Networking · Concept · 8 min read

Port 4444, and Why an Abandoned Port Makes a Clean Signal

A registered port with nothing on it is the kind of number a tool adopts as a default. It is also the kind of number that makes an alert almost binary, which is rare and cheap.

Written by Marko Ristic, Editor Updated Sep 17, 2026
2Separate IANA registrations on this one port, and both are dead
0Of them describe software a business is likely to be running
1023The number a listener has to clear to bind without privilege
outThe direction worth catching, since the compromised host connects out
Short answer

Port 4444 is unusual among the ports people ask about, because nothing you run is likely to be listening on it. The IANA registry carries two separate entries for it, krb524 and nv-video, and its own note records that one of them took the port without an assignment.

Neither name belongs to software in common use today, which leaves the port effectively abandoned. That is exactly the kind of number a tool picks as a default listener, and it is why searching it returns security results.

The practical consequence is the useful part: on a port carrying a real service you have to judge whether traffic is legitimate, and on 4444 there is usually no legitimate baseline to judge against.

  • IANA lists two services on 4444, krb524 and nv-video, TCP and UDP
  • The registry note says one used the port without an assignment
  • Neither is software you are likely to be running
  • It is a common default listener port in offensive tooling
  • The direction that matters is outbound, not inbound
On this page

The registryWhat the registry actually says

Most ports have one owner. This one has two, and the registry says so plainly.

The IANA service names and port numbers registry lists krb524 on 4444 over both TCP and UDP, credited to B. Clifford Neuman, and nv-video, described as NV Video default, on the same port and both protocols, credited to Ron Frederick.

Attached to those entries is a note the registry does not usually need to make: krb524 assigned the port, and nv used it without an assignment.

That is a squatting dispute recorded in the official list. It is also ancient. Neither of those names describes software a business runs in 2026, so both registrations are historical rather than operational.

The result is a registered port with nothing on it. That is a different situation from an unregistered high port, and a very different situation from 445 or 389, where a real service is listening on every machine and the question is only whether this particular conversation is normal.

Why 4444Why an unclaimed port becomes a default

This is worth understanding because it explains the reputation rather than just reporting it.

Anything that needs to open a listener has to choose a number. The requirements are simple: it should be above 1023 so it does not need privileged access to bind, it should be memorable, and it should be unlikely to collide with something already running.

A port with two dead registrations and no live software satisfies all three, and 4444 is memorable in a way that 41983 is not.

So port 4444 became a convention. It is widely used as the default listener port in penetration testing and post-exploitation tooling, which is why searching the number returns security results rather than protocol documentation.

Metasploit is the best known case. In the framework's public source code, the reverse and bind TCP handlers both set the LPORT option to 4444 by default. A reverse shell or Meterpreter payload generated without changing anything therefore calls back to the attacker's handler on TCP 4444.

That convention is not a property of the port. Nothing about the 4444 port number is dangerous, and a tool configured to use 8080 instead is exactly as effective.

What the convention gives you is a detection opportunity, and it is a real one precisely because it is a default that many operators never change.

Known usersWhat is known to use TCP 4444

No common network service owns the port, but a short list of software picks it by default. Each row below was read at the source named in it.

SoftwareWhat it does on port 4444Source
MetasploitDefault LPORT for reverse and bind TCP handlers, where the shell connectsMetasploit Framework source code
Blaster worm, 2003After exploiting a Windows target, connected to TCP port 4444 on it and sent a tftp command to fetch msblast.exeMicrosoft's malware encyclopedia entry for Msblast.A
Selenium GridThe server listens for browser test requests on http://localhost:4444Selenium documentation
I2PThe local HTTP proxy that a browser points atThe I2P project's port list
Sophos FirewallThe web admin console, at https on port 4444 of the LAN addressSophos Firewall documentation

The pattern matters more than the list. Malware and attack tools use port 4444 because it is free, and so do developers and appliance vendors. Open firewall access to it only for a service you can name, and expect anything else found on TCP 4444 to need an explanation.

What it meansWhat traffic on 4444 usually means

Work through these in order, because the harmless explanation is genuinely common and checking it first saves an escalation.

Something you deployed chose it. Development servers, build tools, test harnesses and message brokers pick memorable high ports, and 4444 is a popular one. This is the most likely explanation on a developer workstation and it is not an incident.

A tool a colleague is running. Security testing that somebody scheduled, or a lab. Worth confirming before anything else, because the alternative explanation is expensive.

An outbound connection from a machine to somewhere unfamiliar. This is the shape worth caring about. A reverse listener is contacted outbound by the compromised host, so the interesting direction is a workstation opening a connection to an external address on 4444, not something knocking on your firewall.

Inbound scanning. Constant, meaningless, and equally true of every other port. An inbound probe that never connects is background noise.

The direction is the part people get backwards. Blocking inbound 4444 at the perimeter feels like the fix and addresses the least likely case. The connection you would actually want to catch is leaving.

The commandsFinding out what is actually listening

To check whether port 4444 is open on a machine, ask the machine rather than a port scanner. The port number is not the answer to anything. The process holding the socket is, and every platform will tell you in one command.

PlatformCommandWhat it gives back
Windowsnetstat -ano | findstr :4444The connection and a process ID
Windows, PowerShellGet-NetTCPConnection -LocalPort 4444The same, as objects rather than text
Linuxss -tulpn | grep :4444The process name and the user running it
macOSlsof -i :4444The process, the user and the far end

On Windows the first two give you a number rather than a name, so the second step is mapping that process ID to an executable and an account.

That mapping is the whole investigation: a build tool running as your developer is one story, and the same port held by something running as SYSTEM out of a temporary directory is another.

Two details make the difference between an answer and a false alarm. Check the local address, because a socket bound to 127.0.0.1 is reachable only from that machine and is almost always a development server.

And check whether the entry is listening or established, because a listener waiting for nothing is a much weaker signal than a live connection to an address outside your network. The same distinction applies to any port, and the commands that read a machine's network state are the same ones you would use for it.

In practiceWhat to do if you find it

Identify the listening process, not the port. Use the commands above to find which program holds the socket and which account it runs as. The port number tells you nothing; the process tells you everything.

Check the direction and the peer. Outbound to an unfamiliar external address is a different event from a local service bound to 127.0.0.1, which is not reachable from anywhere.

Do not rely on blocking the number. A default is a convenience, not a constraint. Anything using port 4444 can use another one, and a control that stops only the default stops only the operators who left it alone.

Treat egress as the control that matters. Restricting which machines may open arbitrary outbound connections is what actually limits this category, and it works regardless of the port chosen. That is the same argument as the one for segmentation and rule discipline rather than for a list of bad numbers.

Alert on it anyway. It costs nothing. A quiet port produces very few false positives, and a default that people forget to change is caught by exactly this kind of cheap rule.

How to block port 4444 on a host firewall

If you decide to block port 4444 anyway, block it in both directions, and remember that the outbound rule is the one that stops a reverse shell from reaching its handler.

PlatformCommandEffect
Windows, PowerShell as administratorNew-NetFirewallRule -DisplayName "Block TCP 4444 out" -Direction Outbound -Protocol TCP -RemotePort 4444 -Action BlockBlocks outbound connections to TCP 4444
Linux with ufwsudo ufw deny out 4444/tcpBlocks outbound connections to TCP 4444
Linux with ufwsudo ufw deny 4444/tcpBlocks inbound connections to TCP 4444

On a network firewall the same two rules apply at the edge. Often the better design is a default deny on outbound traffic with a short allow list, so an unexpected callback fails whichever port the malware or the tester picked.

PitfallsWhere people go wrong

Treating the number as the threat. The port is arbitrary. Blocking 4444 and stopping there addresses a default rather than a technique.

Blocking it inbound only. The connection that matters is usually outbound from an internal machine, so a perimeter rule facing the wrong way changes nothing.

