if you are using a linux desktop, in order to detect each process activity on specific port, e.g when a hiddensuddenly
bind port at port 1337, you can use user mode technic just like lsof, another technic is by using a kernel module which runs on your kernel space, e.g by hooking netfilter to monitor incoming or outgoing packets.
but if you use windows, sorry, I can't help