netstat与PowerShell Get-Process的区别及结果不一致问题咨询
Netstat vs. Get-Process: Key Differences & Why Your PID 13708 Isn’t Showing Up
Great question—this is a super common gotcha when mixing Windows network tools and PowerShell process management. Let’s break this down step by step.
Core Differences Between netstat and Get-Process
These two tools pull data from completely different parts of the Windows system, which is why their results don’t always line up:
- Focus & Data Source:
netstatis a network-focused utility that talks directly to the Windows TCP/IP stack. It tracks active network connections, listening ports, and the PID associated with each connection—even if that PID is tied to kernel-level operations.Get-Processis a PowerShell cmdlet that queries the Windows Process Manager, which only lists user-mode processes (things with an executable.exefile you can see in Task Manager). It doesn’t touch kernel-level system components.
- Handling System/Kernel Entities:
- When
netstatencounters a connection owned by a kernel-mode driver or system component (not a user process), it labels it[System]and reports the PID used by the network stack to manage that connection. Get-Processignores these kernel-level "pseudo-processes" entirely because they aren’t traditional executable processes you can interact with.
- When
Why PID 13708 Is Missing From Get-Process
In your case, that lingering port 18882 labeled [System] is a classic leftover from an unclean proxy shutdown:
- When Titanium Web Proxy doesn’t exit properly, it might leave a network endpoint (the listening port) that gets picked up and held by the Windows kernel instead of the proxy’s own process.
- The PID 13708
netstatshows is tied to the kernel’s handling of that port, not a user-mode process. That’s whyGet-Processcan’t find it, andStop-Processthrows an error—there’s no actual.exeprocess to terminate here.
How to Free Up the Lingering Port
Since you can’t kill a kernel-held port with process termination tools, try these fixes:
- Restart the Network Connections service: Open Services (
services.msc), find "Network Connections", right-click and select Restart. This often clears lingering network endpoints. - Reset the TCP/IP stack: Run Command Prompt as admin and execute
netsh int ip reset. Note that this will reset your network adapter settings temporarily, so you might need to rejoin Wi-Fi or reconfigure static IPs if you use them. - Reboot your system: If all else fails, a reboot will clear all kernel-held resources, including that stuck port.
内容的提问来源于stack exchange,提问作者Cosmin
相关产品推荐
相关产品推荐

