Skip to main content

Port Details

Port
4444
Transport
TCP
Service
Metasploit / backdoor listener
IANA service name
krb524, nv-video
Range
User port (1024-49151)

Security Exposure

Outside its IANA registration, 4444 is best known from Metasploit reverse shell examples and the Blaster worm backdoor. CERT advised sites to consider blocking 4444/TCP inbound and outbound, depending on network requirements. An unexpected listener or outbound connection on 4444 warrants investigation.

Hardening

  • +Block inbound and outbound TCP 4444 at the perimeter unless a documented service needs it.
  • +Apply default-deny egress filtering so that hosts cannot open arbitrary outbound connections.
  • +Keep endpoint detection in place to flag processes that listen on or connect to unusual high ports.
  • +Patch remotely exploitable services; CERT notes that the 4444 backdoor was created by exploits for the DCOM RPC flaw.

Monitoring

Alert on any host listening on 4444 and on outbound connections to remote port 4444, then trace the owning process. Sysmon network connection events (Event ID 3, disabled by default) link each connection to a process.

Tools for Auditing and Monitoring Metasploit / backdoor listener

Sysmon

Free
SIEM Tools

Windows Sysinternals service that logs detailed process, network, and file activity to the event log.

LicenseProprietary
PlatformWindows

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Frequently Asked Questions

What is port 4444 used for?→

IANA lists krb524 on 4444 and notes unassigned use by nv-video. Metasploit documentation uses 4444 as the listener port in its reverse shell examples.

Is traffic on port 4444 malicious?→

Not always, but it should be investigated. CERT advised blocking 4444/TCP during the Blaster outbreak because exploits created backdoors on it.

Should port 4444 be blocked?→

Blocking 4444/TCP inbound and outbound is reasonable unless an approved application uses it; CERT's Blaster advisory told sites to consider blocking both directions depending on network requirements.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 4444 is not guaranteed to be Metasploit / backdoor listener. Exploited-in-the-wild data from the CISA KEV catalog (CC0).