Capture a snapshot first
An unexpected connection is an investigation lead, not a malware diagnosis. Browsers, backup agents, update services and collaboration software create many normal connections. The same cloud address can serve many unrelated customers.
List established TCP connections:
Get-NetTCPConnection -State Established |
Select-Object LocalAddress, LocalPort, RemoteAddress,
RemotePort, OwningProcessThe result is a snapshot. Short-lived sessions may finish before you inspect their process. UDP traffic is not included in this command.
Look up one owning process
Take an OwningProcess value from the result and use it in this separate command:
Get-Process -Id 1234 | Select-Object Id, ProcessName, PathReplace 1234 with the real process number. Do not repurpose PowerShell's built-in $PID variable. If the process exited, the query can fail; that does not itself prove evasion or malicious activity.
Build context before deciding
- Check the process path and whether it belongs to an expected installed application.
- Review its publisher signature through the file properties where available.
- Compare connection timing with your own activity: opening a browser tab, running a backup or installing updates.
- Investigate unfamiliar persistent connections using approved logs and tooling. Do not terminate a system process solely because its name is unfamiliar.
You can use Resource Monitor's Network tab for a graphical view. Process ownership and network activity remain separate from whether the remote service is trustworthy.
Verify an explanation
If a known application is responsible, close it normally and repeat the query. Some background services will remain active by design. Record the process, path, destination and time so someone else can reproduce the observation. Avoid publishing an unredacted connection list from a sensitive business computer.
Common mistakes
Port 443 usually suggests HTTPS but is not proof of benign behaviour. A legitimate signature does not guarantee every action is appropriate. A process name can be copied. Conversely, a connection to a content-delivery network is not proof of data theft.
Escalation
If several indicators align with compromise, isolate according to your incident process and preserve evidence. This read-only workflow helps identify the owner; it does not replace endpoint investigation or prove that a device is clean.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.