345
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No confirmed modern software implements 'pawserv' and the port shows no significant real-world uptake, so a legitimate reason for it to be open — internally or externally — is unestablished; an open instance is best treated as an anomaly to investigate.
- // analyst note
- treat an open port 345 as anomalous given no confirmed legitimate modern use.
- // if you see it open
- No CVE or malware association is documented for this port. It is dual-registered (TCP/UDP) with blank Assignee and Reference fields in the IANA registry, and shows no confirmed modern software footprint or significant real-world uptake (absent from Wikipedia's list of ports with notable usage). An open port 345 has no established legitimate purpose and should be treated as an anomaly worth investigating rather than routine service traffic.
About port 345.
Port 345/tcp is IANA-registered for pawserv, described as "Perf Analysis Workbench"; no confirmed modern software implements this service, so it has no legitimate reason to be internet-facing, and an open instance should be treated as an anomaly to investigate rather than routine service traffic.
The IANA registry lists both 345/tcp and 345/udp as dual-registered under the same pawserv name, with the Assignee and Reference columns blank — no individual or organization is recorded as owner, and no RFC or specification is cited. This blank-reference pattern is common among early, sparsely documented registry entries and does not by itself indicate a defect.
No publicly documented protocol specification, vendor implementation, or widely reported software footprint for "Perf Analysis Workbench" turned up in this research pass. The port is absent from Wikipedia's list of ports with significant real-world uptake, consistent with negligible adoption, and no CVE or malware campaign has been tied to port 345.
As of 2026-07-25, SANS Internet Storm Center reports port 345 at threat level "green" (low concern), with only light, generic background internet scanning — not evidence of a live exploit or a campaign targeting this port specifically. This is a dated, live snapshot rather than a fixed characteristic of the port.
- IANA assignment
pawserv— "Perf Analysis Workbench"; reference (blank); assignee (blank); dual-registered 345/tcp + 345/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-668- Range class
- well-known (0–1023) [Confirmed] — IANA registry port-number range
- Prevalence/scanning activity
- SANS ISC reports threat level "green" (low concern) as of 2026-07-25, with light/low-volume generic background scanning, not indicative of an active exploit or campaign [Likely, dated snapshot] — https://isc.sans.edu/port.html?port=345
- Related ports
- neighboring registered-but-rarely-seen entries (344/tcp, 346/tcp); contrast against actively used well-known ports
Primary use
registered for "Perf Analysis Workbench" per IANA; no publicly documented protocol spec or widely known software implementation found in this research pass
Other/unofficial uses
none found in this research pass [Unknown]
Security implications
no CVE or malware association found; port absent from Wikipedia's list of ports with significant real-world uptake
Typically seen on
no confirmed hosts or software; an open port 345 would be atypical and worth investigating [Unknown]
- Analyst note
- treat an open port 345 as anomalous given no confirmed legitimate modern use.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| pawserv | UDP | Perf Analysis Workbench | 0.04% |
| pawserv | TCP | Perf Analysis Workbench | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.