Network port detail · UDP/TCP

559

Teedtap
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Exposure: Unknown - the teedtap service's function is not documented beyond the bare IANA registry name, so there is no curated basis to classify its intended network exposure. No CVE or named malware family is documented specifically for 559/tcp as of a September 2026 search.
// analyst note
an open 559/tcp advertising teedtap carries no documented purpose or known malware association in available sources; treat it as low-information and verify against local host inventory rather than assuming either benign or malicious intent.
[ 01 ] — Context

About port 559/tcp.

Updated  ·  Confidence: Low  ·  4 sources  ·  How this page is checked

Port 559/tcp carries teedtap, an IANA-registered service whose function is otherwise undocumented, so whether it belongs on the public internet cannot be determined from available sources.

IANA registers 559 on both TCP and UDP as teedtap, description "TEEDTAP," with no reference RFC, no registration date, and assignee recorded as Charlie Limoges. There is no independent documentation explaining what the protocol actually does beyond that bare registry entry.

No vendor documentation, blog post, or forum/support thread was found naming a specific application or software product that generates traffic on this port, despite searching for community-sourced sightings. Port-database mirror sites (GRC Port Authority, portDB, and similar) only republish the bare IANA label with no elaboration on real-world usage.

No CVE or named malware family is documented against port 559 as of a September 2026 search, and GRC's Port Authority — a standard trojan/malware port reference — shows no trojan association beyond the bare IANA name.

Malware note
GRC's Port Authority, a standard trojan/malware port reference, shows no trojan association for port 559 beyond the bare IANA name.
Best practice
Treat an open 559/tcp as low-information until the running service is identified locally — verify against host inventory rather than assuming either benign or malicious intent.
IANA assignment
teedtap — "TEEDTAP"; reference blank (no RFC cited); assignee recorded as Charlie Limoges; dual-registered 559/tcp + 559/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry teedtap 559/tcp; cross-checked https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Range class
well-known (0-1023) [Confirmed]
Prevalence
nmap-services open-frequency 559/tcp = 0.000000 (sampled, not observed open); 559/udp ≈ 0.001433 [Confirmed] — this site's own tooling
Related ports
559/udp (same teedtap name, dual-registered) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry teedtap 559/udp

Primary use

Unknown — no independent documentation of what teedtap does was found beyond the bare IANA registry name

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Other/unofficial uses

none identified; no vendor, blog, or forum source names a specific application generating traffic on this port as of a September 2026 search

[Unknown] — https://www.grc.com/port_559.htm, https://portdb.yaleman.org/udp/559/

Security implications

no CVE or named malware family documented for 559/tcp as of a September 2026 search

[Likely] — https://www.grc.com/port_559.htm

Typically seen on

Unknown [Unknown]

Analyst note
an open 559/tcp advertising teedtap carries no documented purpose or known malware association in available sources; treat it as low-information and verify against local host inventory rather than assuming either benign or malicious intent.
[ 02 ] — Context

About port 559/udp.

Updated  ·  Confidence: Medium  ·  7 sources  ·  How this page is checked

Port 559/udp is registered to IANA as teedtap, but no documented protocol, RFC, or software application has been identified as using it; absent any known legitimate service, an open 559/udp should not be exposed to the public internet.

IANA lists the service name as teedtap, described simply as "TEEDTAP," with the assignee recorded as [Charlie_Limoges] and no reference RFC or specification cited. The registration is dual on both transports — 559/tcp and 559/udp carry the identical entry — with no registration date recorded.

The nmap-services corpus records an open-frequency of approximately 0.001433 for 559/udp, a low but nonzero sampled rate, versus approximately 0.000000 (not observed open) for 559/tcp. That asymmetry suggests any background traffic on this port pair is concentrated on UDP, though the absolute rate remains negligible.

No CVE or named malware/trojan family is documented specifically for 559/udp as of a September 2026 search. GRC's page lists only the bare service name with no trojan association noted.

Exposure
Unknown — no documented legitimate application exists for teedtap on 559/udp, so any observed traffic should be investigated rather than assumed benign.
Malware note
No credible source ties 559/udp to a named malware/trojan family as of a September 2026 search; GRC's Port Authority page lists only the bare service name with no trojan association noted.
Best practice
Treat any open 559/udp as unexplained — since no legitimate service is attested, investigate rather than assume routine or benign traffic.
IANA assignment
teedtap — "TEEDTAP"; reference (blank — no RFC cited in registry); assignee [Charlie_Limoges]; dual-registered 559/tcp + 559/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry teedtap 559/udp; cross-checked https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=559
Range class
well-known (0-1023) [Confirmed]
Prevalence
nmap-services open-frequency 559/udp ≈ 0.001433 (sampled open at a low but nonzero rate); 559/tcp ≈ 0.000000 (not observed open) [Confirmed] — this site's own tooling (built from nmap-services)
Related ports
559/tcp (same teedtap name, dual-registered) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry teedtap 559/tcp

Primary use

no documented protocol or software implements teedtap on 559/udp beyond the bare IANA name registration

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=559

Other/unofficial uses

none confirmed; no vendor product or community tool credibly tied to 559/udp [Unknown] — https://www.speedguide.net/port.php?port=559, https://www.grc.com/port_559.htm, http://www.t1shopper.com/tools/port-number/559/

Security implications

no CVE or named malware/trojan family documented for 559/udp as of a September 2026 search

[Unknown] — https://www.grc.com/port_559.htm

Typically seen on

no confirmed deployment context [Unknown]

Analyst note
an open 559/udp has no attested legitimate application behind it — investigate rather than assume routine traffic.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
teedtap UDP — 0.14%
teedtap TCP — 0.00%
IANA name
teedtap
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.