Yes, everything you mentioned above is true. I know netstat is old and ss is new. I am coming from Windows and i do have someone poking around in my business. I know who it is, I'm just trying to get dead solid proof. I'm learning nmap,WireShark,and now Linux. I've noticed the system gives me...
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 Excalibur:60902 104.16.249.249:https ESTABLISHED
udp 0 0 Excalibur:bootpc _gateway:bootps ESTABLISHED
Active UNIX domain sockets (w/o servers)
Proto RefCnt...