Skip to main content

Port Details

Port
5355
Transport
UDP / TCP
Service
LLMNR
IANA service name
llmnr
Range
User port (1024-49151)
Related ports

Security Exposure

Any host on the same link can answer an LLMNR query, so an attacker can spoof responses and steer a victim to a system it controls. MITRE ATT&CK T1557.001 describes LLMNR and NBT-NS poisoning used to collect or relay authentication material. The risk is mostly internal, since LLMNR traffic is link-local.

Hardening

  • +Disable LLMNR by Group Policy where DNS is available, as MITRE ATT&CK mitigation M1042 recommends.
  • +Disable NetBIOS over TCP/IP and mDNS where they are not needed; MITRE lists all three protocols under the same poisoning technique.
  • +Enable SMB signing, which MITRE ATT&CK notes can stop NTLMv2 relay attacks.
  • +Make sure internal DNS resolves every name clients request so fallback to LLMNR is rare.

Monitoring

Watch for hosts answering LLMNR queries on UDP 5355 that are not expected responders, and for authentication attempts from internal hosts toward unknown systems right after a failed DNS lookup.

Tools for Auditing and Monitoring LLMNR

Responder

Open Source
Penetration Testing Tools

LLMNR, NBT-NS, and mDNS poisoner that captures network credentials and runs rogue authentication servers during authorized internal assessments.

LicenseGPL-3.0-or-later
PlatformLinux, macOS

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Wireshark

Open Source
Network Monitoring Tools

Network packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.

LicenseGPL-2.0-or-later
PlatformWindows, macOS, Linux, BSD

Frequently Asked Questions

Should LLMNR be disabled?→

MITRE ATT&CK recommends disabling LLMNR, mDNS and NetBIOS through local security settings or Group Policy when they are not needed, because spoofed responses can capture authentication material.

Is port 5355 TCP or UDP?→

Both. RFC 4795 sends queries to UDP 5355 on a multicast address and has responders listen on TCP 5355 for unicast.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5355 is not guaranteed to be LLMNR. Exploited-in-the-wild data from the CISA KEV catalog (CC0).