365
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — 365/tcp is registered to a niche honeypot/deception toolkit (DTK) rather than a mainstream production service, so a live listener is essentially never a normal legitimate service and should be investigated as a possible decoy or anomaly.
- // analyst note
- A responsive port 365 is uncommon and most plausibly either a deliberate honeypot or an artifact of broad scanning — investigate rather than assume legitimacy.
- // if you see it open
- Not a mainstream production service; a live listener is most plausibly an intentional honeypot/decoy deployment or incidental exposure caught by broad port scanning. No CVEs or malware/trojan-port-list entries naming port 365 were found in sources reviewed this pass (absence not confirmed as exhaustive). IANA Reference field is blank and no registration date is published.
About port 365/tcp.
Port 365/tcp is registered to DTK (Deception Toolkit), a honeypot/deception framework rather than a mainstream production service, so a live listener should generally be either an intentional decoy or treated as an anomaly worth investigating — not exposed as ordinary infrastructure.
IANA registers both 365/tcp and 365/udp under the service name dtk, description "DTK," with assignee Fred Cohen and a blank Reference field (no RFC is cited). DTK is an early (1997-era) honeypot toolkit created by security researcher Fred Cohen that emulates vulnerable services to lure, log, and study attacker or scanner activity.
No registration date is recorded in the IANA registry data retrieved, so that field is left Unknown rather than fabricated. The port is not tied to any mainstream well-known service (no HTTP, mail, database, or similar role), and no CVEs or malware/trojan-port associations were found for it in the sources reviewed this pass.
Community-sourced usage data is thin: DTK's own project domain (dtk.org) has lapsed and now resolves to a domain-parking page, Wikipedia has no entry for the port or DTK, and secondary port-reference sites (speedguide.net, adminsub.net) returned errors when fetched. As a result, no specific "commonly seen" applications beyond DTK itself could be verified, and that gap is recorded honestly rather than guessed.
- IANA assignment
dtk— "DTK"; reference (blank — no RFC cited); assignee Fred Cohen; dual-registered 365/tcp + 365/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- no nmap-services or scan-prevalence figures were available from the research angles run this pass [Unknown]
- Related ports
- none specifically documented as related; compare against mainstream well-known ports in the same 0–1023 range for baseline expectations [Unknown]
Primary use
Deception Toolkit (DTK), an early honeypot/deception framework by Fred Cohen that emulates vulnerable services to attract and log attacker/scanner activity [Likely] — IANA registry entry (protocol behavior inferred from the registry description and DTK's documented purpose, not a dedicated RFC)
Other/unofficial uses
none verifiably documented; DTK's own domain (dtk.org) has lapsed to a parked-domain page and no other applications could be confirmed on this port [Unknown]
Security implications
essentially a niche security-research/decoy port rather than a production service; no CVEs or malware associations found this pass
Typically seen on
hosts intentionally running DTK as a honeypot/deception deployment; otherwise not expected in normal production traffic [Likely]
- Analyst note
- A responsive port 365 is uncommon and most plausibly either a deliberate honeypot or an artifact of broad scanning — investigate rather than assume legitimacy.
About port 365/udp.
Port 365/udp carries no mainstream application traffic; it is IANA-registered to Fred Cohen's Deception Toolkit (DTK), a legacy honeypot/deception framework, and should essentially never be found open on production internet-facing infrastructure.
IANA lists 365 as dtk — "DTK" — dual-registered on both 365/tcp and 365/udp, with assignee and contact "[Fred_Cohen]" and a blank Reference field (no RFC was ever published for it). No registration date is present in the registry.
DTK's own project documentation designates port 365 as the toolkit's fixed "deception port": a machine can expose or intentionally suppress it to signal that DTK-style deception defenses (simulated vulnerable services meant to waste attacker effort and aid detection) may be running. This is a niche, largely historical late-1990s security-research use rather than a mainstream protocol or service.
No third-party or community-sourced report of any other software, game client, or malware using UDP/365 was found in this pass, and no independent scan-telemetry source (e.g., a honeypot-tracking or scan-observatory report) confirming active internet scanning of the port turned up either — those dimensions are Unknown rather than assumed.
- IANA assignment
dtk— "DTK"; dual-registered 365/tcp + 365/udp; assignee/contact[Fred_Cohen]; Reference field blank (no RFC) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-724- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- no nmap-services or telemetry figure surfaced for this port in this pass [Unknown]
- Related ports
- 365/tcp (same
dtkdual registration)
Primary use
fixed "deception port" for Fred Cohen's Deception Toolkit (DTK), a honeypot/deception framework
Other/unofficial uses
none identified — no other software found using UDP/365
Security implications
exposure signals deception-defense presence per DTK's own design rationale; no independent scan or malware-association data found
Typically seen on
legacy/niche DTK honeypot deployments; otherwise an anomaly [Likely]
- Analyst note
- An open port 365/udp is rare and, per the tool's own documentation, most plausibly a DTK deception signal rather than a genuine service — investigate rather than assume routine traffic.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| dtk | UDP | Deception Tool Kit (www.all.net) | 0.04% |
| dtk | TCP | Deception Tool Kit (www.all.net) | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.