Windows PowerShell: Query TCP connections with Get-NetTCPConnection

Detects PowerShell usage of Get-NetTCPConnection to enumerate TCP network connections.

FreeReviewedSigma · Low · v2
Product
windows
Category
ps_classic_start
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-10
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule matches PowerShell Classic command/script content containing Get-NetTCPConnection, which lists TCP network connections on the local or remote context available to the process. Adversaries can use this to enumerate active connections during discovery and understand network activity for further targeting. Telemetry relied on is Windows PowerShell Classic script or command text where the string Get-NetTCPConnection appears.

Related detections9 linkedT1049 — drag to rearrange
Suspicious Java Process Spawning Reconnaissance Commands via Cleo MFT (via process_creation)
Suspicious Reconnaissance Spawned by Injected SearchProtocolHost via process_creation
Windows Process Creation Signals for Pikabot System Discovery
Windows Net.exe Network Connections Discovery via Use Sessions Query
PowerShell Get-NetTCPConnection Network Connection Discovery (Windows)
Windows Process Creation: SharpView.exe with Recon/Domain Discovery Cmdlets
Linux System Network Connections Discovery via who, w, last, lsof, or netstat
macOS System Network Connection Discovery via who, w, last, lsof, or netstat
Cisco AAA discovery via show/dir commands
Windows PowerShell: Query TCP connections with Get-NetTCPConnection
Pivot detection · T1049 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.