536
Summary
- // typical exposure
- Internal-only — opalis-rdv is a legacy Windows automation-related service-name registration with no evidence of current mainstream or public-facing deployment, analogous to other internal Windows automation services that should never face the public internet.
- // analyst note
- An open port 536/udp is unusual today; investigate as a legacy automation artifact rather than assume malicious intent, but do not expect a modern Opalis/System Center Orchestrator deployment to use it.
- // if you see it open
- No CVE or malware/trojan association was found as of an August 2026 search; GRC's port-536 page lists only the bare service name and purpose string with no trojan note. The service is a legacy Windows automation-related registration with negligible real-world exposure today, and Microsoft's own connectivity documentation for the successor product (Opalis Integration Server / System Center Orchestrator) does not list port 536 among the ports it uses.
About port 536/udp.
Port 536/udp carries the IANA-registered service name opalis-rdv, associated with the Opalis Windows job-automation product line; it has no documented legitimate reason to be reachable from the public internet and should stay confined to whatever internal network still runs that software, if any does.
IANA lists opalis-rdv identically on both 536/tcp and 536/udp, assignee Laurent_Domenech, with a blank Reference field — no RFC or other spec backs the registration. The registry's description string is simply the service name itself, so little beyond the name and its product-line association is independently documented.
Opalis Software made a Windows workflow/job-automation product; Microsoft acquired the company in 2009 and folded it into Opalis Integration Server, later renamed System Center Orchestrator. Microsoft's own connectivity-requirements documentation for that successor product lists TCP 1433, TCP 135 plus dynamic RPC, TCP 5314, and TCP 139/445 as the ports it uses — port 536 does not appear anywhere in that document.
A prior version of this entry described opalis-rdv as a Dynamic Data Exchange (DDE) rendezvous channel bound to a specific "Opalis Robot Server" component. That framing has been dropped: the cited sources do not carry it. GRC's port-536 page contains only the bare service name and purpose string, with no mention of DDE, rendezvous, or a Robot Server component, and no independent source was found that does.
- Exposure
- opalis-rdv is a legacy Windows automation service-name registration with no evidence of current mainstream deployment; treat any host answering on 536/udp as an internal legacy artifact, never as something meant to face the public internet.
- Notable CVE
- none recorded in the NVD as of an August 2026 search.
- Malware association
- none found; GRC's port-536 listing shows only the bare service name with no trojan/malware note.
- Prevalence
- essentially unseen in the wild — nmap-services open-frequency for 536/udp is 0.000428 (~0.04%), and for 536/tcp 0.000025 (~0.003%).
- IANA assignment
opalis-rdv— description "opalis-rdv"; reference (blank — no RFC cited); assignee Laurent_Domenech; dual-registered 536/tcp + 536/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry opalis-rdv 536/udp- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency 536/udp ≈ 0.000428 (~0.04%); 536/tcp ≈ 0.000025 (~0.003%) [Confirmed] — this site's own tooling
- Related ports
- 536/tcp (identical dual registration); Opalis Integration Server ports TCP 1433, 135(+dynamic RPC), 5314, 139/445 [Confirmed] — https://learn.microsoft.com/it-it/archive/blogs/opalis/overview-of-opalis-integration-server-connectivity-requirements
Primary use
IANA-registered service name opalis-rdv, associated with the Opalis product line (Opalis Software's Windows job-automation tools, later Opalis Integration Server / System Center Orchestrator after Microsoft's 2009 acquisition); the registry carries no description beyond the bare name and no live source ties the assignment to a Dynamic Data Exchange mechanism or a specific "Robot Server" component
Other/unofficial uses
none found beyond the general Opalis product-line naming association; Microsoft's connectivity docs for the successor product (Opalis Integration Server / System Center Orchestrator) do not list port 536
Security implications
no CVE or malware association found as of an August 2026 search; legacy/obscure service-name registration with negligible real-world exposure today
Typically seen on
legacy Windows hosts running Opalis-era automation software (pre-Microsoft-acquisition era); otherwise essentially never seen [Likely]
- Analyst note
- An open port 536/udp is unusual today; investigate as a legacy automation artifact rather than assume malicious intent, but do not expect a modern Opalis/System Center Orchestrator deployment to use it.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| opalis-rdv | UDP | — | 0.04% |
| opalis-rdv | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.