Port Reference
Search common ports, triage scan output, build selected-port Nmap commands, and copy report-ready service notes for authorized assessments.
98
Total ports
98
Showing
0
Selected
39
High risk shown
Operator presets
Start from common assessment slices, then refine the selected ports.
Port table
Click a row for details, or select rows for copy/export actions.
| Select | Notes | ||||
|---|---|---|---|---|---|
FTP data transfer | File Sharing | low | Often filtered, used with port 21 | ||
File Transfer Protocol control | File Sharing | high | Anonymous login, credential brute-force, bounce attacks | ||
Secure Shell | Remote Access | high | Brute-force, key-based attacks, tunneling | ||
Unencrypted remote access | Remote Access | high | Cleartext credentials, legacy systems | ||
Simple Mail Transfer Protocol | high | Open relay, user enumeration (VRFY) | |||
Domain Name System | Infrastructure | medium | Zone transfers (AXFR), DNS tunneling | ||
DHCP Server | Infrastructure | low | Rogue DHCP, starvation attacks | ||
DHCP Client | Infrastructure | low | Client-side attacks | ||
Trivial File Transfer | File Sharing | high | No authentication, file retrieval | ||
Web Server | Web | medium | Web app attacks, directory bruteforce | ||
Kerberos authentication | Directory / AD | high | AS-REP roasting, Kerberoasting | ||
Post Office Protocol | medium | Credential brute-force | |||
RPC Port Mapper | Infrastructure | medium | Enumerate RPC services | ||
Network Time Protocol | Infrastructure | medium | NTP amplification DDoS | ||
Microsoft RPC | Infrastructure | high | RPC enumeration, WMI access | ||
NetBIOS Name Service | Infrastructure | low | Name enumeration | ||
NetBIOS Datagram | Infrastructure | low | Browser service attacks | ||
NetBIOS Session | File Sharing | high | SMB over NetBIOS, null sessions | ||
Internet Message Access Protocol | medium | Email access, credential attacks | |||
Simple Network Management | Infrastructure | high | Community string brute-force, info disclosure | ||
SNMP Traps | Infrastructure | low | Trap spoofing | ||
Lightweight Directory Access | Directory / AD | high | Anonymous bind, AD enumeration | ||
HTTP over TLS | Web | medium | SSL/TLS attacks, web app testing | ||
Server Message Block | File Sharing | high | EternalBlue, relay attacks, shares | ||
Kerberos password change | Directory / AD | low | Password attacks | ||
IPSec/IKE VPN | VPN / Tunneling | medium | VPN enumeration, aggressive mode | ||
Industrial control protocol | OT / IoT | high | Unauthenticated OT control, device register reads/writes | ||
System Logging | Infrastructure | medium | Log injection, info gathering | ||
Line Printer Daemon | Infrastructure | low | Printer exploitation | ||
IBM DB2 Discovery | Database | low | Database enumeration | ||
Apple Filing Protocol | File Sharing | medium | macOS file sharing attacks | ||
Real Time Streaming Protocol | Web | low | Camera/streaming enumeration | ||
SMTP Submission | medium | Email submission, credential attacks | |||
Microsoft RPC over HTTP | Web | low | Exchange RPC | ||
Intelligent Platform Management | Infrastructure | high | Hash dump, cipher zero attack | ||
LDAP over SSL | Directory / AD | medium | Secure LDAP enumeration | ||
Remote Sync | File Sharing | medium | Anonymous access, file retrieval | ||
IMAP over SSL | medium | Secure email access | |||
POP3 over SSL | medium | Secure email retrieval | |||
SOCKS Proxy | VPN / Tunneling | medium | Proxy pivoting | ||
Java Remote Method Invocation | Other | high | Deserialization attacks | ||
Microsoft SQL Server | Database | high | SQL injection, xp_cmdshell | ||
SQL Server Browser | Database | medium | Instance enumeration | ||
Oracle Database | Database | high | TNS listener attacks | ||
Point-to-Point Tunneling | VPN / Tunneling | medium | VPN attacks, MS-CHAPv2 cracking | ||
MQ Telemetry Transport | OT / IoT | medium | IoT broker discovery, anonymous publish/subscribe checks | ||
Universal Plug and Play discovery | OT / IoT | medium | Device discovery, amplification risk, unexpected perimeter exposure | ||
Network File System | File Sharing | medium | Share enumeration, access | ||
Docker API (unencrypted) | DevOps / Admin | high | Container escape, RCE | ||
Docker API (TLS) | DevOps / Admin | medium | Certificate attacks | ||
etcd client API | DevOps / Admin | high | Kubernetes secret exposure, cluster state access | ||
etcd peer communication | DevOps / Admin | high | Cluster membership exposure, peer trust review | ||
