Active Directory ports
Port → protocol → why → risk. What admins google their whole career.
| Port | Proto | Service | Why | Risk |
|---|---|---|---|---|
| 53 | TCP/UDP | DNS | Finding DCs via SRV records | DNS spoofing, malicious ADIDNS records |
| 88 | TCP/UDP | Kerberos | Authentication and tickets (TGT/TGS) | Kerberoasting, AS-REP Roasting, Golden Ticket |
| 135 | TCP | RPC Endpoint Mapper | Points to RPC services (replication, admin) | Lateral movement, DCSync, PetitPotam |
| 139 / 445 | TCP | SMB | SYSVOL, NETLOGON, shares, GPO | NTLM Relay, Pass-the-Hash, worms |
| 389 | TCP/UDP | LDAP | Reading and writing directory objects | Cleartext Simple Bind, LDAP relay |
| 636 | TCP | LDAPS | LDAP over TLS | Expired certificate breaks services |
| 3268 / 3269 | TCP | Global Catalog | Forest-wide search (3269 = TLS) | Forest-wide recon by attackers (BloodHound) |
| 464 | TCP/UDP | Kerberos kpasswd | Password change | Password guessing without lockout |
| 123 | UDP | NTP | Time sync — Kerberos allows 5 min skew | Wrong time = nobody can log in |
| 49152–65535 | TCP | RPC dynamic | DC replication and RPC services | Wide firewall range — restrict it |
| 5985 / 5986 | TCP | WinRM | PowerShell remoting | Lateral movement with admin creds |
| 3389 | TCP | RDP | Remote desktop | Brute force, creds left in memory |