359
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — Port 359 is IANA-reserved with no current service assignment and no documented legitimate application, so any traffic observed on it today should be treated as anomalous rather than expected.
- // analyst note
- given the reserved/de-assigned IANA status and absence of any documented legitimate service, a responsive 359/tcp host warrants investigation as anomalous traffic rather than a routine service.
- // if you see it open
- Port is IANA-reserved with no active service definition and no documented legitimate use today, so any traffic on it should be treated as anomalous. auditmypc.com's community database marks TCP port 359 as not associated with known virus/trojan activity, though this is a single, unverified community data point.
About port 359/tcp.
Port 359/tcp has no active, documented service today: IANA's registry lists both 359/tcp and 359/udp as Reserved, with the service-name, assignee, and reference columns blank and Description reading "Reserved".
Before that de-assignment, port 359 (both TCP and UDP) had long carried the informal legacy label "nsrmp" (Network Security Risk Management Protocol), registered by Eric Jacksch of Tenebris Technologies. Third-party mirrors of the old IANA port list and GRC's Port Authority page both preserve this label, but no RFC or formal specification was ever published for it, and no mainstream software is documented as implementing it. A related older label, "tenebris_nts" (Tenebris Network Trace Service), traces to the same registrant lineage rather than a competing service — community port databases (nmap-services, auditmypc.com) carry it against 359/tcp specifically.
IANA's current entry carries a Modification Date of 2023-11-16 (with Assignment Notes reading "De-Assigned on 2023-11-16"), which marks the registry's de-assignment/reservation event rather than an original allocation date — the Registration Date column itself is blank. No modern software or service was found to be commonly associated with port 359, so common applications and traffic context are left unfilled rather than guessed.
- IANA assignment
- Service Name, Assignee, Contact, Registration Date, and Reference all blank; Description "Reserved"; Modification Date 2023-11-16; Assignment Notes "De-Assigned on 2023-11-16." [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-704
- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- no nmap-services open-frequency figure captured in this research pass [Unknown]
- Related ports
- none registered — the IANA rows for this port carry no service name at all (359/tcp and 359/udp both read Description "Reserved", Assignment Notes "De-Assigned on 2023-11-16"), so there is no service name for any other row to share and no related port exists in the registry[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry 359/tcp and 359/udp (Reserved, blank Service Name)
Primary use
no current assignment; historically associated with the informal "nsrmp" (Network Security Risk Management Protocol, Eric Jacksch/Tenebris Technologies) label carried by third-party port-list mirrors and GRC's Port Authority page, with "tenebris_nts" (Tenebris Network Trace Service) as a related legacy label from the same registrant lineage per community port databases; no RFC or formal spec found for either
Other/unofficial uses
none credibly documented [Unknown]
Security implications
reserved/de-assigned with no expected legitimate use; auditmypc.com's community database marks it clean of known virus/trojan activity
Typically seen on
no known typical host type; unexpected or anomalous if observed [Unknown]
- Analyst note
- given the reserved/de-assigned IANA status and absence of any documented legitimate service, a responsive 359/tcp host warrants investigation as anomalous traffic rather than a routine service.
About port 359/udp.
Port 359/udp carries no officially assigned service today: IANA's current registry lists it as Reserved, with a blank Service Name, and notes it was de-assigned on 2023-11-16 — so it has no legitimate reason to be listening, let alone exposed to the public internet, and any responsive traffic on it is anomalous rather than expected.
Before that de-assignment, port 359 (both TCP and UDP) had long carried the informal legacy label "nsrmp" (Network Security Risk Management Protocol), registered by Eric Jacksch of Tenebris Technologies. Third-party mirrors of the old IANA port list and GRC's Port Authority page both preserve this label, but no RFC or formal specification was ever published for it, and no mainstream software is documented as implementing it. A related older label, "tenebris_nts" (Tenebris Network Trace Service), traces to the same registrant lineage rather than a competing service.
No credible, currently-active application or vendor product was found reported as generating traffic on 359/udp, and no malware or trojan association is confirmed for this port — no named family, dated incident, or CVE turned up in any source checked.
- IANA assignment
- no current Service Name (blank); Description "Reserved"; Reference blank; de-assigned 2023-11-16; dual-registered 359/tcp + 359/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (line 704)
- Range class
- well-known (0–1023), currently unassigned
- Prevalence
- no nmap-services open-frequency data found for 359/udp in this pass [Unknown]
- Related ports
- none specifically documented as related
Primary use
none — no active IANA-assigned service
Other/unofficial uses
historically informal "nsrmp" (Network Security Risk Management Protocol, Eric Jacksch/Tenebris Technologies), never a widely deployed product [Likely] — https://raw.githubusercontent.com/Distrotech/iana-etc/master/port-numbers.dist, https://www.grc.com/port_359.htm; alternate legacy label "tenebris_nts" from the same registrant lineage
Security implications
no known current legitimate service, and no confirmed malware/trojan association — no named family, dated incident, or CVE was found [Confirmed absence in sources checked]
Typically seen on
not typically seen anywhere — no deployed service is documented
- Analyst note
- treat any responsive 359/udp as anomalous given its Reserved/de-assigned status; do not assume it is nsrmp or any other named service without further investigation.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| tenebris_nts | UDP | Tenebris Network Trace Service | 0.05% |
| tenebris_nts | TCP | nsrmp | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.