MYTHOSAI

Windows security / PRACTICAL GUIDE

Find which Windows process owns a network connection

Use built-in PowerShell to connect an established TCP session to its process.

Before you start

Windows PowerShell; administrator access can reveal additional process details.

Capture a snapshot first

An unexpected connection is an investigation lead, not a malware diagnosis. Browsers, backup agents, update services and collaboration software create many normal connections. The same cloud address can serve many unrelated customers.

List established TCP connections:

powershell
Get-NetTCPConnection -State Established |
  Select-Object LocalAddress, LocalPort, RemoteAddress,
    RemotePort, OwningProcess

The result is a snapshot. Short-lived sessions may finish before you inspect their process. UDP traffic is not included in this command.

Look up one owning process

Take an OwningProcess value from the result and use it in this separate command:

powershell
Get-Process -Id 1234 | Select-Object Id, ProcessName, Path

Replace 1234 with the real process number. Do not repurpose PowerShell's built-in $PID variable. If the process exited, the query can fail; that does not itself prove evasion or malicious activity.

Build context before deciding

  1. Check the process path and whether it belongs to an expected installed application.
  2. Review its publisher signature through the file properties where available.
  3. Compare connection timing with your own activity: opening a browser tab, running a backup or installing updates.
  4. Investigate unfamiliar persistent connections using approved logs and tooling. Do not terminate a system process solely because its name is unfamiliar.

You can use Resource Monitor's Network tab for a graphical view. Process ownership and network activity remain separate from whether the remote service is trustworthy.

Verify an explanation

If a known application is responsible, close it normally and repeat the query. Some background services will remain active by design. Record the process, path, destination and time so someone else can reproduce the observation. Avoid publishing an unredacted connection list from a sensitive business computer.

Common mistakes

Port 443 usually suggests HTTPS but is not proof of benign behaviour. A legitimate signature does not guarantee every action is appropriate. A process name can be copied. Conversely, a connection to a content-delivery network is not proof of data theft.

Escalation

If several indicators align with compromise, isolate according to your incident process and preserve evidence. This read-only workflow helps identify the owner; it does not replace endpoint investigation or prove that a device is clean.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.