167
Summary
- // if you see it open
- No known CVEs, malware, or trojan-port associations identified. Negligible real-world exposure; an unexpected open port 167 would be anomalous and worth investigating rather than a normal service.
- // analyst note
- an open port 167 is statistically rare and undocumented — treat any responsive instance as anomalous and worth investigating rather than routine.
About port 167/tcp.
Port 167/tcp is registered with IANA under the bare service name namp, with the description field simply repeating "NAMP" — the registry does not spell out what the acronym stands for. The assignment is dual-registered: 167/udp carries the identical service name and description, with no protocol-specific distinction between the two rows. The assignee/contact listed in the registry is Marty Schoffstall (the registry text renders the surname as "Schoffstahl," though the correctly spelled "Schoffstall" is the RFC-documented co-author of early SNMP work such as RFC 1157 and RFC 1098 from the NYSERNet/Rensselaer era of the late 1980s — no document ties that SNMP work specifically to NAMP, so the connection is circumstantial). No RFC or other reference is cited for this assignment, and no registration or modification date is published, consistent with many other very-low-numbered legacy registrations from that period. Independent secondary port-list aggregator sites offer conflicting, uncited expansions of "NAMP" (e.g. "Network Administration Message Protocol"), so the acronym's meaning is treated as unverified rather than asserted. No current software, CVEs, or malware associations were found for this port, and nmap's empirical open-frequency data places it among the rarest ports tracked, indicating it is an effectively dormant, undocumented legacy reservation rather than an actively used or actively targeted service today.
- IANA assignment
namp— description "NAMP" (acronym not expanded in the registry); dual-registered 167/tcp + 167/udp, identical rows [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Range class
- well-known (0–1023)
- IANA reference (RFC)
- none published — left blank per no-fabrication rule [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- Registration/modification date
- Unknown — not published in the current IANA registry text, consistent with other undated 1980s-era entries [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- Prevalence
- nmap-services open-frequency for 167 (namp) ≈ 0.000395 — among the rarest tracked ports [Likely] — https://svn.nmap.org/nmap-exp/scriptsuggest/nmap-services
- Related ports
- none identified as a functional cluster
Primary use
no verifiable current use; legacy IANA reservation with no accompanying specification or known active implementation
Security implications
no known CVEs, malware, or trojan-port associations found; negligible real-world exposure
Typically seen on
no identified modern hosts/software; effectively unused
- Assignee/contact
- Marty Schoffstall (registry text shows "Schoffstahl"; RFC-documented spelling is "Schoffstall," co-author of RFC 1157/RFC 1098-era SNMP work) [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt, https://datatracker.ietf.org/doc/html/rfc1157
- Acronym expansion
- Unknown/unconfirmed — secondary aggregator sites give conflicting, uncited guesses; no primary source spells it out [Unknown]
- Analyst note
- an open port 167 is statistically rare and undocumented — treat any responsive instance as anomalous and worth investigating rather than routine.
About port 167/udp.
Port 167/udp is registered with IANA under the service name namp, described only as "NAMP" — an acronym IANA leaves unexpanded, with no RFC or reference field populated for either 167/udp or its dual-registered counterpart, 167/tcp; the two entries share the same service name, description, assignee, and contact in the current IANA Service Name and Transport Protocol Port Number Registry. The listed contact is Marty Schoffstahl, carried forward from the port's original appearance in RFC 1700 (1994) — the earliest confirmable record found — with no assignment or modification date published anywhere in the registry. No specification, RFC, or vendor document defines what NAMP actually does; several secondary port-lookup aggregator sites gloss it as "Network Administration Message Protocol," but none of these glosses trace back to a primary source, so the protocol's real function and any software that implements it remain unverified. Wikipedia's port-number list separately attributes port 167 to "Cisco IP SLA (Service Assurance Agent)" without citation; Cisco's own configuration guides place the IP SLA control protocol on UDP 1967 instead, so this looks like a transcription error rather than a genuine second use, and is not carried into this entry as a confirmed use case. SANS Internet Storm Center's live scanning data for port 167 (checked 2026-07-10) shows only low, single-digit hit counts consistent with routine internet background-noise scanning, with the overall ISC threat indicator green and no elevated or targeted signal. Given the absent specification and negligible legitimate footprint, an open port 167 in the wild is best treated as unusual and worth investigating rather than assumed benign.
- IANA assignment
namp— description "NAMP" (acronym unexpanded); reference field blank; assignee/contact [Marty_Schoffstahl]; dual-registered 167/tcp + 167/udp with identical name/description/assignee [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry lines 411–412; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=167- Range class
- well-known (0–1023) [Confirmed]
- Registration/modification date
- blank in the IANA registry; earliest confirmable appearance is RFC 1700 (1994) [Confirmed] — https://www.freesoft.org/CIE/RFC/1700/4.htm
- Prevalence
- nmap-services observed open-frequency 167/udp ≈ 0.000395 (very low — roughly 4 in 10,000 scanned hosts in the nmap-services sample); the dual-registered 167/tcp row carries a frequency of 0 — never observed open in that sample, so what little activity the port number shows sits on the UDP side[Confirmed] — nmap-services dataset
- Related ports
- 1967/udp — the port Cisco IP SLA / Service Assurance Agent actually uses, occasionally conflated with 167 via the uncited Wikipedia entry [Likely] — Cisco docs, Cisco community thread
Primary use / protocol definition
undocumented — no RFC or spec exists for NAMP; the IANA description field is just the acronym
Other/unofficial uses
third-party port-lookup aggregator sites gloss it as "Network Administration Message Protocol" for generic network monitoring/management, but this gloss does not trace to any primary source
Security implications / exposure
SANS ISC live port-167 activity (checked 2026-07-10) shows only low-volume, single-digit-hit generic scanning noise with a green threat indicator — no elevated or targeted interest; no CVEs or malware families were found associated with port 167 [Confirmed for scan data, Unknown for CVE/malware] — https://isc.sans.edu/data/port/167
Typically seen on
no current software was found that actually implements or listens on port 167 (namp); an open instance should be treated as anomalous [Unknown]
- Disputed claim
- Wikipedia lists port 167 as "Cisco IP SLA (Service Assurance Agent)" with no citation; Cisco's own docs place the IP SLA control protocol on UDP 1967, so this appears to be a transcription error and is not treated as a confirmed use of 167 [Unknown/likely-incorrect] — https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers; https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipsla/configuration/xe-16/sla-xe-16-book/sla-overview.html
- Analyst note
- an open port 167 has no documented legitimate protocol or widely deployed software behind it; investigate rather than assume benign, and note that any "Cisco IP SLA" attribution to this specific port is very likely a Wikipedia transcription error (the real port is 1967).
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| namp | UDP | — | 0.04% |
| namp | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.