Network port detail · UDP/TCP

561

Monitor
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Exposure: Anomalous — no documented modern application or malware family uses this port as of a September 2026 search of GRC's Port Authority page and the Chebucto trojan-port table, so it is essentially never legitimately open. Because no maintained service is known to run here, an open 561/tcp listener is unexpected and should be investigated as a possible misconfiguration, decoy, or backdoor rather than assumed to be a legitimate service.
[ 01 ] — Context

About port 561/tcp.

Updated  ·  Confidence: Medium  ·  5 sources  ·  How this page is checked

Port 561/tcp carries the IANA-registered service name monitor, but no protocol specification, description, or maintained application is documented for it, so it should not be expected on a host and has no place facing the public internet.

The IANA Service Name and Transport Protocol Port Number Registry lists monitor as dual-registered on 561/tcp and 561/udp with blank description, assignee, and reference fields — a bare reservation rather than a described service (the IANA Service Name and Transport Protocol Port Number Registry monitor 561/tcp).

RFC 1340 (Assigned Numbers, July 1992) corroborates the same bare name at 561/tcp with no further elaboration. The adjacent port 562/tcp is a separate RFC 1340 assignment, chshell/chcmd, and some secondary sources conflate the two; that assignment belongs to 562, not 561.

No software, service, or malware family is documented as using 561/tcp as of a September 2026 search of GRC's Port Authority page and the Chebucto trojan-port compilation; nothing rules out an isolated or legacy use, but nothing documents one either.

nmap-services records an open-frequency of 0.000038 for 561/tcp (about 0.004% of scanned hosts) and 0.000544 for 561/udp — among the least commonly observed open ports in the dataset, consistent with a largely inactive legacy reservation.

Exposure
Anomalous — no protocol or application is documented, so an open 561/tcp should be treated as unexpected and investigated rather than assumed legitimate.
Malware
No malware or trojan family is documented as using this port; GRC's Port Authority page for 561 shows no known-application data, and the Chebucto trojan-port table does not list 561 among its trojan-to-port mappings, as of a September 2026 search.
Related-port caution
RFC 1340 assigns chshell/chcmd to the adjacent 562/tcp, not 561/tcp — some secondary sources conflate the two.
Prevalence
nmap-services open-frequency for 561/tcp is 0.000038 (~0.004%), among the least frequently observed open ports recorded.
IANA assignment
monitor — no description, assignee, or reference; dual-registered 561/tcp + 561/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry monitor 561/tcp
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services open-frequency 561/tcp = 0.000038 (~0.004%); 561/udp = 0.000544 [Confirmed] — this site's own tooling (built from nmap-services)
Related ports
562/tcp (chshell/chcmd, RFC 1340) is a distinct, adjacent assignment sometimes conflated with 561 [Confirmed] — https://datatracker.ietf.org/doc/html/rfc1340

Primary use

no published protocol specification; monitor is a bare IANA reservation with no documented function

[Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Other/unofficial uses

none found as of a September 2026 search [Unknown]

Security implications

no documented modern usage or malware association; essentially never legitimately open, so an observed listener warrants investigation

[Unknown] — https://www.grc.com/port_561.htm, http://www.chebucto.ns.ca/~rakerman/trojan-port-table.html

Typically seen on

no known legitimate host type identified; treat any open instance as anomalous [Unknown]

Malware associations

none documented as of a September 2026 search of GRC's Port Authority page and the Chebucto trojan-port table

[Unknown] — https://www.grc.com/port_561.htm, http://www.chebucto.ns.ca/~rakerman/trojan-port-table.html
[ 02 ] — Context

About port 561/udp.

Updated  ·  Confidence: Likely  ·  5 sources  ·  How this page is checked

Port 561/udp carries the IANA-registered service name "monitor" with a blank description; third-party aggregators informally describe it as a BSD-era status-query service, but that characterization is unsupported by any IANA or standards document. It has no accompanying RFC or reference document, and — whichever description applies — it should be kept restricted to trusted networks rather than exposed to the public internet.

IANA lists "monitor" on both 561/tcp and 561/udp with no description, assignee, or reference column populated in the service-names-port-numbers registry. Third-party port-lookup aggregators (SpeedGuide, WhatPortIs) characterize it informally as a BSD-era protocol for querying remote host status and performance, later largely superseded in practice by SNMP, but this characterization is not sourced to any IANA or standards document.

Measured against the site's own port-frequency dataset (built from nmap-services), 561/udp shows an open-frequency of 0.000544 (about 0.05%) and 561/tcp shows 0.000038 (about 0.004%) — both near the low end of the observed distribution, consistent with a port that is rarely found open in general internet scanning today.

No CVE, malware family, or trojan is documented in mainstream security sources as associated with port 561 as of a September 2026 search. No specific application or vendor software could be confirmed as commonly generating traffic on this port from the sources reviewed.

Exposure
Restricted — a legacy, seemingly unauthenticated status-monitoring service with no published spec; keep it off the public internet and limited to trusted network segments if it is running at all.
Protocol maturity
No RFC or IANA reference document exists for the "monitor" assignment, so no authoritative specification defines its expected wire format or authentication model.
Aggregator risk scoring
WhatPortIs assigns an informal "moderate" (5/10) risk rating to this port with no stated methodology; treat this as unverified aggregator scoring rather than an authoritative assessment.
IANA service name
monitor [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
IANA reference/RFC
None listed in the registry entry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry — Reference column is blank
Dual registration
"monitor" is registered on both 561/tcp and 561/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry monitor 561/tcp and monitor 561/udp

Common software

Unknown — no credibly-sourced application or vendor product was found reported as commonly using this port [Unknown]

Malware/CVE association

None found as of a September 2026 search

[Likely] — http://whatportis.com/561
Port
561 [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry monitor 561/udp
Transport
UDP [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry monitor 561/udp
Assignee
Unknown [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry — Assignee column is blank
Informal description
Legacy BSD-era system/network status-monitoring service, per third-party aggregators [Likely] — https://www.speedguide.net/port.php?port=561, http://whatportis.com/561
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
monitor UDP — 0.05%
monitor TCP — 0.00%
IANA name
monitor
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.