Method
The check opens a TCP connection and closes it, 25 ports at a time with a 3-second timeout. On
ports whose protocol greets first (SSH, FTP, SMTP, POP3, IMAP, MySQL, VNC), the greeting the server
sends unprompted is read to identify the product and version; the scanner sends nothing. On open
web and admin ports, up to 6 ordinary GET / requests do the same. That identification
feeds vulnerability matching.
When every address a host resolves to belongs to a shared CDN edge (Cloudflare, CloudFront,
Fastly, Akamai and similar), only the web ports 80, 443, 8080, 8443
are checked: the other ports on a shared edge answer for the provider, not for you. Ports are only
compared between scans that both tried them, so a change to the list, or skipping ports on a CDN
edge, never reads as a port opening or closing.
How severity is set
Severity reflects what reachability alone implies. Anything that should only ever be reached
from a private network (databases, remote desktop, file shares, orchestration APIs, industrial
protocols) is high; admin panels and brokers that are sometimes deliberately public are
medium; services that are normal to expose but worth an inventory line are low
or info. Findings use the ID fingerprint.open-port-<port>. Adjust to your
context through triage: an SSH port you expose deliberately can be accepted with a review date.
Every port checked
Web
| Port | Service | Severity |
|---|---|---|
80 | HTTP | info |
443 | HTTPS | info |
8080 | HTTP-alt | low |
8443 | HTTPS-alt | low |
8000 | HTTP dev server | low |
8008 | HTTP-alt | low |
8081 | HTTP-alt | low |
8888 | HTTP-alt / Jupyter | medium |
3000 | Node / Grafana dev | low |
4200 | Angular dev server | medium |
5173 | Vite dev server | medium |
9000 | HTTP-alt / Portainer / PHP-FPM | medium |
File transfer and sharing
| Port | Service | Severity |
|---|---|---|
21 | FTP | medium |
990 | FTPS | low |
139 | NetBIOS | high |
445 | SMB | high |
2049 | NFS | high |
873 | rsync | high |
548 | AFP | medium |
3690 | Subversion | medium |
9418 | Git daemon | medium |
Remote access and administration
| Port | Service | Severity |
|---|---|---|
22 | SSH | low |
2222 | SSH-alt | low |
23 | Telnet | high |
512 | rexec | high |
513 | rlogin | high |
514 | rsh | high |
3389 | RDP | high |
5900 | VNC | high |
5901 | VNC | high |
5985 | WinRM | high |
5986 | WinRM over TLS | medium |
6000 | X11 | high |
135 | MS RPC | high |
10000 | Webmin | medium |
2082 | cPanel | medium |
2083 | cPanel (TLS) | medium |
2086 | WHM | medium |
2087 | WHM (TLS) | medium |
8291 | MikroTik Winbox | high |
8728 | MikroTik API | high |
9090 | Cockpit / Prometheus | medium |
9443 | Portainer / admin (TLS) | medium |
4848 | GlassFish admin | medium |
9990 | WildFly admin | medium |
Directory and identity
| Port | Service | Severity |
|---|---|---|
88 | Kerberos | high |
389 | LDAP | high |
636 | LDAPS | medium |
3268 | AD Global Catalog | high |
| Port | Service | Severity |
|---|---|---|
25 | SMTP | info |
465 | SMTPS | info |
587 | SMTP submission | info |
110 | POP3 | low |
995 | POP3S | info |
143 | IMAP | low |
993 | IMAPS | info |
Databases and caches
| Port | Service | Severity |
|---|---|---|
1433 | Microsoft SQL Server | high |
1521 | Oracle DB | high |
3306 | MySQL | high |
5432 | PostgreSQL | high |
6379 | Redis | high |
11211 | Memcached | high |
27017 | MongoDB | high |
27018 | MongoDB shard | high |
9200 | Elasticsearch | high |
9300 | Elasticsearch transport | high |
5601 | Kibana | medium |
5984 | CouchDB | high |
9042 | Cassandra | high |
7474 | Neo4j browser | high |
7687 | Neo4j Bolt | high |
8086 | InfluxDB | high |
8123 | ClickHouse HTTP | high |
8983 | Apache Solr | high |
28015 | RethinkDB | high |
50000 | IBM Db2 | high |
3050 | Firebird | high |
2181 | ZooKeeper | high |
9870 | Hadoop NameNode UI | high |
Message queues and streaming
| Port | Service | Severity |
|---|---|---|
5672 | AMQP (RabbitMQ) | medium |
15672 | RabbitMQ management | medium |
1883 | MQTT (cleartext) | high |
8883 | MQTT over TLS | medium |
9092 | Kafka | high |
4222 | NATS | medium |
61616 | ActiveMQ OpenWire | high |
8161 | ActiveMQ console | medium |
Containers, orchestration, service mesh, config management
| Port | Service | Severity |
|---|---|---|
2375 | Docker API (no TLS) | high |
2376 | Docker API (TLS) | medium |
6443 | Kubernetes API | medium |
10250 | Kubelet API | high |
10255 | Kubelet read-only | high |
2379 | etcd | high |
8500 | Consul | high |
4646 | Nomad | high |
8200 | Vault | medium |
5000 | Docker registry / dev server | medium |
4505 | SaltStack publisher | high |
4506 | SaltStack request server | high |
8140 | Puppet server | medium |
Java and app-server internals
| Port | Service | Severity |
|---|---|---|
8009 | AJP (Tomcat) | high |
1099 | Java RMI | high |
7001 | WebLogic | high |
4040 | Spark UI | medium |
Monitoring agents
| Port | Service | Severity |
|---|---|---|
9100 | Node exporter / JetDirect | medium |
10050 | Zabbix agent | medium |
5666 | Nagios NRPE | medium |
VPN and proxies
| Port | Service | Severity |
|---|---|---|
1723 | PPTP VPN | medium |
1194 | OpenVPN (TCP) | info |
10443 | SSL-VPN portal | info |
4443 | HTTPS-alt / VPN portal | low |
3128 | Squid proxy | medium |
1080 | SOCKS proxy | high |
Industrial control and building automation
| Port | Service | Severity |
|---|---|---|
502 | Modbus | high |
102 | Siemens S7 | high |
20000 | DNP3 | high |
44818 | EtherNet/IP | high |
2404 | IEC 60870-5-104 | high |
1911 | Niagara Fox | high |
Telephony, printing, misc
| Port | Service | Severity |
|---|---|---|
5060 | SIP | medium |
631 | IPP printing | medium |
6667 | IRC | medium |
79 | Finger | medium |
Change detection
Ports opening and closing between scans appear in the change feed as port.opened and
port.closed. A high-severity port that starts answering is a critical change and is sent
immediately to your alert channels rather than waiting for the digest.
Extra TLS ports
Separately from this check, you can list up to 10 extra ports per domain for full certificate monitoring (for example a mail server or an admin console). See Certificates.