Skip to main content
AD Academy

Active Directory ports

Port → protocol → why → risk. What admins google their whole career.

PortProtoServiceWhyRisk
53TCP/UDPDNSFinding DCs via SRV recordsDNS spoofing, malicious ADIDNS records
88TCP/UDPKerberosAuthentication and tickets (TGT/TGS)Kerberoasting, AS-REP Roasting, Golden Ticket
135TCPRPC Endpoint MapperPoints to RPC services (replication, admin)Lateral movement, DCSync, PetitPotam
139 / 445TCPSMBSYSVOL, NETLOGON, shares, GPONTLM Relay, Pass-the-Hash, worms
389TCP/UDPLDAPReading and writing directory objectsCleartext Simple Bind, LDAP relay
636TCPLDAPSLDAP over TLSExpired certificate breaks services
3268 / 3269TCPGlobal CatalogForest-wide search (3269 = TLS)Forest-wide recon by attackers (BloodHound)
464TCP/UDPKerberos kpasswdPassword changePassword guessing without lockout
123UDPNTPTime sync — Kerberos allows 5 min skewWrong time = nobody can log in
49152–65535TCPRPC dynamicDC replication and RPC servicesWide firewall range — restrict it
5985 / 5986TCPWinRMPowerShell remotingLateral movement with admin creds
3389TCPRDPRemote desktopBrute force, creds left in memory