An incident handler is investigating a suspected data exfiltration on a Windows workstation. The SIEM generated an alert for a large outbound transfer to an unfamiliar IP address. The handler needs to determine which process initiated the connection. Which built-in Windows tool is most appropriate to correlate the active network connection to its owning process?
The -ano flags list all connections with their owning process ID (PID) in numeric form. Combined with Task Manager or tasklist, the PID maps directly to the executable, allowing the handler to identify which process initiated the suspicious outbound transfer. This is the fastest native method to correlate a live connection to its process without additional tooling.
Why this answer
Correlating a live network connection to its owning process is a core incident response task. The netstat -ano command provides the essential PID mapping, which can then be resolved to an executable using tasklist or Task Manager. This native capability allows rapid triage without installing additional tools, directly answering which process initiated the suspicious outbound transfer.
Exam trap
The trap here is assuming that DNS or route tracing tools can attribute network activity to a process, when only connection listing tools with PID output can do that.