Network port detail · UDP/TCP

395

Netcp
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Internal-only — netcp is a legacy network-monitoring-probe control channel with no confirmed current legitimate use; if present it belongs strictly on an internal management network, never exposed to the public internet.
// common applications
NetScout Systems probes (legacy/historic Traffic on this port, if seen at all, most likely traces to legacy NetScout Systems network-monitoring probe control channels; no current vendor documentation or independent community report confirms active software using it today.
// analyst note
a formally registered but apparently dormant IANA service — an open port 395 is not explained by any current mainstream software and merits investigation.
// if you see it open
No CVE or dated exposure/scanning report for this port was found in the sources checked. auditmypc.com's own verdict line for port 395 reads "Virus / Trojan: No" — the aggregator records no confirmed malware association. No current NetScout product documentation names this port, suggesting a dormant/legacy assignment; an open port 395 is anomalous and worth investigating rather than assuming routine service.
[ 01 ] — Context

About port 395/tcp.

Updated  ·  Confidence: Low

Port 395/tcp carries netcp, the NetScout Control Protocol registered with IANA; it is a legacy monitoring-probe control channel with no evidence of a legitimate need for public exposure, so it should stay internal-only if it ever appears in a scan.

The IANA registry lists 395 as dual-registered on TCP and UDP under the service name netcp, description "NetScout Control Protocol," assignee Ashwani Singhal, with a blank Reference column — no RFC documents the protocol. The registration itself confirms the historical tie to NetScout Systems' network-probe hardware/software, which used this channel to communicate with and configure remote monitoring probes (a predecessor line to today's nGenius/nGeniusONE products).

Current-day evidence is thin. No NetScout product documentation (nGenius Collector, nGeniusONE, nGeniusPULSE, Edge Sensor) references port 395, and no forum, blog, or scanning report turned up an independent sighting of active software using it — the only non-IANA sources found are generic port-lookup directories restating the same registry entry. The nmap-services corpus records 395/tcp at an open-frequency of essentially 0.000000, meaning it is present in the dataset but almost never seen open in real-world scans; no CVE or dated exposure/scanning report for this port was found in the sources checked.

auditmypc.com was checked as a possible source for a malware association: its own verdict line for port 395 reads verbatim "Virus / Trojan: No," so the aggregator records no confirmed malware association for this port.

IANA assignment
netcp — "NetScout Control Protocol"; reference (blank — no RFC cited); assignee Ashwani Singhal; dual-registered 395/tcp + 395/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (IANA service registry, cached locally)
Registration date
2010-04-07 per the cached IANA registry record [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services open-frequency for 395/tcp ≈0.000000 (present in the dataset, zero observed open-frequency) [Confirmed] — this site's own tooling (cached nmap-services dataset)
Related ports
none documented — the registry records no companion or clustered assignment for this service [Unknown]

Primary use

control-channel protocol historically used by NetScout Systems network-monitoring probe hardware/software to communicate with and configure remote probes

[Likely] — http://www.t1shopper.com/tools/port-number/395/, https://www.speedguide.net/port.php?port=395

Other/unofficial uses

none confirmed; no current NetScout product documentation (nGenius Collector, nGeniusONE, nGeniusPULSE, Edge Sensor) references this port [Unknown]

Security implications

no CVE or dated exposure report found; auditmypc.com's own verdict line for port 395 reads "Virus / Trojan: No" — no confirmed malware association

[Confirmed] — https://www.auditmypc.com/tcp-port-395.asp

Typically seen on

legacy/historical NetScout Systems probe deployments, if seen at all; otherwise treat as an anomaly [Unknown]

Analyst note
a formally registered but apparently dormant IANA service — an open port 395 is not explained by any current mainstream software and merits investigation.
[ 02 ] — Context

About port 395/udp.

Updated  ·  Confidence: Low

Port 395/udp carries netcp (NetScout Control Protocol), a legacy monitoring-probe control channel registered with IANA; it should stay internal-only if it ever appears in a scan, not exposed to the public internet.

The port is IANA-registered under the service name netcp, described as "NetScout Control Protocol," with the assignee listed as Ashwani Singhal (netscout.com). Registration date: 2010-04-07 per the cached IANA registry record. The port is dual-registered on both 395/tcp and 395/udp. The IANA Reference field is blank — no RFC is cited for this assignment.

No detailed protocol specification is publicly documented, and a check of the current NetScout product documentation (nGenius Collector, nGeniusONE, nGeniusPULSE, Edge Sensor) found no reference to this port. The likely primary use, inferred from the registered service name and vendor identity rather than from a published spec, is a control-plane channel between NetScout monitoring probes and their managing console or agent infrastructure — historically, not necessarily today.

No independently corroborated third-party applications beyond the NetScout registrant were found. Generic port-lookup mirror sites (SpeedGuide, t1shopper, tcp-udp-ports.com, ports.my-addr.com) simply restate the IANA registration without naming additional software, and no game, P2P, or other client documentation referencing 395/udp was located. auditmypc.com was checked as a possible source for a malware association: its own verdict line for port 395 reads verbatim "Virus / Trojan: No," so the aggregator records no confirmed malware association for this port.

IANA assignment
netcp — "NetScout Control Protocol"; reference (blank — no RFC cited); assignee Ashwani Singhal; dual-registered 395/tcp + 395/udp [Confirmed] — IANA service-names-port-numbers registry (the IANA Service Name and Transport Protocol Port Number Registry lines 783–784; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml)
Registration date
2010-04-07 per the cached IANA registry record [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services open-frequency for 395/udp ≈0.000428 [Confirmed] — this site's own tooling (cached nmap-services dataset)
Related ports
none documented — the registry records no companion or clustered assignment for this service [Unknown]

Primary use

control-channel protocol historically used by NetScout Systems network-monitoring probe hardware/software to communicate with and configure remote probes; inferred from service name and vendor identity, not a detailed protocol spec

[Likely] — IANA registry, https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml

Other/unofficial uses

none corroborated; generic port-mirror sites only restate the IANA registration; no current NetScout product documentation references this port

[Unknown] — https://www.speedguide.net/port.php?port=395, http://www.t1shopper.com/tools/port-number/395/

Security implications

no CVE or dated exposure report found; auditmypc.com's own verdict line for port 395 reads "Virus / Trojan: No" — no confirmed malware association

[Confirmed] — https://www.auditmypc.com/udp-port-395.asp

Typically seen on

legacy/historical NetScout Systems probe deployments, if seen at all; otherwise treat as an anomaly [Unknown]

Analyst note
legitimate traffic on this port, if seen at all, most likely traces to legacy NetScout Systems monitoring deployments; unexplained sightings are worth investigating.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
netcp UDP NETscout Control Protocol 0.04%
netcp TCP NETscout Control Protocol 0.00%
IANA name
netcp
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.