Port 135: Microsoft RPC Endpoint Mapper (DCE/RPC)
TCP port 135 is the RPC Endpoint Mapper on Windows, registered with IANA as epmap (DCE endpoint resolution). RPC clients ask the endpoint mapper which dynamic port a service uses, then connect to that port, which on current Windows versions falls in the 49152 to 65535 range. The RPC service also acts as the COM Service Control Manager, so DCOM and WMI administration depend on it.
Port Details
Security Exposure
An open port 135 exposes Windows RPC interfaces to remote callers. UK Government Cyber Unit guidance warns that unprotected RPC can lead to unauthorized access, remote code execution through vulnerable endpoints, denial of service, and lateral movement.
Hardening
- +Remove inbound internet rules for port 135 and allow it only from trusted management addresses.
- +Narrow the RPC dynamic port range in the registry so firewalls only need to open a small set of ports.
- +Use RPC filters on interface UUID (netsh rpc filter) to allow only required interfaces.
- +Require Kerberos or NTLM authentication and RPC packet privacy for RPC services.
- +Disable services that register RPC interfaces when they are not needed.
Monitoring
UK Government Cyber Unit guidance recommends regular event log monitoring with SIEM tools to detect anomalies. RPC connections to 135 and the dynamic range from hosts with no administrative need for them are worth review, since the same guidance lists lateral movement as an RPC risk.
Tools for Auditing and Monitoring MS-RPC
Impacket
FreePython library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Related Tool Categories
Frequently Asked Questions
What is port 135 used for?→
It is the Microsoft RPC Endpoint Mapper. Clients contact it to find out which dynamic port an RPC service such as WMI or DCOM is listening on.
Should port 135 be open to the internet?→
No. UK Government Cyber Unit guidance recommends removing inbound internet rules for port 135 and allowing connections only from trusted IP addresses.
Why does Windows RPC need ports above 49152?→
After the endpoint mapper lookup, RPC services listen on dynamically assigned ports, which Microsoft lists as 49152 to 65535. The range can be restricted in the registry for firewall rules.
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 135)
- Microsoft Learn: Service overview and network port requirements for Windows
- Microsoft Learn: How to configure RPC dynamic port allocation to work with firewalls
- Microsoft Learn: netsh rpc
- UK Government Cyber Unit: Open port 135, Remote Procedure Call (RPC)
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 135 is not guaranteed to be MS-RPC. Exploited-in-the-wild data from the CISA KEV catalog (CC0).