Skip to main content

Port Details

Port
135
Transport
TCP
Service
MS-RPC
IANA service name
epmap
Range
System port (0-1023)
Related ports

Security Exposure

An open port 135 exposes Windows RPC interfaces to remote callers. UK Government Cyber Unit guidance warns that unprotected RPC can lead to unauthorized access, remote code execution through vulnerable endpoints, denial of service, and lateral movement.

Hardening

  • +Remove inbound internet rules for port 135 and allow it only from trusted management addresses.
  • +Narrow the RPC dynamic port range in the registry so firewalls only need to open a small set of ports.
  • +Use RPC filters on interface UUID (netsh rpc filter) to allow only required interfaces.
  • +Require Kerberos or NTLM authentication and RPC packet privacy for RPC services.
  • +Disable services that register RPC interfaces when they are not needed.

Monitoring

UK Government Cyber Unit guidance recommends regular event log monitoring with SIEM tools to detect anomalies. RPC connections to 135 and the dynamic range from hosts with no administrative need for them are worth review, since the same guidance lists lateral movement as an RPC risk.

Tools for Auditing and Monitoring MS-RPC

Penetration Testing Tools

Python library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.

LicenseModified Apache-1.1 (custom; see repo LICENSE)
PlatformLinux, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Frequently Asked Questions

What is port 135 used for?→

It is the Microsoft RPC Endpoint Mapper. Clients contact it to find out which dynamic port an RPC service such as WMI or DCOM is listening on.

Should port 135 be open to the internet?→

No. UK Government Cyber Unit guidance recommends removing inbound internet rules for port 135 and allowing connections only from trusted IP addresses.

Why does Windows RPC need ports above 49152?→

After the endpoint mapper lookup, RPC services listen on dynamically assigned ports, which Microsoft lists as 49152 to 65535. The range can be restricted in the registry for firewall rules.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 135 is not guaranteed to be MS-RPC. Exploited-in-the-wild data from the CISA KEV catalog (CC0).