Port 4444 is unusual among the ports people ask about, because nothing you run is likely to be listening on it. The IANA registry carries two separate entries for it, krb524 and nv-video, and its own note records that one of them took the port without an assignment.
Neither name belongs to software in common use today, which leaves the port effectively abandoned. That is exactly the kind of number a tool picks as a default listener, and it is why searching it returns security results.
The practical consequence is the useful part: on a port carrying a real service you have to judge whether traffic is legitimate, and on 4444 there is usually no legitimate baseline to judge against.
- IANA lists two services on 4444, krb524 and nv-video, TCP and UDP
- The registry note says one used the port without an assignment
- Neither is software you are likely to be running
- It is a common default listener port in offensive tooling
- The direction that matters is outbound, not inbound
On this page
The registryWhat the registry actually says
Most ports have one owner. This one has two, and the registry says so plainly.
The IANA service names and port numbers registry lists krb524 on 4444 over both TCP and UDP, credited to B. Clifford Neuman, and nv-video, described as NV Video default, on the same port and both protocols, credited to Ron Frederick.
Attached to those entries is a note the registry does not usually need to make: krb524 assigned the port, and nv used it without an assignment.
That is a squatting dispute recorded in the official list. It is also ancient. Neither of those names describes software a business runs in 2026, so both registrations are historical rather than operational.
The result is a registered port with nothing on it. That is a different situation from an unregistered high port, and a very different situation from 445 or 389, where a real service is listening on every machine and the question is only whether this particular conversation is normal.
Why 4444Why an unclaimed port becomes a default
This is worth understanding because it explains the reputation rather than just reporting it.
Anything that needs to open a listener has to choose a number. The requirements are simple: it should be above 1023 so it does not need privileged access to bind, it should be memorable, and it should be unlikely to collide with something already running.
A port with two dead registrations and no live software satisfies all three, and 4444 is memorable in a way that 41983 is not.
So port 4444 became a convention. It is widely used as the default listener port in penetration testing and post-exploitation tooling, which is why searching the number returns security results rather than protocol documentation.
Metasploit is the best known case. In the framework's public source code, the reverse and bind TCP handlers both set the LPORT option to 4444 by default. A reverse shell or Meterpreter payload generated without changing anything therefore calls back to the attacker's handler on TCP 4444.
That convention is not a property of the port. Nothing about the 4444 port number is dangerous, and a tool configured to use 8080 instead is exactly as effective.
What the convention gives you is a detection opportunity, and it is a real one precisely because it is a default that many operators never change.
Known usersWhat is known to use TCP 4444
No common network service owns the port, but a short list of software picks it by default. Each row below was read at the source named in it.
| Software | What it does on port 4444 | Source |
|---|---|---|
| Metasploit | Default LPORT for reverse and bind TCP handlers, where the shell connects | Metasploit Framework source code |
| Blaster worm, 2003 | After exploiting a Windows target, connected to TCP port 4444 on it and sent a tftp command to fetch msblast.exe | Microsoft's malware encyclopedia entry for Msblast.A |
| Selenium Grid | The server listens for browser test requests on http://localhost:4444 | Selenium documentation |
| I2P | The local HTTP proxy that a browser points at | The I2P project's port list |
| Sophos Firewall | The web admin console, at https on port 4444 of the LAN address | Sophos Firewall documentation |
The pattern matters more than the list. Malware and attack tools use port 4444 because it is free, and so do developers and appliance vendors. Open firewall access to it only for a service you can name, and expect anything else found on TCP 4444 to need an explanation.
What it meansWhat traffic on 4444 usually means
Work through these in order, because the harmless explanation is genuinely common and checking it first saves an escalation.
Something you deployed chose it. Development servers, build tools, test harnesses and message brokers pick memorable high ports, and 4444 is a popular one. This is the most likely explanation on a developer workstation and it is not an incident.
A tool a colleague is running. Security testing that somebody scheduled, or a lab. Worth confirming before anything else, because the alternative explanation is expensive.
An outbound connection from a machine to somewhere unfamiliar. This is the shape worth caring about. A reverse listener is contacted outbound by the compromised host, so the interesting direction is a workstation opening a connection to an external address on 4444, not something knocking on your firewall.
Inbound scanning. Constant, meaningless, and equally true of every other port. An inbound probe that never connects is background noise.
The direction is the part people get backwards. Blocking inbound 4444 at the perimeter feels like the fix and addresses the least likely case. The connection you would actually want to catch is leaving.
The commandsFinding out what is actually listening
To check whether port 4444 is open on a machine, ask the machine rather than a port scanner. The port number is not the answer to anything. The process holding the socket is, and every platform will tell you in one command.
| Platform | Command | What it gives back |
|---|---|---|
| Windows | netstat -ano | findstr :4444 | The connection and a process ID |
| Windows, PowerShell | Get-NetTCPConnection -LocalPort 4444 | The same, as objects rather than text |
| Linux | ss -tulpn | grep :4444 | The process name and the user running it |
| macOS | lsof -i :4444 | The process, the user and the far end |
On Windows the first two give you a number rather than a name, so the second step is mapping that process ID to an executable and an account.
That mapping is the whole investigation: a build tool running as your developer is one story, and the same port held by something running as SYSTEM out of a temporary directory is another.
Two details make the difference between an answer and a false alarm. Check the local address, because a socket bound to 127.0.0.1 is reachable only from that machine and is almost always a development server.
And check whether the entry is listening or established, because a listener waiting for nothing is a much weaker signal than a live connection to an address outside your network. The same distinction applies to any port, and the commands that read a machine's network state are the same ones you would use for it.
