Ports & Services

🚧

Premium feature

Ports and Services data is only available to VirusTotal Enterprise users. Vulnerability data is only returned to users whose subscription includes vulnerability intelligence.

This section covers the open ports, services and technologies observed on IP addresses by Google's internet scanning (Internet Scanning): which ports are open on an IP address, the service and technology answering on each one, and how that has changed over time.

  • Port Info: current state and open/closed history of one {entity}:{port} pair.
  • Port Analysis: the record of a single scan of that port (banner, service, TLS, OS/device fingerprint, script output).
  • Scanning technologies: the technologies and versions detected across all the ports of an IP address, with the vulnerabilities that affect them.
  • The port_info attribute of the IP address object summarises every port observed on the IP.

Coverage and freshness

  • What is scanned: the public IPv4 address space, on a set of key ports. These include common service ports (for example FTP 21, SSH 22/2222, Telnet 23, SMTP 25, DNS 53, HTTP 80, NTP 123, LDAP 389, HTTPS 443, SMB 445, MySQL 3306, RDP 3389, PostgreSQL 5432, Redis 6379 and MongoDB 27017) and default ports of well-known malware and attack frameworks (for example AsyncRAT, Remcos, QuasarRAT, njRAT, Cobalt Strike and Metasploit). Coverage keeps growing.
  • How often: ports are scanned and updated daily. A port that stops answering moves to recently closed and then closed, and the date it was last seen open is kept (last_seen_open).
  • What is recorded per scan: port and host state, transport, TLS, banner, identified service and product/version (CPE), OS and device fingerprint, hostname, protocol details such as HTTP headers, and the output of detection scripts. Open ports are recorded even when no service could be identified.