Assuming it is always malicious. Plenty of development and test software binds to it. Check the process before escalating, because being wrong about this is expensive in trust.

Ignoring it because it is often benign. The opposite mistake. A port with almost no legitimate baseline is worth an alert precisely because the alert is cheap.

Looking it up in a service list and stopping. The registry entries are historical, and reading krb524 and concluding this is Kerberos will send you somewhere that has nothing to do with what you found.

WHY A QUIET PORT IS WORTH ALERTING ONBars show how much legitimate traffic is normally there. Illustrative, not measured.Port 443the weban alert here is noisePort 445Windows file sharingan alert here is statisticsPort 4444two dead registrationsan alert here is an answeralmost nothing legitimateThe detection value of a port runs opposite to how busy it is.Port 4444 is quiet because both of its registrations died decades ago.
On a busy port an alert is a statistics problem. On an abandoned one it is close to a binary answer, which is a rare and cheap thing in detection.

ComparisonPort 4444, port 445 and port 443, side by side

CriterionPort 4444Port 445Port 443
Something is normally listeningNoYes, on every Windows hostYes, everywhere
Legitimate traffic to compare againstAlmost noneConstantConstant
Blocking it breaks thingsRarelyYes, file sharing stopsYes, the web stops
Alerting on it is noisyNoYes, veryYes, extremely
What its presence tells youWorth investigatingNothing on its ownNothing on its own

The fourth row is the reason this page exists. On a busy port an alert is a statistics problem. On an abandoned one it is close to a binary answer, and that is a rare and cheap thing in detection.

FAQFrequently asked questions

What is port 4444 used for?

Formally, two historical services: IANA lists krb524 and nv-video on port 4444, both TCP and UDP. In practice neither is in use, and it is best known as a default listener in penetration testing tools.

Is port 4444 dangerous?

The number is not. Nothing about it is special, and any tool that defaults to it can use a different port. What makes it worth watching is that almost nothing legitimate uses it, so traffic there stands out.

Why do two services share port 4444 in the registry?

IANA records both krb524 and nv-video on it, with a note saying that krb524 was assigned the port and nv used it without an assignment. It is a squatting dispute preserved in the official list.

Should I block port 4444?

Blocking it costs almost nothing, so there is no reason not to. Do not treat it as a control, because a default is easily changed. Restricting outbound connections generally is the thing that actually helps.

Is traffic on port 4444 always an attack?

No. Development servers, test tools and message brokers pick memorable high ports and this is a popular one. Identify the process before deciding.

Which direction should I worry about?

Outbound. A reverse listener is contacted by the compromised machine, so an internal host opening a connection to an unfamiliar external address on 4444 is the interesting event. Inbound probing is background noise.

How do I find what is using port 4444?

On the host, list listening sockets and map the port to a process and the account running it. The process identity answers the question; the port number does not.

Is port 4444 TCP or UDP?

Both are registered. The uses people encounter are almost always TCP, because a listener waiting for a shell wants a connection.

Why does searching this port return security results?

Because its only widely known role is as a default in offensive tooling. There is no live protocol documentation to return instead, which is unusual for a registered port.

What is krb524?

One of the two names IANA records on this port, from the era when Kerberos version 4 still mattered. It is not something you are running, and finding traffic on 4444 is not a reason to investigate Kerberos.

Does changing the port stop the technique?

No, and neither does blocking it. Port choice is a configuration detail. The controls that matter are which machines may open outbound connections and what is allowed to run on them.

Why is there talk of a port 4444 exploit?

Port 4444 is the default listener for Metasploit's reverse shell payloads, so an unexpected connection on it is a classic sign of compromise. The phrase port 4444 exploit is loose wording: the port is where the attacker's shell connects after some other weakness was exploited, not the weakness itself.

Read next · Ports What Is a Port Number? Why a listener has to clear 1023 to bind without privilege, and what the registered range actually promises. Open this next12 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.