48
Summary
- // if you see it open
- Negligible internet-wide traffic; not among mass-scanner target ports. No CVE is publicly tied to the 'Digital Audit Daemon' service. SANS ISC lists the port but shows no sustained scanning. Standard practice is to block unless a specific internal application requires it.
- // analyst note
- A responsive port 48 is statistically rare; identify the actual application rather than trusting the IANA
auditdlabel, and note the legacy DRAT trojan reference.
About port 48/tcp.
Port 48/tcp is registered with IANA as auditd with the description "Digital Audit Daemon," assignee Larry Scott, and a blank reference field (dual-registered on TCP and UDP — 48/udp carries an identical service name, description, and assignee). The IANA reference column is blank: no RFC or other document is cited for this assignment, and no registration or modification date is recorded in the registry. This is a legacy System Port (the 0–1023 well-known range) whose auditd label is unrelated to the Linux kernel audit subsystem daemon, which does not use port 48. No widely deployed or documented software is known to bind to TCP/48 under the "Digital Audit Daemon" name today; third-party port databases generally just echo the IANA label without citing an implementation, so the practical "what runs here" answer is effectively unknown. Empirically the port is rare: Nmap's nmap-services open-frequency for 48/tcp is about 0.000013 — among the lowest observed for any System Port — while 48/udp is higher at roughly 0.000708 but still uncommon. For an analyst the chief historical note is a malware association: the DRAT remote-access trojan has long been listed in trojan-port reference tables as using TCP/48, a legacy early-2000s database artifact rather than a current high-activity campaign. A separate Delphi-compiled "DRAT V2" was reported by Recorded Future in a targeted campaign against Indian government organizations, but that report does not confirm port 48 usage specifically. No CVE is publicly tied to the "Digital Audit Daemon" service itself, and SANS ISC shows no sustained scanning of the port. Treat a responsive port 48 as statistically rare: it is not part of mass-scanner target sets, so an open listener warrants identifying the actual application rather than assuming the IANA label.
- IANA assignment
auditd— "Digital Audit Daemon"; reference (blank — no RFC cited in IANA registry); assignee Larry Scott; dual-registered 48/tcp + 48/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv)- Range class
- well-known / System Port (0–1023)
- Registration & modification dates
- blank in the IANA registry — IANA publishes no registration dates for System Port entries; any third-party "date registered" value is a database artifact, not IANA data [Confirmed] — IANA registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv)
- Prevalence
- nmap-services open-frequency 48/tcp ≈ 0.000013 (among the lowest for any System Port); 48/udp ≈ 0.000708 (higher but still uncommon) [Confirmed] — nmap-services file (https://svn.nmap.org/nmap/nmap-services)
- Related ports
- adjacent low System Ports — 46/tcp (mpm-snd), 49/tcp (tacacs); contrast the Linux audit subsystem, which does not use a network port
Primary use
IANA-registered name only; no widely deployed or documented software is known to actively use TCP/48 under the "Digital Audit Daemon" label, and the auditd name is unrelated to the Linux audit daemon (which does not use port 48)
Common software
Unknown — no recognized current product is documented as binding TCP/48 under this service name
Malware associations
DRAT remote-access trojan historically listed as using TCP/48 in early-2000s trojan-port tables (legacy, low-activity); a Delphi "DRAT V2" was reported against Indian government targets but without confirmed port-48 usage [Likely] — SANS ISC (https://isc.sans.edu/port.html?port=48), Recorded Future DRAT V2 report (https://www.recordedfuture.com/research/drat-v2-updated-drat-emerges-tag-140s-arsenal)
Security implications
negligible internet-wide traffic; not in mass-scanner target sets; no CVE tied to the "Digital Audit Daemon" service; standard practice is to block unless a specific internal application requires it
Typically seen on
no characteristic modern host class; an open listener is an anomaly worth identifying directly
- Analyst note
- A responsive port 48 is statistically rare; identify the actual application rather than trusting the IANA
auditdlabel, and note the legacy DRAT trojan reference.
About port 48/udp.
Port 48/udp is registered with IANA as auditd with the description "Digital Audit Daemon," assignee Larry Scott, and a blank reference field — the same assignment also covers 48/tcp, so the port is dual-registered on TCP and UDP under one service name. The IANA registry records no RFC or other reference document for this entry, and no registration or modification date is published, so the assignment reads as a legacy individual-registrant allocation in the well-known range (0–1023) rather than a protocol with a public specification. Despite the name, this "auditd / Digital Audit Daemon" is unrelated to the familiar Linux kernel audit daemon: Linux auditd communicates over the kernel's netlink interface and does not bind a fixed network port, so the shared name on port 48 is a naming coincidence rather than a functional relationship. No active open-source or commercial software product that uses port 48/udp under the IANA name has been identified in current sources, and the port carries a low (green) threat level on the SANS Internet Storm Center with no notable scan spikes or CVE submissions recorded at the time of research. Legacy malware catalogues do list a trojan named DRAT as historically using port 48 — but that association is documented on the TCP side, in pre-2010 trojan port listings, not on UDP; no CVE or active exploit campaign was found targeting 48/udp specifically. For an analyst, an open 48/udp is best treated as a rare, low-signal observation: the IANA label tells you little about what is actually listening, so investigate the host directly rather than assuming the registered service. As with any unused well-known port, blocking 48/udp at the firewall is standard hygiene.
- IANA assignment
auditd— "Digital Audit Daemon"; reference (blank — no RFC cited in IANA registry); assignee Larry Scott (individual registrant, no organization listed); dual-registered 48/tcp + 48/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry; the IANA Service Name and Transport Protocol Port Number Registry line 106- Range class
- well-known (0–1023) [Confirmed]
- Registration / modification date
- blank in IANA registry — none published [Confirmed] — IANA registry (Reference and date columns blank)
- Prevalence / exposure
- SANS ISC shows a green (low) threat level for port 48 with no notable scan spikes or CVE submissions at time of research; no verified Shodan mass-exposure data specific to 48/udp found [Likely] — SANS ISC port 48 page
- Related ports
- 48/tcp (same IANA assignment); other well-known small/legacy services
Primary use
legacy IANA well-known-port assignment with no public specification; no active software product identified using the IANA name on 48/udp
Security implications
no known active malware or exploit specifically targets 48/udp; firewall-blocking unused well-known ports is standard practice
Malware associations
legacy trojan DRAT listed for port 48 in older (pre-2010) catalogues, documented on the TCP side, not UDP; a DRAT-V2/APT36 claim surfaced only in an unverified search snippet and is excluded
Typically seen on
no characteristic host class identified; an open 48/udp is an anomaly worth investigating directly
- Naming note
- unrelated to Linux kernel
auditd, which uses the netlink interface and binds no fixed network port — the shared name is a coincidence [Likely] — general knowledge of Linux auditd architecture - Analyst note
- The IANA name is not a reliable indicator of what is listening on 48/udp — probe the host rather than trusting the label; legitimate use is rare.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| auditd | UDP | Digital Audit Daemon | 0.07% |
| auditd | TCP | Digital Audit Daemon | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.