560
Summary
- // if you see it open
- No documented RFC or specification exists for this port; as a name-only, undocumented legacy registration it should stay internal-only. SANS ISC records only generic background scan noise, not targeted exploitation.
About port 560/tcp.
Port 560/tcp carries rmonitor (rmonitord), a bare IANA name-only registration with no documented function; it should stay internal-only rather than be exposed to the public internet.
IANA registers 560 for both TCP and UDP under the same name, "rmonitor" (description "rmonitord"), with no assignee, no registration or modification date, and a blank Reference field (the IANA Service Name and Transport Protocol Port Number Registry). RFC 1340 (July 1992) records the identical bare mapping — "rmonitor 560/tcp rmonitord" — and adds no further functional detail.
The name lineage points toward BSD-derived Unix remote-monitoring utilities historically used to query the load or status of remote hosts, but no technical specification or current protocol document describing the wire format could be located as of a September 2026 search. Neither rmonitord nor rmonitor has a man page on FreeBSD or NetBSD.
No specific vendor product or client application beyond the bare rmonitord name was found actively documented as generating traffic on this port; mirror listings (SpeedGuide, WhatPortIs, portsmaster.net) only repeat the bare IANA assignment. No CVE is recorded in the NVD and no Trojan/virus association is listed in GRC's Port Authority database for port 560, as of a September 2026 search.
SANS Internet Storm Center's port-560 activity page recorded ongoing background-scan traffic against the port as of a September 2026 check (30 records, 25 targets, 20 sources, all TCP), consistent with routine opportunistic internet scanning rather than a known targeted campaign. nmap-services records this port as rarely seen open — an open-frequency of 0.000038 on TCP and 0.000626 on UDP — so a live response on the port is unusual and worth investigating rather than expected.
- Exposure
- Internal-only — no protocol specification, authentication documentation, or vendor implementation could be confirmed for this bare IANA registration; should never be reachable from the public internet.
- Protocol documentation
- IANA's Reference field is blank — no RFC defines rmonitor's wire format, so there is no public specification to audit against.
- Scanning activity
- SANS ISC recorded background internet scan traffic against port 560 as of a September 2026 check, consistent with routine opportunistic scanning rather than targeted exploitation.
- Software sightings
- Unknown — no vendor product or client application beyond the bare rmonitord name was found documented as using this port.
- IANA assignment
rmonitor— "rmonitord"; reference (blank — no RFC cited in IANA registry); assignee Unknown; dual-registered 560/tcp + 560/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known/system (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency 560/tcp = 0.000038, 560/udp = 0.000626 [Confirmed] — this site's own tooling
- Related ports
- 560/udp (companion registration); 513/tcp login (rlogin) and 513/udp who; 514/tcp shell/rsh — same BSD r-utils era; 514/udp syslog ([RFC5426]) is a separate, unrelated registration on that same port number [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Primary use
IANA registers the bare name rmonitor (description rmonitord) on 560/tcp and 560/udp with no documented function; no protocol specification or implementation could be located
Other/unofficial uses
Name lineage suggests a possible connection to the BSD rwho/rstat family of remote-monitoring utilities (rwhod, ruptime, rstatd), but no source documents that connection or rmonitor's actual function [Unknown]
Security implications
no documented RFC/spec; a name-only registration with no public specification to audit; SANS ISC shows generic background scan noise
Typically seen on
Unknown — no confirmed application, vendor product, or host type; observed traffic should be treated as generic scanning noise absent contrary evidence [Unknown]
Malware associations
no CVE is recorded in the NVD and no Trojan/virus listing appears in GRC's Port Authority database for port 560, as of a September 2026 check
About port 560/udp.
Port 560/udp carries rmonitor (rmonitord), a legacy IANA-registered remote-monitor daemon name with no attached protocol specification; it has no documented legitimate use case and should stay internal-only rather than be exposed to the public internet.
IANA's service-names registry lists the assignment with the description rmonitord and no RFC or reference document (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp). The name lineage points toward BSD-derived Unix remote-monitoring utilities historically used to query the load or status of remote hosts, but no technical specification or current protocol document describing the wire format could be located as of a September 2026 search.
No current vendor documentation, blog post, or forum/support thread reporting active use of this exact port turned up as of a September 2026 search. Third-party port-lookup aggregators only restate the IANA registration name rather than reporting observed application traffic, so they were not treated as sightings of real-world use.
SANS Internet Storm Center's port-activity data recorded 20 distinct source IPs and 25 targets against port 560 in a single-day sample as of early September 2026, with the site's overall threat indicator at green (no elevated activity) — consistent with routine internet background-noise scanning rather than a targeted campaign. GRC's Port Authority database lists port 560 only as rmonitor/rmonitord with no trojan or malware notation, and no CVE ties to this port as of this search.
- Exposure
- No evidence of legitimate public-facing use; treat any external sighting of 560/udp as unexpected and worth investigating rather than expected service traffic.
- Protocol documentation
- No RFC or technical specification is attached to this IANA assignment, so the exact wire protocol used by
rmonitordcould not be confirmed.
- IANA service name
- rmonitor [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp)
- IANA description
- rmonitord [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp)
- IANA reference/RFC
- none listed [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp)
- Dual registration
- also registered as 560/tcp for the same service [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/tcp)
Common software applications
Unknown; no specific vendor or software could be confirmed generating traffic on this exact port [Unknown] (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)
Malware/trojan association
none listed as of a September 2026 search [Likely] (https://www.grc.com/port_560.htm)
- Port
- 560 [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp)
- Transport
- udp [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp)
- Assignee
- Unknown [Unknown] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp — assignee column blank)
- Observed open frequency
- 0.0626% of sampled hosts, per nmap-services-derived data [Confirmed] (this site's own tooling, port 560, udp service entry)
- Scanning activity
- 20 source IPs and 25 targets in a single-day sample as of early September 2026, overall threat indicator green [Likely] (https://isc.sans.edu/data/port/560)
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| rmonitor | UDP | rmonitord | 0.06% |
| rmonitor | TCP | rmonitord | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.