaign)
- 2025 Poland Wiper Attacks (campaign)
- Threat Group-3390 (threat-actor)
- Volt Typhoon (threat-actor)
- Turla (threat-actor)
- Ke3chang (threat-actor)
- HEXANE (threat-actor)
- admin@338 (threat-actor)
- APT41 (threat-actor)
- Orangeworm (threat-actor)
- OilRig (threat-actor)
- ToddyCat (threat-actor)
- APT5 (threat-actor)
Reports & references
- MITRE ATT&CK — S0104 (report)
- Microsoft — Bb490947 (report)