daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

common-ports-and-services.md (22671B)


      1 ---
      2 title: "Common Ports & Services (2026)"
      3 description: "Field reference for common TCP/UDP ports and services — core internet, Windows/AD, web, database and remote-access mappings with confirmation tips."
      4 category: enumeration
      5 tags: ["enumeration", "port-scanning", "network"]
      6 tools: ["Nmap", "ffuf", "smbmap", "NetExec", "ldapsearch"]
      7 difficulty: beginner
      8 updated: "2026-08-28"
      9 source: "vault:Enumeration/Common Ports and Services Cheatsheet 2026.md"
     10 ---
     11 > [!important]+ The Rule That Prevents Bad Findings
     12 > A port number is a **convention**, not proof of the application behind it. TCP and UDP are separate namespaces, services move to non-standard ports, and multiple products reuse popular ports such as 443, 8080, and 9000. Confirm with `nmap -sV`, a protocol handshake, TLS certificate/SNI, and application behaviour.
     13 >
     14 > Pairs with: Nmap Cheatsheet 2026, Nmap NSE Scripts Cheatsheet 2026, and NSE Guide.
     15 
     16 ---
     17 
     18 ## Port Number Ranges
     19 
     20 | Range | IANA Class | Typical Use |
     21 |---:|---|---|
     22 | `0` | Reserved | Not a normal service port; some scanners only include it when explicitly requested |
     23 | `1–1023` | System ports | Core protocols and privileged listeners on Unix-like systems |
     24 | `1024–49151` | User/registered ports | Applications and registered vendor services |
     25 | `49152–65535` | Dynamic/private ports | Client ephemeral ports, dynamic RPC, and private services |
     26 
     27 > [!note]+ Same Number, Different Transport
     28 > `53/tcp` and `53/udp` are different endpoints. DNS uses both; `514/udp` usually means syslog while `514/tcp` historically maps to the remote-shell service. Always record `port/protocol`, not the number alone.
     29 
     30 ---
     31 
     32 ## Core Internet and Infrastructure Services
     33 
     34 | Port | Transport | Usual Service | What It Normally Does / Important Note |
     35 |---:|:---:|---|---|
     36 | 20 | TCP | FTP data | Active-mode FTP data channel |
     37 | 21 | TCP | FTP control | File transfer commands and authentication |
     38 | 22 | TCP | SSH | Secure shell; also SFTP and SCP |
     39 | 23 | TCP | Telnet | Cleartext remote terminal; common on legacy/IoT equipment |
     40 | 25 | TCP | SMTP | Server-to-server mail transfer; STARTTLS may upgrade encryption |
     41 | 49 | TCP/UDP | TACACS+ / TACACS | Network-device AAA; TACACS+ normally uses TCP |
     42 | 53 | TCP/UDP | DNS | UDP for most queries; TCP for large responses, zone transfers, and fallback |
     43 | 67 | UDP | DHCP server | IPv4 address/configuration offers |
     44 | 68 | UDP | DHCP client | IPv4 DHCP client endpoint |
     45 | 69 | UDP | TFTP | Simple unauthenticated file transfer; PXE/network-device use |
     46 | 80 | TCP | HTTP | Unencrypted web traffic or redirect to HTTPS |
     47 | 88 | TCP/UDP | Kerberos | Authentication, especially Active Directory |
     48 | 110 | TCP | POP3 | Mailbox retrieval without implicit TLS |
     49 | 111 | TCP/UDP | rpcbind/portmapper | Maps ONC RPC programs; commonly exposes NFS-related services |
     50 | 119 | TCP | NNTP | Usenet/news transfer |
     51 | 123 | UDP | NTP | Network time synchronization |
     52 | 135 | TCP | MS RPC endpoint mapper | Microsoft DCOM/RPC service discovery |
     53 | 137 | UDP | NetBIOS name service | Legacy Windows name registration/resolution |
     54 | 138 | UDP | NetBIOS datagram | Legacy Windows connectionless messaging/browsing |
     55 | 139 | TCP | NetBIOS session/SMB | SMB over NetBIOS; legacy Windows file sharing |
     56 | 143 | TCP | IMAP | Mailbox access without implicit TLS |
     57 | 161 | UDP | SNMP | Device monitoring and management queries |
     58 | 162 | UDP | SNMP trap | Unsolicited SNMP alerts to a manager |
     59 | 179 | TCP | BGP | Inter-router Internet routing protocol |
     60 | 389 | TCP/UDP | LDAP / CLDAP | Directory queries; UDP is commonly CLDAP discovery |
     61 | 427 | TCP/UDP | SLP | Service Location Protocol discovery |
     62 | 443 | TCP/UDP | HTTPS / HTTP/3 | HTTPS over TCP; QUIC/HTTP/3 commonly uses UDP 443 |
     63 | 445 | TCP | SMB | Direct-hosted SMB for Windows file, printer, and AD services |
     64 | 464 | TCP/UDP | Kerberos password change | `kpasswd` password set/change service |
     65 | 500 | UDP | IKE/ISAKMP | IPsec VPN key exchange |
     66 | 514 | UDP | Syslog | Traditional unencrypted log transport |
     67 | 514 | TCP | rsh `shell` | Legacy remote shell assignment; modern syslog-over-TCP deployments also reuse it |
     68 | 515 | TCP | LPD/LPR | Legacy network printing |
     69 | 520 | UDP | RIP | IPv4 routing updates |
     70 | 521 | UDP | RIPng | IPv6 routing updates |
     71 | 546 | UDP | DHCPv6 client | IPv6 DHCP client endpoint |
     72 | 547 | UDP | DHCPv6 server | IPv6 DHCP server/relay endpoint |
     73 | 548 | TCP | AFP | Apple Filing Protocol |
     74 | 554 | TCP/UDP | RTSP | Streaming-media session control |
     75 | 587 | TCP | Mail submission | Authenticated client-to-mail-server submission with STARTTLS |
     76 | 623 | UDP | IPMI RMCP | Out-of-band baseboard management traffic |
     77 | 631 | TCP/UDP | IPP/CUPS | Modern network printing and print-service discovery |
     78 | 636 | TCP | LDAPS | LDAP wrapped in TLS |
     79 | 853 | TCP/UDP | Encrypted DNS | DNS over TLS on TCP; DNS over QUIC may use UDP |
     80 | 873 | TCP | rsync | File synchronization; modules may be exposed anonymously |
     81 | 989 | TCP | FTPS data | FTP data over implicit TLS |
     82 | 990 | TCP | FTPS control | FTP control over implicit TLS |
     83 | 993 | TCP | IMAPS | IMAP over implicit TLS |
     84 | 995 | TCP | POP3S | POP3 over implicit TLS |
     85 
     86 ---
     87 
     88 ## Windows and Active Directory
     89 
     90 | Port/Range | Transport | Service | AD / Windows Role |
     91 |---:|:---:|---|---|
     92 | 53 | TCP/UDP | DNS | AD-integrated DNS and domain-controller discovery |
     93 | 88 | TCP/UDP | Kerberos | Ticket granting and service authentication |
     94 | 123 | UDP | NTP | Domain time synchronization; Kerberos is time-sensitive |
     95 | 135 | TCP | MSRPC endpoint mapper | Locates dynamic RPC services |
     96 | 137–139 | TCP/UDP | NetBIOS | Legacy naming, datagrams, and SMB sessions |
     97 | 389 | TCP/UDP | LDAP/CLDAP | Directory queries and DC discovery |
     98 | 445 | TCP | SMB | Shares, named pipes, Group Policy, SYSVOL/NETLOGON |
     99 | 464 | TCP/UDP | `kpasswd` | Kerberos password operations |
    100 | 593 | TCP | RPC over HTTP | Microsoft RPC transport over HTTP |
    101 | 636 | TCP | LDAPS | TLS-wrapped LDAP |
    102 | 3268 | TCP | Global Catalog LDAP | Forest-wide partial directory search |
    103 | 3269 | TCP | Global Catalog LDAPS | TLS-wrapped Global Catalog |
    104 | 3389 | TCP/UDP | RDP | Remote Desktop; modern RDP also uses UDP |
    105 | 5985 | TCP | WinRM HTTP | PowerShell remoting/WS-Management without TLS wrapper |
    106 | 5986 | TCP | WinRM HTTPS | TLS-wrapped WinRM |
    107 | 9389 | TCP | AD Web Services | PowerShell AD module and AD Administrative Center |
    108 | 49152–65535 | TCP | Dynamic RPC | Default modern Windows high RPC endpoint range |
    109 
    110 ```bash
    111 # Targeted AD/DC service confirmation
    112 sudo nmap -sS -sU -Pn -sV \
    113   -p T:53,88,135,139,389,445,464,593,636,3268,3269,3389,5985,5986,9389,U:53,88,123,137,138,389,464 \
    114   <target>
    115 ```
    116 
    117 > [!tip]+ Recognizing a Domain Controller
    118 > The combination of DNS, Kerberos, LDAP, SMB, Global Catalog, and AD Web Services is much more meaningful than any one open port. Use `-sV`, LDAP RootDSE, SMB discovery, DNS SRV records, and TLS certificates to confirm the role.
    119 
    120 ---
    121 
    122 ## Remote Administration, AAA, Proxies, and VPNs
    123 
    124 | Port | Transport | Usual Service | Note |
    125 |---:|:---:|---|---|
    126 | 22 | TCP | SSH | Unix/network-device administration and tunnelling |
    127 | 23 | TCP | Telnet | Cleartext legacy administration |
    128 | 49 | TCP | TACACS+ | Central network-device authentication/authorization/accounting |
    129 | 443 | TCP | SSL VPN / web admin | Common shared port; fingerprint the product |
    130 | 500 | UDP | IKE | IPsec phase-one negotiation |
    131 | 1080 | TCP | SOCKS proxy | Generic TCP proxy/pivot endpoint |
    132 | 1194 | UDP/TCP | OpenVPN | UDP is the common default |
    133 | 1701 | UDP | L2TP | Often paired with IPsec rather than exposed alone |
    134 | 1723 | TCP | PPTP control | Data uses GRE IP protocol 47, not another TCP/UDP port |
    135 | 1812 | UDP | RADIUS authentication | Network access authentication |
    136 | 1813 | UDP | RADIUS accounting | Session/accounting records |
    137 | 3128 | TCP | Squid HTTP proxy | Forward proxy and web cache |
    138 | 3389 | TCP/UDP | RDP | Windows graphical administration |
    139 | 4500 | UDP | IPsec NAT-T | Encapsulates IPsec ESP through NAT |
    140 | 4899 | TCP | Radmin | Third-party Windows remote administration |
    141 | 5900–5999 | TCP | VNC | Display numbers commonly map from 5900 upward |
    142 | 5985/5986 | TCP | WinRM | Windows remote management over HTTP/HTTPS |
    143 | 7547 | TCP | TR-069/CWMP | ISP management of customer-premises equipment |
    144 | 8291 | TCP | MikroTik Winbox | RouterOS administration |
    145 | 10000 | TCP | Webmin | Unix web administration console |
    146 | 16992–16995 | TCP | Intel AMT | Out-of-band management, HTTP(S), and redirection services |
    147 | 51820 | UDP | WireGuard | Common/default WireGuard tunnel port; configurable |
    148 
    149 ---
    150 
    151 ## File Sharing, Storage, and Printing
    152 
    153 | Port | Transport | Service | Typical Use |
    154 |---:|:---:|---|---|
    155 | 20/21 | TCP | FTP | Legacy file transfer |
    156 | 22 | TCP | SFTP/SCP | SSH-based encrypted file transfer |
    157 | 69 | UDP | TFTP | PXE boot, firmware, and network-device configs |
    158 | 111 | TCP/UDP | rpcbind | Discovers dynamic NFS/ONC RPC programs |
    159 | 139/445 | TCP | SMB | Windows/Samba file and printer sharing |
    160 | 515 | TCP | LPD | Legacy printer queue protocol |
    161 | 548 | TCP | AFP | Legacy Apple file sharing |
    162 | 631 | TCP/UDP | IPP | CUPS and modern printing |
    163 | 873 | TCP | rsync | File synchronization modules |
    164 | 989/990 | TCP | FTPS | Implicit-TLS FTP data/control |
    165 | 2049 | TCP/UDP | NFS | Unix network file systems; modern NFS favors TCP |
    166 | 3260 | TCP | iSCSI | Block-storage transport |
    167 | 9100 | TCP | JetDirect/raw printing | Direct printer data socket; also reused by node_exporter |
    168 
    169 ---
    170 
    171 ## Databases, Search, and Caches
    172 
    173 | Port | Transport | Usual Product/Protocol | Note |
    174 |---:|:---:|---|---|
    175 | 1433 | TCP | Microsoft SQL Server | Database engine endpoint |
    176 | 1434 | UDP | SQL Server Browser | Instance/port discovery |
    177 | 1521 | TCP | Oracle TNS Listener | Oracle database connection broker |
    178 | 3050 | TCP | Firebird | Firebird relational database |
    179 | 3306 | TCP | MySQL/MariaDB | MySQL protocol |
    180 | 5432 | TCP | PostgreSQL | PostgreSQL wire protocol |
    181 | 5984 | TCP | CouchDB | HTTP API |
    182 | 6379 | TCP | Redis | In-memory data store; TLS is often configured elsewhere |
    183 | 7474 | TCP | Neo4j HTTP | Neo4j browser/HTTP API |
    184 | 7687 | TCP | Neo4j Bolt | Native Bolt protocol |
    185 | 8086 | TCP | InfluxDB | HTTP API |
    186 | 8123 | TCP | ClickHouse HTTP | HTTP query interface |
    187 | 8529 | TCP | ArangoDB | HTTP API |
    188 | 9000 | TCP | ClickHouse native | Also heavily reused by unrelated products |
    189 | 9042 | TCP | Cassandra CQL | Native Cassandra client protocol |
    190 | 9200 | TCP | Elasticsearch HTTP | REST API |
    191 | 9300 | TCP | Elasticsearch transport | Cluster/node transport |
    192 | 11211 | TCP/UDP | Memcached | Distributed memory cache; UDP should rarely be exposed |
    193 | 27017 | TCP | MongoDB | MongoDB client protocol |
    194 
    195 > [!warning]+ Databases Should Rarely Be Internet-Facing
    196 > An open database port is not automatically unauthenticated. Confirm binding scope, TLS, authentication, authorization, and network policy with approved credentials rather than inferring exposure from the port alone.
    197 
    198 ---
    199 
    200 ## Containers, Orchestration, and DevOps
    201 
    202 | Port | Transport | Usual Product/Service | Security-Relevant Note |
    203 |---:|:---:|---|---|
    204 | 2375 | TCP | Docker API (plain HTTP) | Unauthenticated exposure can amount to host control |
    205 | 2376 | TCP | Docker API (TLS) | Confirm mutual TLS and authorization |
    206 | 2377 | TCP | Docker Swarm management | Manager control plane |
    207 | 2379 | TCP | etcd client API | Kubernetes state/config data |
    208 | 2380 | TCP | etcd peer traffic | Cluster replication |
    209 | 3000 | TCP | Grafana / dev web server | Product convention, not reliable identification |
    210 | 4646 | TCP | Nomad HTTP API | HashiCorp Nomad control/API |
    211 | 4789 | UDP | VXLAN | Overlay-network encapsulation |
    212 | 5000 | TCP | Container registry / dev web | Frequently reused; fingerprint it |
    213 | 5601 | TCP | Kibana | Elastic web interface |
    214 | 6443 | TCP | Kubernetes API | Kubernetes control-plane API |
    215 | 8001 | TCP | Kubernetes API proxy | Common local `kubectl proxy` listener |
    216 | 8200 | TCP | HashiCorp Vault API | Secrets-management API |
    217 | 8500 | TCP | Consul HTTP API | Service catalog/control API |
    218 | 8501 | TCP | Consul HTTPS API | TLS-wrapped Consul HTTP API |
    219 | 8600 | TCP/UDP | Consul DNS | Service discovery through DNS |
    220 | 9000 | TCP | Portainer legacy / SonarQube / apps | Highly ambiguous convention |
    221 | 9090 | TCP | Prometheus | Metrics query and web UI |
    222 | 9093 | TCP | Alertmanager | Prometheus alert management |
    223 | 9100 | TCP | Prometheus node_exporter | Conflicts with raw printer convention |
    224 | 9418 | TCP | Git protocol | Unencrypted native Git transport |
    225 | 10250 | TCP | Kubelet API | Node-level Kubernetes API |
    226 | 15672 | TCP | RabbitMQ management | HTTP management UI/API |
    227 | 50000 | TCP | Jenkins inbound agent | Configurable; not every Jenkins uses it |
    228 
    229 ---
    230 
    231 ## Messaging, Queues, and Service Discovery
    232 
    233 | Port | Transport | Service | Typical Role |
    234 |---:|:---:|---|---|
    235 | 1883 | TCP | MQTT | Unencrypted IoT/message broker traffic |
    236 | 2181 | TCP | ZooKeeper | Distributed coordination |
    237 | 3478 | TCP/UDP | STUN/TURN | NAT traversal for real-time communications |
    238 | 3702 | UDP | WS-Discovery | Windows/printer/device discovery multicast |
    239 | 4222 | TCP | NATS | Client messaging endpoint |
    240 | 4369 | TCP | Erlang EPMD | Discovers Erlang distributed-node ports |
    241 | 5349 | TCP/UDP | TURN over TLS/DTLS | Encrypted relay service |
    242 | 5353 | UDP | mDNS | `.local` multicast service discovery |
    243 | 5355 | TCP/UDP | LLMNR | Windows local-link name resolution |
    244 | 5671 | TCP | AMQP over TLS | TLS-wrapped message queue protocol |
    245 | 5672 | TCP | AMQP | RabbitMQ and other AMQP brokers |
    246 | 5683 | UDP | CoAP | Constrained/IoT application protocol |
    247 | 5684 | UDP | CoAP over DTLS | Encrypted CoAP |
    248 | 8222 | TCP | NATS monitoring | HTTP monitoring endpoint |
    249 | 8883 | TCP | MQTT over TLS | TLS-wrapped MQTT |
    250 | 9092 | TCP | Apache Kafka | Broker/client protocol |
    251 | 25672 | TCP | Erlang/RabbitMQ distribution | RabbitMQ inter-node traffic |
    252 | 61613 | TCP | STOMP | Messaging protocol, often ActiveMQ |
    253 | 61616 | TCP | ActiveMQ OpenWire | ActiveMQ broker transport |
    254 
    255 ---
    256 
    257 ## Email and Collaboration
    258 
    259 | Port | Transport | Service | Typical Use |
    260 |---:|:---:|---|---|
    261 | 25 | TCP | SMTP | Mail relay/server-to-server transfer |
    262 | 110 | TCP | POP3 | Mail retrieval with optional STARTTLS |
    263 | 143 | TCP | IMAP | Mailbox access with optional STARTTLS |
    264 | 465 | TCP | Submissions over TLS | Implicit-TLS mail submission |
    265 | 587 | TCP | Message submission | Authenticated submission, normally STARTTLS |
    266 | 993 | TCP | IMAPS | IMAP over implicit TLS |
    267 | 995 | TCP | POP3S | POP3 over implicit TLS |
    268 | 2525 | TCP | Alternate SMTP/submission | Common provider convention, not universal |
    269 | 4190 | TCP | ManageSieve | Server-side mail-filter management |
    270 | 5222 | TCP | XMPP client | Client-to-server chat/federation ecosystem |
    271 | 5269 | TCP | XMPP server | Server-to-server federation |
    272 
    273 ---
    274 
    275 ## Voice, Video, and Real-Time Communications
    276 
    277 | Port/Range | Transport | Service | Typical Use |
    278 |---:|:---:|---|---|
    279 | 1720 | TCP | H.323 | Call signalling |
    280 | 2427 | UDP | MGCP gateway | Media gateway control |
    281 | 3478 | TCP/UDP | STUN/TURN | NAT discovery and media relay |
    282 | 4569 | UDP | IAX2 | Asterisk inter-server/client VoIP |
    283 | 5060 | TCP/UDP | SIP | Unencrypted signalling |
    284 | 5061 | TCP | SIP over TLS | TLS-wrapped SIP signalling |
    285 | 5349 | TCP/UDP | TURN over TLS/DTLS | Encrypted media relay |
    286 | 16384–32767 | UDP | RTP/RTCP convention | Dynamic voice/video media range; implementation-specific |
    287 
    288 ---
    289 
    290 ## Monitoring and Logging
    291 
    292 | Port | Transport | Service | Typical Use |
    293 |---:|:---:|---|---|
    294 | 161/162 | UDP | SNMP / traps | Polling and asynchronous device alerts |
    295 | 514 | UDP | Syslog | Traditional unencrypted logs |
    296 | 2003 | TCP | Graphite Carbon | Plaintext metric ingestion |
    297 | 5666 | TCP | NRPE | Nagios remote plugin execution |
    298 | 6514 | TCP | Syslog over TLS | Encrypted log transport |
    299 | 8125 | UDP | StatsD | Metric ingestion |
    300 | 9090 | TCP | Prometheus | Metrics/query web service |
    301 | 9093 | TCP | Alertmanager | Alert routing/management |
    302 | 9100 | TCP | node_exporter | Host metrics; conflicts with JetDirect convention |
    303 | 10050 | TCP | Zabbix agent | Agent checks |
    304 | 10051 | TCP | Zabbix server/trapper | Server/proxy collection endpoint |
    305 
    306 ---
    307 
    308 ## ICS / OT and Building Automation
    309 
    310 > [!danger]+ Fragile Environments
    311 > Do not assume ordinary IT scan rates are safe for PLCs, safety systems, field devices, printers, or building controllers. Prefer passive asset data and vendor-approved, rate-limited probes under explicit OT rules of engagement.
    312 
    313 | Port | Transport | Protocol/Product Family | Typical Environment |
    314 |---:|:---:|---|---|
    315 | 102 | TCP | ISO-TSAP / Siemens S7 | Siemens PLC programming/communications |
    316 | 502 | TCP | Modbus/TCP | PLC, HMI, energy, and industrial control |
    317 | 1911 | TCP | Niagara Fox | Building automation |
    318 | 1962 | TCP/UDP | PCWorx | Phoenix Contact PLC engineering |
    319 | 2404 | TCP | IEC 60870-5-104 | Electric utility telecontrol |
    320 | 4840 | TCP | OPC UA | Industrial interoperability/data modelling |
    321 | 5094 | TCP/UDP | HART-IP | Industrial field-device communications |
    322 | 9600 | TCP/UDP | OMRON FINS | OMRON PLC communications |
    323 | 20000 | TCP/UDP | DNP3 | Utility/SCADA telemetry and control |
    324 | 34962–34964 | UDP | PROFINET | Discovery, RPC/context, and alarms |
    325 | 44818 | TCP/UDP | EtherNet/IP | Common Industrial Protocol (CIP) |
    326 | 47808 | UDP | BACnet/IP | Building automation and HVAC |
    327 
    328 ---
    329 
    330 ## Frequently Ambiguous Web and Application Ports
    331 
    332 | Port | Common Possibilities | Do Not Assume |
    333 |---:|---|---|
    334 | 3000 | Grafana, Rails/Node/React dev server | That it is Grafana |
    335 | 5000 | Flask/dev server, Docker Registry, UPnP control, vendor API | That HTTP implies one product |
    336 | 8000 | Django/dev HTTP, appliance UI, streaming service | That it is “just alternate HTTP” |
    337 | 8008 | Alternate HTTP, Chromecast-related traffic, appliance UI | Product identity |
    338 | 8080 | Proxy, Tomcat, Jenkins, alternate HTTP/admin UI | That it is always a web proxy |
    339 | 8081 | Artifact repository, alternate admin UI, dev server | Nexus/Artifactory without fingerprints |
    340 | 8443 | Alternate HTTPS, Kubernetes/dashboard/appliance UI | That TLS identifies the application |
    341 | 8888 | Jupyter, alternate HTTP, proxy/control UI | That an exposed notebook exists |
    342 | 9000 | ClickHouse, SonarQube, Portainer legacy, PHP-FPM/vendor apps | Any single product |
    343 | 9100 | JetDirect raw printing or Prometheus node_exporter | Printer versus metrics service |
    344 | 9443 | Alternate HTTPS, container/admin UI | Product or authorization model |
    345 
    346 ```bash
    347 # Identify an ambiguous service instead of trusting the port label
    348 nmap -Pn -n -sV --version-all --reason -p3000,5000,8000,8080,8443,9000,9100 <target>
    349 
    350 # Add web/TLS metadata where applicable
    351 nmap -Pn -n -sV -p3000,5000,8000,8080,8443,9000,9100 \
    352   --script=http-title,http-headers,ssl-cert <target>
    353 ```
    354 
    355 ---
    356 
    357 ## High-Value UDP Triage List
    358 
    359 ```bash
    360 sudo nmap -sU -Pn -n -sV --reason \
    361   -p53,67,68,69,88,111,123,137,138,161,162,389,500,514,520,521,623,1434,1701,1812,1813,1900,2049,3478,3702,4500,4789,5060,5353,5355,5683,11211,20000,34962-34964,44818,47808,51820 \
    362   <target>
    363 ```
    364 
    365 | UDP Port | First Thought | Confirmation Idea |
    366 |---:|---|---|
    367 | 53 | DNS | `dig`, `dns-nsid`, recursion/authoritative checks |
    368 | 69 | TFTP | Request a known in-scope filename; avoid blind writes |
    369 | 123 | NTP | `ntpq`, `ntp-info` |
    370 | 161 | SNMP | `snmpwalk` with an approved community/credential |
    371 | 500/4500 | IPsec VPN | IKE fingerprinting; confirm NAT-T |
    372 | 623 | IPMI | RMCP/IPMI version and cipher checks |
    373 | 1434 | SQL Browser | Query instance names/ports |
    374 | 1900 | SSDP/UPnP | Multicast discovery and device description XML |
    375 | 5353 | mDNS | Browse `.local` service records |
    376 | 11211 | Memcached | Confirm UDP enablement; amplification exposure is high risk |
    377 
    378 ---
    379 
    380 ## IP Protocol Numbers Are Not Ports
    381 
    382 | IP Protocol Number | Protocol | Why You May See It |
    383 |---:|---|---|
    384 | 1 | ICMP | IPv4 errors and diagnostics |
    385 | 2 | IGMP | IPv4 multicast membership |
    386 | 4 | IP-in-IP | IP tunnelling |
    387 | 6 | TCP | Transmission Control Protocol |
    388 | 17 | UDP | User Datagram Protocol |
    389 | 41 | IPv6 encapsulation | IPv6-in-IPv4 tunnels |
    390 | 47 | GRE | PPTP data and generic routing encapsulation |
    391 | 50 | ESP | IPsec encrypted payload |
    392 | 51 | AH | IPsec authentication header |
    393 | 58 | ICMPv6 | IPv6 discovery, errors, and diagnostics |
    394 | 89 | OSPF | Interior routing protocol |
    395 | 132 | SCTP | Telecom/signalling and specialized applications |
    396 
    397 ```bash
    398 # Scan IP protocol numbers rather than TCP/UDP ports
    399 sudo nmap -sO --reason <target>
    400 ```
    401 
    402 ---
    403 
    404 ## From an Open Port to the Right Next Tool
    405 
    406 | Service | Confirm / Enumerate With |
    407 |---|---|
    408 | DNS | `dig`, `host`, `dnsrecon`, Nmap `dns-*` scripts |
    409 | FTP | `ftp`, `curl`, `ftp-anon`, banner and TLS inspection |
    410 | SSH | `ssh -vv`, `ssh-keyscan`, `ssh-audit`, SSH NSE scripts |
    411 | HTTP(S) | `curl`, browser/devtools, `whatweb`, `ffuf`, HTTP/TLS NSE |
    412 | SMB | `smbclient`, `enum4linux-ng`, `netexec`, `smbmap`, SMB NSE |
    413 | LDAP | `ldapsearch`, RootDSE query, TLS certificate review |
    414 | Kerberos | DNS SRV records, `kinit`, approved AD enumeration tooling |
    415 | SNMP | `snmpwalk`, `snmpget`, SNMP NSE scripts |
    416 | NFS | `rpcinfo`, `showmount`, NFS NSE scripts |
    417 | SMTP | `openssl s_client`, SMTP dialogue, `smtp-*` NSE scripts |
    418 | RDP | `xfreerdp`, RDP encryption/NTLM-info NSE |
    419 | WinRM | PowerShell remoting or `evil-winrm` with approved credentials |
    420 | Database | Native read-only client with an approved account; capture TLS/auth settings |
    421 
    422 ---
    423 
    424 ## Quick Reference Scan Sets
    425 
    426 ```bash
    427 # Common TCP infrastructure and administration
    428 sudo nmap -sS -Pn -n -sV \
    429   -p21,22,23,25,49,53,80,88,110,111,135,139,143,179,389,443,445,464,514,515,548,554,587,631,636,873,990,993,995,1080,1194,1433,1521,1723,2049,2375,2376,3000,3128,3260,3268,3269,3306,3389,5432,5672,5900,5985,5986,6379,6443,8080,8443,8883,9000,9090,9100,9200,10000,10250,11211,27017 \
    430   <target>
    431 
    432 # Core UDP infrastructure
    433 sudo nmap -sU -Pn -n -sV \
    434   -p53,67,68,69,88,111,123,137,138,161,162,389,500,514,520,521,623,1434,1701,1812,1813,1900,2049,3478,3702,4500,4789,5060,5353,5355,5683,51820 \
    435   <target>
    436 ```
    437 
    438 ---
    439 
    440 ## References
    441 
    442 1. [IANA Service Name and Transport Protocol Port Number Registry](https://www.iana.org/assignments/service-names-port-numbers/)
    443 2. [RFC 6335 — Service Name and Port Number Procedures](https://www.rfc-editor.org/rfc/rfc6335)
    444 3. [Nmap `nmap-services` Database](https://nmap.org/book/nmap-services.html)
    445 4. [Nmap Service and Version Detection](https://nmap.org/book/vscan.html)
    446 5. [Nmap Port Specification](https://nmap.org/book/man-port-specification.html)