Port 365Deception Toolkit

A port associated with Fred Cohen’s Deception Toolkit, an early honeypot for detecting and recording attacker activity.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
2/10

safe

lookups
0

rank 994 of 1,879 · top 53%

also known as dtk

Technical Details

what runs on :365

DTK is a configurable honeypot toolkit rather than a wire protocol with one universal handshake or framing format. The assignment covers both TCP and UDP, while the actual listeners, emulated services, responses, and payload formats depend on the deployment; traffic may resemble the decoy service rather than identify itself as DTK. There are no generally applicable companion ports or protocol defaults beyond the registered port.

Security Information

exposure of :365

risk score

2/ 10safe

routine exposure. this port is rarely the way in on its own — keep it patched and logged and move on.

security averages 3.6 across 241 ports — this one sits 1.6 below.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

This port is normally exposed intentionally as part of a honeypot, not as a production service. It will accept and record hostile probes, and an old or misconfigured deployment could expose the host or reveal deception-monitoring details; keep it isolated, restrict management access, and do not treat its presence as evidence of a normal business service.

the 8 most looked-up other ports in security — 241 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted