Service-to-port map for enumeration. Ports are TCP unless the row says UDP. Services move, so always check with -sV. A port is only what the banner proves it is.
Always check first
The high-value set worth prioritising on any target.
Port
Service
Why it matters
21
FTP
Anonymous login, file read/write.
22
SSH
Version-specific bugs, key or password auth, tunneling.
25
SMTP
User enumeration (VRFY, EXPN, RCPT).
53
DNS
Zone transfer, subdomain and host names.
80 / 443
HTTP / HTTPS
Largest attack surface. Directory brute, vhosts, app bugs.
88
Kerberos
AD present. AS-REP roast, user enumeration.
111
rpcbind
Maps to NFS and other RPC services.
135 / 139 / 445
MSRPC / NetBIOS / SMB
Shares, users, RCE.
161 (UDP)
SNMP
Community strings leak users, processes, routes.
389 / 636
LDAP / LDAPS
AD objects, users, groups.
1433 / 3306 / 5432
MSSQL / MySQL / PostgreSQL
Weak creds, command execution.
3389
RDP
Credential access to Windows.
5985 / 5986
WinRM
Remote shell with valid creds (evil-winrm).
File sharing and transfer
Port
Proto
Service
Notes
20
TCP
FTP data
Active-mode data channel.
21
TCP
FTP control
Anonymous login, banner leaks version.
69
UDP
TFTP
No auth, no listing. Guess filenames.
111
TCP/UDP
rpcbind / portmapper
Lists RPC services. Feed into showmount.
135
TCP
MSRPC
Endpoint mapper. rpcdump, DCOM.
137
UDP
NetBIOS name
nmblookup, name resolution.
138
UDP
NetBIOS datagram
Browser service.
139
TCP
NetBIOS session
SMB over NetBIOS.
445
TCP
SMB / CIFS
Shares, users, EternalBlue.
512
TCP
rexec
Remote exec, cleartext creds.
513
TCP
rlogin
Trust-based login, .rhosts.
514
TCP
rsh
Remote shell, no auth if trusted.
548
TCP
AFP
Apple filing. nmap afp-* scripts.
873
TCP
rsync
Often anonymous module listing and file pull.
2049
TCP/UDP
NFS
showmount -e, mount exports, no_root_squash.
2121
TCP
FTP (alt)
Secondary FTP instance.
Remote access and shells
Port
Proto
Service
Notes
22
TCP
SSH
Auth methods, version bugs, port forwarding.
23
TCP
Telnet
Cleartext login, banner.
512-514
TCP
r-services
See file-sharing table. Trust abuse.
3389
TCP
RDP
xfreerdp, NLA check, BlueKeep on old hosts.
5800
TCP
VNC over HTTP
Java VNC applet.
5900
TCP
VNC
Weak or no password, vncviewer.
5985
TCP
WinRM HTTP
evil-winrm, crackmapexec winrm.
5986
TCP
WinRM HTTPS
TLS variant of WinRM.
6000-6009
TCP
X11
Keystroke capture, screenshots if open.
47001
TCP
WinRM (WSMan listener)
Windows remote management.
Web and application servers
Port
Proto
Service
Notes
80
TCP
HTTP
Primary web surface.
443
TCP
HTTPS
TLS web. Check certificate for hostnames.
280
TCP
http-mgmt
Management HTTP.
591
TCP
FileMaker HTTP
Alternate web.
593
TCP
HTTP-RPC-EPMAP
RPC over HTTP.
832
TCP
NetWare HTTP
Rare web admin.
981
TCP
HTTPS (alt)
Firewall admin panels.
1311
TCP
Dell OpenManage
Web admin.
2082 / 2083
TCP
cPanel
HTTP / HTTPS.
2086 / 2087
TCP
WHM
HTTP / HTTPS.
2095 / 2096
TCP
Webmail
HTTP / HTTPS.
3000
TCP
Node / Grafana / dev
App dev servers.
3128
TCP
Squid proxy
Proxy, may reach internal hosts.
4443
TCP
HTTPS (alt)
Admin consoles.
4848
TCP
GlassFish admin
Default creds, WAR deploy.
5000
TCP
Flask / UPnP / Docker registry
Context-dependent.
7001
TCP
WebLogic
Deserialization RCE.
7070
TCP
RealServer / app
HTTP variants.
8000
TCP
HTTP (alt)
Dev and admin apps.
8008
TCP
HTTP (alt)
Embedded web.
8009
TCP
AJP13
Tomcat AJP. Ghostcat file read.
8080
TCP
HTTP proxy / Tomcat
Manager panel, WAR upload.
8081
TCP
HTTP (alt)
JForum, Nexus, misc.
8180
TCP
Tomcat (alt)
Manager panel.
8443
TCP
HTTPS (alt)
Tomcat, VMware, admin.
8500
TCP
Consul / ColdFusion
Config store or app server.
8888
TCP
HTTP (alt)
Jupyter, admin panels.
9000
TCP
PHP-FPM / SonarQube
FastCGI or app.
9090
TCP
Openfire / Prometheus
Admin console.