In practiceWhat to do if you find it
Identify the listening process, not the port. Use the commands above to find which program holds the socket and which account it runs as. The port number tells you nothing; the process tells you everything.
Check the direction and the peer. Outbound to an unfamiliar external address is a different event from a local service bound to 127.0.0.1, which is not reachable from anywhere.
Do not rely on blocking the number. A default is a convenience, not a constraint. Anything using port 4444 can use another one, and a control that stops only the default stops only the operators who left it alone.
Treat egress as the control that matters. Restricting which machines may open arbitrary outbound connections is what actually limits this category, and it works regardless of the port chosen. That is the same argument as the one for segmentation and rule discipline rather than for a list of bad numbers.
Alert on it anyway. It costs nothing. A quiet port produces very few false positives, and a default that people forget to change is caught by exactly this kind of cheap rule.
How to block port 4444 on a host firewall
If you decide to block port 4444 anyway, block it in both directions, and remember that the outbound rule is the one that stops a reverse shell from reaching its handler.
| Platform | Command | Effect |
|---|---|---|
| Windows, PowerShell as administrator | New-NetFirewallRule -DisplayName "Block TCP 4444 out" -Direction Outbound -Protocol TCP -RemotePort 4444 -Action Block | Blocks outbound connections to TCP 4444 |
| Linux with ufw | sudo ufw deny out 4444/tcp | Blocks outbound connections to TCP 4444 |
| Linux with ufw | sudo ufw deny 4444/tcp | Blocks inbound connections to TCP 4444 |
On a network firewall the same two rules apply at the edge. Often the better design is a default deny on outbound traffic with a short allow list, so an unexpected callback fails whichever port the malware or the tester picked.
PitfallsWhere people go wrong
Treating the number as the threat. The port is arbitrary. Blocking 4444 and stopping there addresses a default rather than a technique.
Blocking it inbound only. The connection that matters is usually outbound from an internal machine, so a perimeter rule facing the wrong way changes nothing.
Assuming it is always malicious. Plenty of development and test software binds to it. Check the process before escalating, because being wrong about this is expensive in trust.
Ignoring it because it is often benign. The opposite mistake. A port with almost no legitimate baseline is worth an alert precisely because the alert is cheap.
Looking it up in a service list and stopping. The registry entries are historical, and reading krb524 and concluding this is Kerberos will send you somewhere that has nothing to do with what you found.
ComparisonPort 4444, port 445 and port 443, side by side
| Criterion | Port 4444 | Port 445 | Port 443 |
|---|---|---|---|
| Something is normally listening | No | Yes, on every Windows host | Yes, everywhere |
| Legitimate traffic to compare against | Almost none | Constant | Constant |
| Blocking it breaks things | Rarely | Yes, file sharing stops | Yes, the web stops |
| Alerting on it is noisy | No | Yes, very | Yes, extremely |
| What its presence tells you | Worth investigating | Nothing on its own | Nothing on its own |
The fourth row is the reason this page exists. On a busy port an alert is a statistics problem. On an abandoned one it is close to a binary answer, and that is a rare and cheap thing in detection.
FAQFrequently asked questions
What is port 4444 used for?
Formally, two historical services: IANA lists krb524 and nv-video on port 4444, both TCP and UDP. In practice neither is in use, and it is best known as a default listener in penetration testing tools.
Is port 4444 dangerous?
The number is not. Nothing about it is special, and any tool that defaults to it can use a different port. What makes it worth watching is that almost nothing legitimate uses it, so traffic there stands out.
Why do two services share port 4444 in the registry?
IANA records both krb524 and nv-video on it, with a note saying that krb524 was assigned the port and nv used it without an assignment. It is a squatting dispute preserved in the official list.
Should I block port 4444?
Blocking it costs almost nothing, so there is no reason not to. Do not treat it as a control, because a default is easily changed. Restricting outbound connections generally is the thing that actually helps.
Is traffic on port 4444 always an attack?
No. Development servers, test tools and message brokers pick memorable high ports and this is a popular one. Identify the process before deciding.
Which direction should I worry about?
Outbound. A reverse listener is contacted by the compromised machine, so an internal host opening a connection to an unfamiliar external address on 4444 is the interesting event. Inbound probing is background noise.
How do I find what is using port 4444?
On the host, list listening sockets and map the port to a process and the account running it. The process identity answers the question; the port number does not.
Is port 4444 TCP or UDP?
Both are registered. The uses people encounter are almost always TCP, because a listener waiting for a shell wants a connection.
Why does searching this port return security results?
Because its only widely known role is as a default in offensive tooling. There is no live protocol documentation to return instead, which is unusual for a registered port.
What is krb524?
One of the two names IANA records on this port, from the era when Kerberos version 4 still mattered. It is not something you are running, and finding traffic on 4444 is not a reason to investigate Kerberos.
Does changing the port stop the technique?
No, and neither does blocking it. Port choice is a configuration detail. The controls that matter are which machines may open outbound connections and what is allowed to run on them.
Why is there talk of a port 4444 exploit?
Port 4444 is the default listener for Metasploit's reverse shell payloads, so an unexpected connection on it is a classic sign of compromise. The phrase port 4444 exploit is loose wording: the port is where the attacker's shell connects after some other weakness was exploited, not the weakness itself.
Keep readingRelated concepts
Read next · Ports What Is a Port Number? Why a listener has to clear 1023 to bind without privilege, and what the registered range actually promises. Open this next12 min- Ports · 10 min SMB Port 445, and the One Rule That Matters About It The opposite case: a port with a real service on every Windows machine, where the same alert would be unreadable.
- Network security · 9 min The Implicit Deny, and Why the Rule You Just Added Did Nothing The egress control that actually limits this, since it works whatever port a tool is configured to use.