Port 137: NetBIOS Name Service
UDP port 137 is the NetBIOS Name Service (NBT-NS) defined in RFC 1001 and RFC 1002. It resolves NetBIOS names, and RFC 1002 also defines node status requests, which return the names in a host's local name table. Microsoft lists NetBIOS name resolution on UDP 137 for services such as the Server service and Computer Browser.
Port Details
Security Exposure
An attacker on the local network can answer NBT-NS queries, pose as the requested host, and capture or relay the credentials victims send (MITRE ATT&CK T1557.001). Node status responses disclose a host's NetBIOS name table. CISA alert TA14-017A also lists NetBIOS name resolution as a UDP reflection vector with an amplification factor of 3.8.
Hardening
- +Disable NetBIOS over TCP/IP and LLMNR where they are not needed, as MITRE ATT&CK recommends.
- +Block UDP 137 at the internet edge and between segments that do not need NetBIOS.
- +Enable SMB signing to stop NTLMv2 relay of credentials gathered through name poisoning.
- +Use host-based security software to block NetBIOS and LLMNR traffic where it cannot be disabled, as MITRE ATT&CK suggests.
Monitoring
Watch for anomalous traffic on UDP 137 (NBT-NS) and UDP 5355 (LLMNR), which MITRE ATT&CK uses to detect poisoning, and for NBT-NS responses from hosts that are not name servers.
Tools for Auditing and Monitoring NetBIOS-NS
Responder
Open SourceLLMNR, NBT-NS, and mDNS poisoner that captures network credentials and runs rogue authentication servers during authorized internal assessments.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.
Frequently Asked Questions
Is port 137 TCP or UDP?→
RFC 1002 defines the NetBIOS Name Service on both TCP and UDP port 137, but Microsoft documents Windows NetBIOS name resolution on UDP 137.
Can NetBIOS be disabled?→
Yes, where no legacy system needs it. MITRE ATT&CK recommends disabling LLMNR, mDNS, and NetBIOS if they are not required, and Microsoft states that SMB2 and later shares do not use ports 137 to 139.
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 137)
- RFC 1001: Protocol Standard for a NetBIOS Service on a TCP/UDP Transport: Concepts and Methods
- RFC 1002: Protocol Standard for a NetBIOS Service on a TCP/UDP Transport: Detailed Specifications
- Microsoft Learn: Service overview and network port requirements for Windows
- MITRE ATT&CK T1557.001: Name Resolution Poisoning and SMB Relay
- CISA Alert TA14-017A: UDP-Based Amplification Attacks
- Microsoft Learn: Secure SMB traffic in Windows Server
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 137 is not guaranteed to be NetBIOS-NS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).