Network port detail · UDP/TCP

560

Rmonitor
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No documented RFC or specification exists for this port; as a name-only, undocumented legacy registration it should stay internal-only. SANS ISC records only generic background scan noise, not targeted exploitation.
[ 01 ] — Context

About port 560/tcp.

Updated  ·  Confidence: Medium  ·  5 sources  ·  How this page is checked

Port 560/tcp carries rmonitor (rmonitord), a bare IANA name-only registration with no documented function; it should stay internal-only rather than be exposed to the public internet.

IANA registers 560 for both TCP and UDP under the same name, "rmonitor" (description "rmonitord"), with no assignee, no registration or modification date, and a blank Reference field (the IANA Service Name and Transport Protocol Port Number Registry). RFC 1340 (July 1992) records the identical bare mapping — "rmonitor 560/tcp rmonitord" — and adds no further functional detail.

The name lineage points toward BSD-derived Unix remote-monitoring utilities historically used to query the load or status of remote hosts, but no technical specification or current protocol document describing the wire format could be located as of a September 2026 search. Neither rmonitord nor rmonitor has a man page on FreeBSD or NetBSD.

No specific vendor product or client application beyond the bare rmonitord name was found actively documented as generating traffic on this port; mirror listings (SpeedGuide, WhatPortIs, portsmaster.net) only repeat the bare IANA assignment. No CVE is recorded in the NVD and no Trojan/virus association is listed in GRC's Port Authority database for port 560, as of a September 2026 search.

SANS Internet Storm Center's port-560 activity page recorded ongoing background-scan traffic against the port as of a September 2026 check (30 records, 25 targets, 20 sources, all TCP), consistent with routine opportunistic internet scanning rather than a known targeted campaign. nmap-services records this port as rarely seen open — an open-frequency of 0.000038 on TCP and 0.000626 on UDP — so a live response on the port is unusual and worth investigating rather than expected.

Exposure
Internal-only — no protocol specification, authentication documentation, or vendor implementation could be confirmed for this bare IANA registration; should never be reachable from the public internet.
Protocol documentation
IANA's Reference field is blank — no RFC defines rmonitor's wire format, so there is no public specification to audit against.
Scanning activity
SANS ISC recorded background internet scan traffic against port 560 as of a September 2026 check, consistent with routine opportunistic scanning rather than targeted exploitation.
Software sightings
Unknown — no vendor product or client application beyond the bare rmonitord name was found documented as using this port.
IANA assignment
rmonitor — "rmonitord"; reference (blank — no RFC cited in IANA registry); assignee Unknown; dual-registered 560/tcp + 560/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known/system (0–1023) [Confirmed]
Prevalence
nmap-services open-frequency 560/tcp = 0.000038, 560/udp = 0.000626 [Confirmed] — this site's own tooling
Related ports
560/udp (companion registration); 513/tcp login (rlogin) and 513/udp who; 514/tcp shell/rsh — same BSD r-utils era; 514/udp syslog ([RFC5426]) is a separate, unrelated registration on that same port number [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry

Primary use

IANA registers the bare name rmonitor (description rmonitord) on 560/tcp and 560/udp with no documented function; no protocol specification or implementation could be located

[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry

Other/unofficial uses

Name lineage suggests a possible connection to the BSD rwho/rstat family of remote-monitoring utilities (rwhod, ruptime, rstatd), but no source documents that connection or rmonitor's actual function [Unknown]

Security implications

no documented RFC/spec; a name-only registration with no public specification to audit; SANS ISC shows generic background scan noise

[Likely] — https://isc.sans.edu/data/port/560

Typically seen on

Unknown — no confirmed application, vendor product, or host type; observed traffic should be treated as generic scanning noise absent contrary evidence [Unknown]

Malware associations

no CVE is recorded in the NVD and no Trojan/virus listing appears in GRC's Port Authority database for port 560, as of a September 2026 check

[Likely] — https://www.grc.com/port_560.htm
[ 02 ] — Context

About port 560/udp.

Updated  ·  Confidence: Low  ·  6 sources  ·  How this page is checked

Port 560/udp carries rmonitor (rmonitord), a legacy IANA-registered remote-monitor daemon name with no attached protocol specification; it has no documented legitimate use case and should stay internal-only rather than be exposed to the public internet.

IANA's service-names registry lists the assignment with the description rmonitord and no RFC or reference document (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp). The name lineage points toward BSD-derived Unix remote-monitoring utilities historically used to query the load or status of remote hosts, but no technical specification or current protocol document describing the wire format could be located as of a September 2026 search.

No current vendor documentation, blog post, or forum/support thread reporting active use of this exact port turned up as of a September 2026 search. Third-party port-lookup aggregators only restate the IANA registration name rather than reporting observed application traffic, so they were not treated as sightings of real-world use.

SANS Internet Storm Center's port-activity data recorded 20 distinct source IPs and 25 targets against port 560 in a single-day sample as of early September 2026, with the site's overall threat indicator at green (no elevated activity) — consistent with routine internet background-noise scanning rather than a targeted campaign. GRC's Port Authority database lists port 560 only as rmonitor/rmonitord with no trojan or malware notation, and no CVE ties to this port as of this search.

Exposure
No evidence of legitimate public-facing use; treat any external sighting of 560/udp as unexpected and worth investigating rather than expected service traffic.
Protocol documentation
No RFC or technical specification is attached to this IANA assignment, so the exact wire protocol used by rmonitord could not be confirmed.
IANA service name
rmonitor [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp)
IANA description
rmonitord [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp)
IANA reference/RFC
none listed [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp)
Dual registration
also registered as 560/tcp for the same service [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/tcp)

Common software applications

Unknown; no specific vendor or software could be confirmed generating traffic on this exact port [Unknown] (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)

Malware/trojan association

none listed as of a September 2026 search [Likely] (https://www.grc.com/port_560.htm)

Port
560 [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp)
Transport
udp [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp)
Assignee
Unknown [Unknown] (the IANA Service Name and Transport Protocol Port Number Registry rmonitor 560/udp — assignee column blank)
Observed open frequency
0.0626% of sampled hosts, per nmap-services-derived data [Confirmed] (this site's own tooling, port 560, udp service entry)
Scanning activity
20 source IPs and 25 targets in a single-day sample as of early September 2026, overall threat indicator green [Likely] (https://isc.sans.edu/data/port/560)
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
rmonitor UDP rmonitord 0.06%
rmonitor TCP rmonitord 0.00%
IANA name
rmonitor
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.