Port 5355: Link-Local Multicast Name Resolution
Port 5355 carries LLMNR, a DNS-based name resolution method that MITRE describes as a Microsoft Windows component that lets hosts on the same local link resolve each other's names. RFC 4795 states that responders listen on UDP 5355 at the link-scope multicast address 224.0.0.252 and on TCP 5355 for unicast.
Port Details
Security Exposure
Any host on the same link can answer an LLMNR query, so an attacker can spoof responses and steer a victim to a system it controls. MITRE ATT&CK T1557.001 describes LLMNR and NBT-NS poisoning used to collect or relay authentication material. The risk is mostly internal, since LLMNR traffic is link-local.
Hardening
- +Disable LLMNR by Group Policy where DNS is available, as MITRE ATT&CK mitigation M1042 recommends.
- +Disable NetBIOS over TCP/IP and mDNS where they are not needed; MITRE lists all three protocols under the same poisoning technique.
- +Enable SMB signing, which MITRE ATT&CK notes can stop NTLMv2 relay attacks.
- +Make sure internal DNS resolves every name clients request so fallback to LLMNR is rare.
Monitoring
Watch for hosts answering LLMNR queries on UDP 5355 that are not expected responders, and for authentication attempts from internal hosts toward unknown systems right after a failed DNS lookup.
Tools for Auditing and Monitoring LLMNR
Responder
Open SourceLLMNR, NBT-NS, and mDNS poisoner that captures network credentials and runs rogue authentication servers during authorized internal assessments.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Related Tool Categories
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Intercepting HTTP proxies, security assessment toolkits, and network exploitation frameworks.
Frequently Asked Questions
Should LLMNR be disabled?→
MITRE ATT&CK recommends disabling LLMNR, mDNS and NetBIOS through local security settings or Group Policy when they are not needed, because spoofed responses can capture authentication material.
Is port 5355 TCP or UDP?→
Both. RFC 4795 sends queries to UDP 5355 on a multicast address and has responders listen on TCP 5355 for unicast.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5355 is not guaranteed to be LLMNR. Exploited-in-the-wild data from the CISA KEV catalog (CC0).