395
Summary
- // typical exposure
- Internal-only — netcp is a legacy network-monitoring-probe control channel with no confirmed current legitimate use; if present it belongs strictly on an internal management network, never exposed to the public internet.
- // common applications
- NetScout Systems probes (legacy/historic Traffic on this port, if seen at all, most likely traces to legacy NetScout Systems network-monitoring probe control channels; no current vendor documentation or independent community report confirms active software using it today.
- // analyst note
- a formally registered but apparently dormant IANA service — an open port 395 is not explained by any current mainstream software and merits investigation.
- // if you see it open
- No CVE or dated exposure/scanning report for this port was found in the sources checked. auditmypc.com's own verdict line for port 395 reads "Virus / Trojan: No" — the aggregator records no confirmed malware association. No current NetScout product documentation names this port, suggesting a dormant/legacy assignment; an open port 395 is anomalous and worth investigating rather than assuming routine service.
About port 395/tcp.
Port 395/tcp carries netcp, the NetScout Control Protocol registered with IANA; it is a legacy monitoring-probe control channel with no evidence of a legitimate need for public exposure, so it should stay internal-only if it ever appears in a scan.
The IANA registry lists 395 as dual-registered on TCP and UDP under the service name netcp, description "NetScout Control Protocol," assignee Ashwani Singhal, with a blank Reference column — no RFC documents the protocol. The registration itself confirms the historical tie to NetScout Systems' network-probe hardware/software, which used this channel to communicate with and configure remote monitoring probes (a predecessor line to today's nGenius/nGeniusONE products).
Current-day evidence is thin. No NetScout product documentation (nGenius Collector, nGeniusONE, nGeniusPULSE, Edge Sensor) references port 395, and no forum, blog, or scanning report turned up an independent sighting of active software using it — the only non-IANA sources found are generic port-lookup directories restating the same registry entry. The nmap-services corpus records 395/tcp at an open-frequency of essentially 0.000000, meaning it is present in the dataset but almost never seen open in real-world scans; no CVE or dated exposure/scanning report for this port was found in the sources checked.
auditmypc.com was checked as a possible source for a malware association: its own verdict line for port 395 reads verbatim "Virus / Trojan: No," so the aggregator records no confirmed malware association for this port.
- IANA assignment
netcp— "NetScout Control Protocol"; reference (blank — no RFC cited); assignee Ashwani Singhal; dual-registered 395/tcp + 395/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (IANA service registry, cached locally)- Registration date
- 2010-04-07 per the cached IANA registry record [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency for 395/tcp ≈0.000000 (present in the dataset, zero observed open-frequency) [Confirmed] — this site's own tooling (cached nmap-services dataset)
- Related ports
- none documented — the registry records no companion or clustered assignment for this service [Unknown]
Primary use
control-channel protocol historically used by NetScout Systems network-monitoring probe hardware/software to communicate with and configure remote probes
Other/unofficial uses
none confirmed; no current NetScout product documentation (nGenius Collector, nGeniusONE, nGeniusPULSE, Edge Sensor) references this port [Unknown]
Security implications
no CVE or dated exposure report found; auditmypc.com's own verdict line for port 395 reads "Virus / Trojan: No" — no confirmed malware association
Typically seen on
legacy/historical NetScout Systems probe deployments, if seen at all; otherwise treat as an anomaly [Unknown]
- Analyst note
- a formally registered but apparently dormant IANA service — an open port 395 is not explained by any current mainstream software and merits investigation.
About port 395/udp.
Port 395/udp carries netcp (NetScout Control Protocol), a legacy monitoring-probe control channel registered with IANA; it should stay internal-only if it ever appears in a scan, not exposed to the public internet.
The port is IANA-registered under the service name netcp, described as "NetScout Control Protocol," with the assignee listed as Ashwani Singhal (netscout.com). Registration date: 2010-04-07 per the cached IANA registry record. The port is dual-registered on both 395/tcp and 395/udp. The IANA Reference field is blank — no RFC is cited for this assignment.
No detailed protocol specification is publicly documented, and a check of the current NetScout product documentation (nGenius Collector, nGeniusONE, nGeniusPULSE, Edge Sensor) found no reference to this port. The likely primary use, inferred from the registered service name and vendor identity rather than from a published spec, is a control-plane channel between NetScout monitoring probes and their managing console or agent infrastructure — historically, not necessarily today.
No independently corroborated third-party applications beyond the NetScout registrant were found. Generic port-lookup mirror sites (SpeedGuide, t1shopper, tcp-udp-ports.com, ports.my-addr.com) simply restate the IANA registration without naming additional software, and no game, P2P, or other client documentation referencing 395/udp was located. auditmypc.com was checked as a possible source for a malware association: its own verdict line for port 395 reads verbatim "Virus / Trojan: No," so the aggregator records no confirmed malware association for this port.
- IANA assignment
netcp— "NetScout Control Protocol"; reference (blank — no RFC cited); assignee Ashwani Singhal; dual-registered 395/tcp + 395/udp [Confirmed] — IANA service-names-port-numbers registry (the IANA Service Name and Transport Protocol Port Number Registry lines 783–784; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml)- Registration date
- 2010-04-07 per the cached IANA registry record [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency for 395/udp ≈0.000428 [Confirmed] — this site's own tooling (cached nmap-services dataset)
- Related ports
- none documented — the registry records no companion or clustered assignment for this service [Unknown]
Primary use
control-channel protocol historically used by NetScout Systems network-monitoring probe hardware/software to communicate with and configure remote probes; inferred from service name and vendor identity, not a detailed protocol spec
Other/unofficial uses
none corroborated; generic port-mirror sites only restate the IANA registration; no current NetScout product documentation references this port
Security implications
no CVE or dated exposure report found; auditmypc.com's own verdict line for port 395 reads "Virus / Trojan: No" — no confirmed malware association
Typically seen on
legacy/historical NetScout Systems probe deployments, if seen at all; otherwise treat as an anomaly [Unknown]
- Analyst note
- legitimate traffic on this port, if seen at all, most likely traces to legacy NetScout Systems monitoring deployments; unexplained sightings are worth investigating.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| netcp | UDP | NETscout Control Protocol | 0.04% |
| netcp | TCP | NETscout Control Protocol | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.