This is an old revision of the document!
Microsoft Windows
Commandes rรฉseau
- ๐ถ๐ฝ๐ฐ๐ผ๐ป๐ณ๐ถ๐ด โ Show network configuration
- ๐ถ๐ฝ๐ฐ๐ผ๐ป๐ณ๐ถ๐ด /๐ฎ๐น๐น โ Detailed IP/DNS info for incident validation
- ๐ถ๐ฝ๐ฐ๐ผ๐ป๐ณ๐ถ๐ด /๐ฟ๐ฒ๐น๐ฒ๐ฎ๐๐ฒ โ Release IP to cut rogue connections
- ๐ถ๐ฝ๐ฐ๐ผ๐ป๐ณ๐ถ๐ด /๐ฟ๐ฒ๐ป๐ฒ๐ โ Renew IP after network reset
- ๐ถ๐ฝ๐ฐ๐ผ๐ป๐ณ๐ถ๐ด /๐ณ๐น๐๐๐ต๐ฑ๐ป๐ โ Clear DNS cache (stop DNS poisoning)
- ๐ฝ๐ถ๐ป๐ด [๐๐ฃ] โ Test host reachability (detect filtering/DoS)
- ๐๐ฟ๐ฎ๐ฐ๐ฒ๐ฟ๐ [๐๐ฃ] โ Trace suspicious traffic path
- ๐ป๐๐น๐ผ๐ผ๐ธ๐๐ฝ [๐ฑ๐ผ๐บ๐ฎ๐ถ๐ป] โ Investigate phishing/malware domains
- ๐ป๐ฒ๐๐๐๐ฎ๐ -๐ฎ๐ป โ Spot unusual open ports & connections
- ๐ป๐ฒ๐๐๐๐ฎ๐ -๐ฏ โ See which process is making network connections
- ๐ฎ๐ฟ๐ฝ -๐ฎ โ Detect ARP spoofing/poisoning attempts
- ๐ต๐ผ๐๐๐ป๐ฎ๐บ๐ฒ โ Verify compromised system identity
- ๐ด๐ฒ๐๐บ๐ฎ๐ฐ โ Validate legitimate MAC addresses
- ๐ป๐ฒ๐ ๐๐๐ฒ โ Check unauthorized shared drive access
- ๐ป๐ฒ๐ ๐๐ต๐ฎ๐ฟ๐ฒ โ List shared resources for data exfil risks
- ๐ป๐ฒ๐ ๐๐๐ฎ๐ฟ๐ โ Spot suspicious or unauthorized services
- ๐ป๐ฒ๐ ๐๐๐ผ๐ฝ โ Kill malicious services
- ๐๐ฎ๐๐ธ๐น๐ถ๐๐ โ See running processes (correlate with netstat)
- ๐ฟ๐ผ๐๐๐ฒ ๐ฝ๐ฟ๐ถ๐ป๐ โ Inspect routing table for anomalies
- ๐ป๐ฒ๐๐๐ต ๐ฎ๐ฑ๐๐ณ๐ถ๐ฟ๐ฒ๐๐ฎ๐น๐น ๐ณ๐ถ๐ฟ๐ฒ๐๐ฎ๐น๐น ๐๐ต๐ผ๐ ๐ฟ๐๐น๐ฒ ๐ป๐ฎ๐บ๐ฒ=๐ฎ๐น๐น โ Review firewall rules for