Using Netstat Utility to locate suspecious hack on Windows Machine and how to delete the backddoor

Поделиться
HTML-код
  • Опубликовано: 22 окт 2024

Комментарии • 57

  • @mahbubla2011
    @mahbubla2011 11 месяцев назад +3

    Thank you so much for explaining in a way that is easy to understand

    • @KamilSec
      @KamilSec  10 месяцев назад

      You are very welcome

  • @shanejager7144
    @shanejager7144 5 месяцев назад +4

    Great information!

    • @KamilSec
      @KamilSec  4 месяца назад

      Glad it was helpful!

  • @leonjones7120
    @leonjones7120 2 года назад +6

    Thanks for explaining this for me. Very useful and understandable.

    • @KamilSec
      @KamilSec  2 года назад

      You are welcome!

  • @bintangprins
    @bintangprins 8 месяцев назад +2

    thanks man!!

    • @KamilSec
      @KamilSec  6 месяцев назад

      You are welcome

  • @captainprototype187
    @captainprototype187 Год назад +2

    Basic but I didnt know it, so very useful.

    • @KamilSec
      @KamilSec  Год назад

      Glad it was helpful!

  • @piratimir1101
    @piratimir1101 Год назад +2

    Useful information for a beginner. Checking the connections is not enough. Malware writers can hide their backdoor through normal PIDs.

    • @KamilSec
      @KamilSec  Год назад

      Absolutely! Malware creation tools like VIEL Evasion, Empire, FAT RAT all have these capabilities of migrating backdoor to a legitimate PIDs. However, like you rightly said, good starting point for beginners dealing with script kiddies.

    • @piratimir1101
      @piratimir1101 Год назад

      @@KamilSec Are you familiar with sysinternals tools ?

  • @vishalprabhakar3523
    @vishalprabhakar3523 3 года назад +3

    Great video and very helpful.

  • @wiki6466
    @wiki6466 Год назад +2

    thanks for explaining it so well

  • @LaurinX929
    @LaurinX929 3 месяца назад +1

    Thanks for sharing this, very helpful. If you have a broadcast IP with a port (192.168.x.x: 0000 whose state shows CLOSE_WAIT on the netstat -ano). What does that mean?

    • @KamilSec
      @KamilSec  3 месяца назад

      This means the remote server side connection socket is closed and waiting on the local connection socket to close.

  • @amandarusso487
    @amandarusso487 Год назад +3

    double click PID to get them in numerical order

  • @Valyrjia
    @Valyrjia Год назад +2

    Thank you!

  • @msa9307
    @msa9307 3 года назад +3

    Hello very helpful video but one question I searched and found nothing suspicious but some PID numbers on cmd I couldn't find them In task manager should I be worried? Thanks in advance

    • @KamilSec
      @KamilSec  3 года назад

      Try to expand the down arrow on the task managers to see the rest of the PIDs.

    • @cameronmarshall8247
      @cameronmarshall8247 2 года назад

      @@KamilSec Same here, i cant seem to find some of the PID connections in task manger.

  • @Intra-DayTrader
    @Intra-DayTrader 10 месяцев назад +1

    Not a single one of my established networks are loopback ip. They are all different. What does that mean?

    • @KamilSec
      @KamilSec  10 месяцев назад

      It is not always a bad idea, they could be legitimate connections for the process on your device

  • @hofsbter
    @hofsbter 6 месяцев назад +1

    what if u find a stablished connection in cmd but the pid found in cmd doesnt show on task manager?

    • @KamilSec
      @KamilSec  5 месяцев назад +1

      It should, sometimes you just have to expand the rows

  • @algbla6042
    @algbla6042 4 года назад +2

    Great video.

  • @itsecha4996
    @itsecha4996 3 года назад +1

    Thank you very much for you video

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked Год назад +1

    Thanks a bunch!! :3

  • @shinzotb9582
    @shinzotb9582 Год назад +1

    Should i be worried because i have some program with nothing in the publisher name no "unknown" just nothing ?

    • @KamilSec
      @KamilSec  Год назад

      No I don't think is anything to worry about, just keep checking on the status of the connections

  • @skeletonking4119
    @skeletonking4119 2 года назад +1

    thanks you!!

    • @KamilSec
      @KamilSec  2 года назад +1

      You're very welcome!

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked Год назад +1

    Interesting that we can do -ano; all three commands in one. Hehe. 🔥🤓😎👨‍💻

  • @razuri4417
    @razuri4417 2 года назад

    Help most of my established connections are popular companies such as Razer, Microsoft and Nvidia should i still delete them?

  • @syeedlabeeb7293
    @syeedlabeeb7293 2 года назад +1

    Cant find pid of an established network . What should i do

    • @KamilSec
      @KamilSec  2 года назад

      It show be there. On the left hand side, you will see a pull down arrow, when you click on that it expands some of the hidden PID on the task manager.

  • @GiannisL31
    @GiannisL31 3 года назад +1

    if i have a pid number at cmd but at taskbar that pid doestn appear what does it mean?

    • @KamilSec
      @KamilSec  3 года назад

      You can turn on the PID on taskbar by "right clicking" on any of the others shown and select PID to display.

  • @4kgamer937
    @4kgamer937 Год назад +1

    Hey bro i have established connections with apple company , and i when i click on it its shows apple company files like bonjour file,is it possible that someone has created a backdoor and named it on apple😢

    • @KamilSec
      @KamilSec  Год назад

      You Good!!! Apple's Bonjour Program? Bonjour is Apple's implementation of zero-configuration networking (zeroconf). It allows devices running both Windows and Apple operating systems (like macOS and iOS) to connect and share resources without any configuration settings.

  • @sarahm2023
    @sarahm2023 Год назад

    is it possible that hackers can hide their acitivity in the netstat? because i checked the pc im currently are using and theres none suspicious established network

    • @KamilSec
      @KamilSec  Год назад

      Yes they can, but hopefully thats not the case here.

    • @sarahm2023
      @sarahm2023 Год назад

      @@KamilSec im in a big problem. i think ive been gangstalked for years. i need to make sure they will not have access to my life anymore.