H3AD-REF / REFERENCES / PROTOCOL & PORT REFERENCE

Every Port Tells
A Story, If You Know It.

The ports every SOC alert eventually points back to, in one table. What each service is for, and why it shows up in an incident. Static lookup data, no traffic capture, no packet inspection, just the reference you keep open in a second tab during triage. For the header bytes those ports sit inside, see the Packet Structure Reference.

Quick Reference

Fifteen ports, the protocol behind each one, and the reason it matters when it shows up in a log line instead of a diagram.

Port Protocol Service SOC Relevance
20/21 FTP File transfer Cleartext credentials
22 SSH Secure shell Brute-force target
23 Telnet Remote terminal Cleartext, legacy/IoT risk
25 SMTP Mail transfer Spam relay abuse
53 DNS Name resolution Tunneling/exfil channel
80 HTTP Web Cleartext web traffic
88 Kerberos AD authentication Kerberoasting/Golden Ticket target
135 RPC Windows RPC endpoint mapper Lateral movement
139/445 SMB File sharing Lateral movement, EternalBlue-class exploits
389/636 LDAP/LDAPS Directory services AD enumeration
443 HTTPS Encrypted web C2 blending with normal traffic
464 kpasswd Kerberos password change AD password change abuse
3389 RDP Remote desktop Lateral movement, brute-force target
5985/5986 WinRM Windows remote management Lateral movement (PSRemoting)
8080/8443 Alt HTTP(S) Proxy/alt web Common C2/proxy port

Ports That Usually Mean Lateral Movement or C2

A handful of ports carry most of the weight once an intrusion starts moving. Knowing which ones, and what "unusual" looks like on them, is most of the triage call.

SMB

445 on an Unusual Host Pair

The default lateral movement port on any Windows network
SMB traffic between two workstations, or from a workstation to a host it has never talked to, is worth a second look. Servers and file shares talk 445 all day; a laptop reaching out to another laptop on 445 usually does not.
RDP

3389 Hopping Between Hosts

Remote desktop sessions that skip the jump box
A single RDP session from an admin workstation to a server is routine. A chain of RDP sessions moving host to host, especially outside the hours an admin normally works, matches how an intruder pivots once one machine is theirs.
WINRM

5985 Powering PSRemoting

The quiet cousin of RDP, easy to miss in a busy log
WinRM traffic on 5985 is how PowerShell Remoting reaches a target, and it rarely gets the same scrutiny RDP does. A source host issuing PSRemoting sessions to several other hosts in a short window is a lateral movement pattern, not routine admin work.
EPHEMERAL

High-Volume Traffic on Ephemeral Ports

Above 1024, and still worth a look
Ports above 1024 are normally just the client side of an outbound connection, assigned at random and gone in seconds. Sustained, high-volume traffic sitting on one of them for a long session is the general tell for a C2 channel or a custom tool that never bothered to bind a well-known port.