Network port detail · UDP/TCP

48

Auditd
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Negligible internet-wide traffic; not among mass-scanner target ports. No CVE is publicly tied to the 'Digital Audit Daemon' service. SANS ISC lists the port but shows no sustained scanning. Standard practice is to block unless a specific internal application requires it.
// analyst note
A responsive port 48 is statistically rare; identify the actual application rather than trusting the IANA auditd label, and note the legacy DRAT trojan reference.
[ 01 ] — Context

About port 48/tcp.

Updated  ·  Confidence: Medium

Port 48/tcp is registered with IANA as auditd with the description "Digital Audit Daemon," assignee Larry Scott, and a blank reference field (dual-registered on TCP and UDP — 48/udp carries an identical service name, description, and assignee). The IANA reference column is blank: no RFC or other document is cited for this assignment, and no registration or modification date is recorded in the registry. This is a legacy System Port (the 0–1023 well-known range) whose auditd label is unrelated to the Linux kernel audit subsystem daemon, which does not use port 48. No widely deployed or documented software is known to bind to TCP/48 under the "Digital Audit Daemon" name today; third-party port databases generally just echo the IANA label without citing an implementation, so the practical "what runs here" answer is effectively unknown. Empirically the port is rare: Nmap's nmap-services open-frequency for 48/tcp is about 0.000013 — among the lowest observed for any System Port — while 48/udp is higher at roughly 0.000708 but still uncommon. For an analyst the chief historical note is a malware association: the DRAT remote-access trojan has long been listed in trojan-port reference tables as using TCP/48, a legacy early-2000s database artifact rather than a current high-activity campaign. A separate Delphi-compiled "DRAT V2" was reported by Recorded Future in a targeted campaign against Indian government organizations, but that report does not confirm port 48 usage specifically. No CVE is publicly tied to the "Digital Audit Daemon" service itself, and SANS ISC shows no sustained scanning of the port. Treat a responsive port 48 as statistically rare: it is not part of mass-scanner target sets, so an open listener warrants identifying the actual application rather than assuming the IANA label.

IANA assignment
auditd — "Digital Audit Daemon"; reference (blank — no RFC cited in IANA registry); assignee Larry Scott; dual-registered 48/tcp + 48/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv)
Range class
well-known / System Port (0–1023)
Registration & modification dates
blank in the IANA registry — IANA publishes no registration dates for System Port entries; any third-party "date registered" value is a database artifact, not IANA data [Confirmed] — IANA registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv)
Prevalence
nmap-services open-frequency 48/tcp ≈ 0.000013 (among the lowest for any System Port); 48/udp ≈ 0.000708 (higher but still uncommon) [Confirmed] — nmap-services file (https://svn.nmap.org/nmap/nmap-services)
Related ports
adjacent low System Ports — 46/tcp (mpm-snd), 49/tcp (tacacs); contrast the Linux audit subsystem, which does not use a network port

Primary use

IANA-registered name only; no widely deployed or documented software is known to actively use TCP/48 under the "Digital Audit Daemon" label, and the auditd name is unrelated to the Linux audit daemon (which does not use port 48)

[Likely] — IANA registry; SANS ISC (https://isc.sans.edu/port.html?port=48)

Common software

Unknown — no recognized current product is documented as binding TCP/48 under this service name

[Unknown] — no source

Malware associations

DRAT remote-access trojan historically listed as using TCP/48 in early-2000s trojan-port tables (legacy, low-activity); a Delphi "DRAT V2" was reported against Indian government targets but without confirmed port-48 usage [Likely] — SANS ISC (https://isc.sans.edu/port.html?port=48), Recorded Future DRAT V2 report (https://www.recordedfuture.com/research/drat-v2-updated-drat-emerges-tag-140s-arsenal)

Security implications

negligible internet-wide traffic; not in mass-scanner target sets; no CVE tied to the "Digital Audit Daemon" service; standard practice is to block unless a specific internal application requires it

[Likely] — nmap-services, SANS ISC (https://isc.sans.edu/port.html?port=48)

Typically seen on

no characteristic modern host class; an open listener is an anomaly worth identifying directly

Analyst note
A responsive port 48 is statistically rare; identify the actual application rather than trusting the IANA auditd label, and note the legacy DRAT trojan reference.
[ 02 ] — Context

About port 48/udp.

Updated  ·  Confidence: Medium

Port 48/udp is registered with IANA as auditd with the description "Digital Audit Daemon," assignee Larry Scott, and a blank reference field — the same assignment also covers 48/tcp, so the port is dual-registered on TCP and UDP under one service name. The IANA registry records no RFC or other reference document for this entry, and no registration or modification date is published, so the assignment reads as a legacy individual-registrant allocation in the well-known range (0–1023) rather than a protocol with a public specification. Despite the name, this "auditd / Digital Audit Daemon" is unrelated to the familiar Linux kernel audit daemon: Linux auditd communicates over the kernel's netlink interface and does not bind a fixed network port, so the shared name on port 48 is a naming coincidence rather than a functional relationship. No active open-source or commercial software product that uses port 48/udp under the IANA name has been identified in current sources, and the port carries a low (green) threat level on the SANS Internet Storm Center with no notable scan spikes or CVE submissions recorded at the time of research. Legacy malware catalogues do list a trojan named DRAT as historically using port 48 — but that association is documented on the TCP side, in pre-2010 trojan port listings, not on UDP; no CVE or active exploit campaign was found targeting 48/udp specifically. For an analyst, an open 48/udp is best treated as a rare, low-signal observation: the IANA label tells you little about what is actually listening, so investigate the host directly rather than assuming the registered service. As with any unused well-known port, blocking 48/udp at the firewall is standard hygiene.

IANA assignment
auditd — "Digital Audit Daemon"; reference (blank — no RFC cited in IANA registry); assignee Larry Scott (individual registrant, no organization listed); dual-registered 48/tcp + 48/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry; the IANA Service Name and Transport Protocol Port Number Registry line 106
Range class
well-known (0–1023) [Confirmed]
Registration / modification date
blank in IANA registry — none published [Confirmed] — IANA registry (Reference and date columns blank)
Prevalence / exposure
SANS ISC shows a green (low) threat level for port 48 with no notable scan spikes or CVE submissions at time of research; no verified Shodan mass-exposure data specific to 48/udp found [Likely] — SANS ISC port 48 page
Related ports
48/tcp (same IANA assignment); other well-known small/legacy services

Primary use

legacy IANA well-known-port assignment with no public specification; no active software product identified using the IANA name on 48/udp

[Likely] — IANA registry; auditmypc.com UDP port 48 page

Security implications

no known active malware or exploit specifically targets 48/udp; firewall-blocking unused well-known ports is standard practice

[Likely] — auditmypc.com; SANS ISC port 48 page

Malware associations

legacy trojan DRAT listed for port 48 in older (pre-2010) catalogues, documented on the TCP side, not UDP; a DRAT-V2/APT36 claim surfaced only in an unverified search snippet and is excluded

[Likely] — Commodon threat list; EventTracker KB (DRAT/TCP entry, unreachable on re-fetch)

Typically seen on

no characteristic host class identified; an open 48/udp is an anomaly worth investigating directly

Naming note
unrelated to Linux kernel auditd, which uses the netlink interface and binds no fixed network port — the shared name is a coincidence [Likely] — general knowledge of Linux auditd architecture
Analyst note
The IANA name is not a reliable indicator of what is listening on 48/udp — probe the host rather than trusting the label; legitimate use is rare.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
auditd UDP Digital Audit Daemon 0.07%
auditd TCP Digital Audit Daemon 0.00%
IANA name
auditd
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.