9200 / 9300
TCP
Elasticsearch
REST API and transport. Data exposure.
10000
TCP
Webmin
RCE on old versions.
Mail
Port
Proto
Service
Notes
25
TCP
SMTP
User enumeration, open relay.
110
TCP
POP3
Cleartext mail retrieval.
143
TCP
IMAP
Cleartext mailbox access.
465
TCP
SMTPS
SMTP over TLS.
587
TCP
SMTP submission
Authenticated mail submission.
993
TCP
IMAPS
IMAP over TLS.
995
TCP
POP3S
POP3 over TLS.
Name, directory, and auth services
Port
Proto
Service
Notes
53
TCP/UDP
DNS
Zone transfer (axfr), reverse lookups.
88
TCP
Kerberos
AS-REP roast, TGT requests.
389
TCP/UDP
LDAP
Anonymous bind, AD objects.
464
TCP
Kerberos kpasswd
Password change service.
636
TCP
LDAPS
LDAP over TLS.
749
TCP
Kerberos admin
kadmin.
3268
TCP
LDAP Global Catalog
Forest-wide AD queries.
3269
TCP
LDAP GC over TLS
TLS global catalog.
9389
TCP
AD Web Services
ADWS, PowerShell AD module.
Databases
Port
Proto
Service
Notes
1433
TCP
MSSQL
xp_cmdshell, mssqlclient.py.
1434
UDP
MSSQL Browser
Instance discovery.
1521
TCP
Oracle TNS
SID brute, odat.
1830
TCP
Oracle (alt)
Secondary listener.
3306
TCP
MySQL / MariaDB
Weak creds, INTO OUTFILE.
5432
TCP
PostgreSQL
COPY ... PROGRAM for RCE.
5984
TCP
CouchDB
REST API, unauth data.
6379
TCP
Redis
No auth by default, key write to RCE.
7474 / 7687
TCP
Neo4j
HTTP browser and Bolt.
9042
TCP
Cassandra
CQL native transport.
11211
TCP/UDP
Memcached
Unauth data dump, amplification.
27017 / 27018
TCP
MongoDB
Unauth access on old configs.
SNMP and network management
Port
Proto
Service
Notes
161
UDP
SNMP
snmpwalk with public. Leaks users, processes, ARP.
162
UDP
SNMP trap
Trap receiver.
199
TCP
SMUX
SNMP multiplexer.
623
UDP
IPMI / BMC
Hash dump (ipmi-dumphashes).
2000
TCP
Cisco SCCP
VoIP signalling.
4786
TCP
Cisco Smart Install
Config theft, RCE.
5060 / 5061
TCP/UDP
SIP
VoIP, user enumeration.
Messaging, orchestration, and misc
Port
Proto
Service
Notes
79
TCP
Finger
User enumeration on old Unix.
113
TCP
ident
Returns service owner.
123
UDP
NTP
ntpq, monlist amplification.
179
TCP
BGP
Routing, rare on HTB-like boxes.
500
UDP
IKE / IPsec
ike-scan, VPN fingerprint.
502
TCP
Modbus
ICS/SCADA.
515
TCP
LPD
Printing service.
631
TCP
IPP / CUPS
Printer admin.
1099
TCP
Java RMI
Deserialization RCE.
1723
TCP
PPTP
VPN, hash capture.
1883
TCP
MQTT
IoT messaging, often unauth.
2181
TCP
ZooKeeper
Config leak, envi command.
2375 / 2376
TCP
Docker API
Unauth 2375 = host RCE.
3632
TCP
distcc
Command execution (CVE-2004-2687).
4369
TCP
EPMD (Erlang)
Cookie auth, RabbitMQ pairing.
5222
TCP
XMPP
Chat, user enumeration.
5353
UDP
mDNS
Local service discovery.
5355
UDP
LLMNR
Poison for hash capture (responder).
5671 / 5672
TCP
AMQP / RabbitMQ
Message broker, default creds.
6443
TCP
Kubernetes API
Cluster control, token abuse.
8140
TCP
Puppet
Config management.
8161
TCP
ActiveMQ
Web console, CVE-2016-3088.
9092
TCP
Kafka
Broker, topic access.
9100
TCP
JetDirect
Raw printing, PJL abuse.
15672
TCP
RabbitMQ mgmt
Web console, guest:guest.
44818
TCP/UDP
EtherNet/IP
ICS/SCADA.
Common backdoor and shell ports
Ports that often mean an attacker already touched the box, or a listener you set.
Port
Meaning
1080
SOCKS proxy, sometimes a pivot.
1337
Common custom backdoor.
4444
Metasploit default handler.
6666 / 6667
IRC, historic botnet C2.
12345
NetBus.
31337
Back Orifice, “elite” backdoor.
Fast lookups
Nmap prints the service guess from /etc/services. Read the real name of a numeric port:
grep -w6379/etc/services
Search a service by name to find its default port:
grep -iwredis/etc/services
Do not trust the default map. Run -sV and read the banner. A service on a non-standard port is common on HTB-like boxes and is exactly what a quick scan misses.