Port 5555: Android Debug Bridge over TCP/IP
Port 5555 is used by the Android Debug Bridge (adb) daemon when a device or emulator accepts debugging connections over TCP/IP. The Android documentation uses 5555 for the first emulator's adb connection and for devices switched to TCP/IP mode with adb tcpip 5555. IANA assigns 5555 to personal-agent and notes known unauthorized uses of the port.
Port Details
Security Exposure
adb provides access to a Unix shell and to app installation on the device, so a reachable adb daemon is a direct control channel. Shadowserver rates internet-accessible ADB on 5555/tcp as critical and states that ADB is often abused by malware and other threat actors.
Hardening
- +Block TCP 5555 at the network perimeter and on guest or IoT networks.
- +Disable adb over TCP/IP on devices when debugging is finished.
- +Use paired wireless debugging on Android 11 and later instead of the adb tcpip mode.
- +Turn off developer options on production and kiosk devices.
Monitoring
Alert on any device listening on TCP 5555 and on inbound connections to that port from outside a development network.
Tools for Auditing and Monitoring ADB
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Shodan
FreemiumSearch engine for Internet-connected devices that indexes service banners, open ports, and exposed assets across public IP space.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Android and iOS application analyzers, runtime instrumentation frameworks, and mobile assessment suites.
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Frequently Asked Questions
What uses port 5555?→
The Android Debug Bridge daemon commonly listens on TCP 5555 for network debugging. IANA's registered service for 5555 is personal-agent.
Is an open port 5555 dangerous?→
Yes. Shadowserver classifies internet-accessible ADB as critical because it is often abused by malware.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5555 is not guaranteed to be ADB. Exploited-in-the-wild data from the CISA KEV catalog (CC0).