Grafana dashboard or Node development server | Security Tooling | medium | Default credentials, exposed dashboards, dev stack leakage | ||
AD Global Catalog | Directory / AD | medium | AD enumeration | ||
AD Global Catalog over SSL | Directory / AD | medium | Secure AD enumeration | ||
MySQL Database | Database | high | Credential attacks, UDF | ||
Remote Desktop Protocol | Remote Access | high | BlueKeep, brute-force, session hijacking | ||
Frontend development server | DevOps / Admin | medium | Development build exposure, source maps, internal API clues | ||
Erlang Port Mapper | Messaging | low | RabbitMQ, distributed Erlang | ||
Local AWS service emulator | DevOps / Admin | medium | Local cloud emulator exposure, test secrets, weak isolation | ||
Common dev server port | DevOps / Admin | medium | Docker Registry, Flask | ||
PostgreSQL Database | Database | high | Database attacks | ||
Elastic dashboard interface | Security Tooling | medium | Unauthenticated dashboards, saved objects, data exposure | ||
Alternate Kibana or Elastic UI port | DevOps / Admin | medium | Exposed admin UI, plugin and version fingerprinting | ||
RabbitMQ | Messaging | medium | Message queue attacks | ||
Constrained Application Protocol | OT / IoT | medium | IoT endpoint discovery, unauthenticated resource enumeration | ||
CoAP over DTLS | OT / IoT | medium | IoT secure transport review, weak DTLS or exposed resources | ||
Virtual Network Computing | Remote Access | high | Authentication bypass, brute-force | ||
Windows Remote Management | Remote Access | high | PowerShell remoting | ||
WinRM over HTTPS | Remote Access | high | Secure PS remoting | ||
Redis Database | Database | high | Unauthenticated access, RCE | ||
Kubernetes API server | DevOps / Admin | high | Cluster API exposure, authz review, service account token impact | ||
Internet Relay Chat | Messaging | low | Botnet C2, info gathering | ||
Oracle WebLogic administration/application port | DevOps / Admin | high | Admin console exposure, deserialization and patch review | ||
Alternative HTTP | Security Tooling | medium | Development servers | ||
HTTP Proxy/Alt | DevOps / Admin | medium | Tomcat, Jenkins, proxies | ||
Artifact repository interface | DevOps / Admin | high | Repository browsing, default credentials, dependency tampering risk | ||
Alternate Nexus/Artifactory service port | DevOps / Admin | high | Exposed repositories, anonymous pull/push, stale components | ||
Splunk management API | Security Tooling | medium | Admin API exposure, app upload impact, credential review | ||
HashiCorp Vault API/UI | DevOps / Admin | high | Secret store exposure, auth method and policy review | ||
Alternative HTTPS | Web | medium | Management interfaces | ||
HashiCorp Consul HTTP API/UI | DevOps / Admin | high | Service catalog exposure, KV secrets, remote exec/config risk | ||
MQTT over TLS | OT / IoT | high | IoT broker TLS/auth review, certificate and topic access checks | ||
Alternative HTTP | DevOps / Admin | medium | Jupyter, various apps | ||
PHP-FPM, SonarQube | DevOps / Admin | medium | FastCGI attacks | ||
MinIO object storage console | DevOps / Admin | medium | Object storage admin exposure, default credentials, bucket policy review | ||
Prometheus metrics UI/API | Security Tooling | medium | Metrics disclosure, target inventory, internal labels and secrets | ||
Elasticsearch REST API | Security Tooling | high | Data exposure, RCE | ||
Git Protocol | File Sharing | medium | Repository access | ||
Container registry or admin HTTPS interface | DevOps / Admin | medium | Registry exposure, project permissions, image pull/push controls | ||
Web administration interface | DevOps / Admin | high | Admin panel exposure, brute-force, patch and module review | ||
Kubernetes kubelet API | DevOps / Admin | high | Node/pod enumeration, exec/log access impact, authz review | ||
Legacy read-only kubelet API | DevOps / Admin | high | Unauthenticated pod/node metadata exposure on older clusters | ||
Memcached Cache | Database | high | Data exposure, amplification | ||
MongoDB Database | Database | high | Unauthenticated access | ||
MongoDB Shard | Database | medium | Shard server access | ||
Building automation and control network | OT / IoT | medium | Building system discovery, device/object enumeration | ||
SAP Management Console | Other | medium | SAP enumeration |
Use in authorized environments only
Generated commands are lookup and enumeration helpers. Confirm scope, rate limits, and written authorization before scanning live systems.