H3AD-REF / REFERENCES / PROTOCOL & PORT REFERENCE
Every Port Tells
A Story, If You Know It.
The ports every SOC alert eventually points back to, in one table. What each service is for, and why it shows up in an incident. Static lookup data, no traffic capture, no packet inspection, just the reference you keep open in a second tab during triage. For the header bytes those ports sit inside, see the Packet Structure Reference.
Quick Reference
Fifteen ports, the protocol behind each one, and the reason it matters when it shows up in a log line instead of a diagram.
| Port | Protocol | Service | SOC Relevance |
|---|---|---|---|
| 20/21 | FTP | File transfer | Cleartext credentials |
| 22 | SSH | Secure shell | Brute-force target |
| 23 | Telnet | Remote terminal | Cleartext, legacy/IoT risk |
| 25 | SMTP | Mail transfer | Spam relay abuse |
| 53 | DNS | Name resolution | Tunneling/exfil channel |
| 80 | HTTP | Web | Cleartext web traffic |
| 88 | Kerberos | AD authentication | Kerberoasting/Golden Ticket target |
| 135 | RPC | Windows RPC endpoint mapper | Lateral movement |
| 139/445 | SMB | File sharing | Lateral movement, EternalBlue-class exploits |
| 389/636 | LDAP/LDAPS | Directory services | AD enumeration |
| 443 | HTTPS | Encrypted web | C2 blending with normal traffic |
| 464 | kpasswd | Kerberos password change | AD password change abuse |
| 3389 | RDP | Remote desktop | Lateral movement, brute-force target |
| 5985/5986 | WinRM | Windows remote management | Lateral movement (PSRemoting) |
| 8080/8443 | Alt HTTP(S) | Proxy/alt web | Common C2/proxy port |
Ports That Usually Mean Lateral Movement or C2
A handful of ports carry most of the weight once an intrusion starts moving. Knowing which ones, and what "unusual" looks like on them, is most of the triage call.
SMB
445 on an Unusual Host Pair
The default lateral movement port on any Windows network
SMB traffic between two workstations, or from a workstation to a host it has never talked to, is worth a second look. Servers and file shares talk 445 all day; a laptop reaching out to another laptop on 445 usually does not.
RDP
3389 Hopping Between Hosts
Remote desktop sessions that skip the jump box
A single RDP session from an admin workstation to a server is routine. A chain of RDP sessions moving host to host, especially outside the hours an admin normally works, matches how an intruder pivots once one machine is theirs.
WINRM
5985 Powering PSRemoting
The quiet cousin of RDP, easy to miss in a busy log
WinRM traffic on 5985 is how PowerShell Remoting reaches a target, and it rarely gets the same scrutiny RDP does. A source host issuing PSRemoting sessions to several other hosts in a short window is a lateral movement pattern, not routine admin work.
EPHEMERAL
High-Volume Traffic on Ephemeral Ports
Above 1024, and still worth a look
Ports above 1024 are normally just the client side of an outbound connection, assigned at random and gone in seconds. Sustained, high-volume traffic sitting on one of them for a long session is the general tell for a C2 channel or a custom tool that never bothered to bind a well-known port.