Port 5364Windows Kernel Debugging over Network (KDNET)

UDP 5364 is assigned to KDNET, Microsoft's network transport for debugging a Windows kernel remotely.

transport
udp

single transport

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
8/10

risk

lookups
0

rank 993 of 5,451 · top 18%

also known as kdnet, Microsoft Kernel Debugger

Technical Details

what runs on :5364

KDNET carries Windows kernel-debugger traffic over UDP between a target machine and a debugger host running tools such as WinDbg. The target is explicitly configured for network debugging, including a UDP port and a shared key; this is a debugger packet transport, not a general request/response service. Although UDP 5364 is the IANA assignment, KDNET configurations can specify a port, so finding this port does not establish that it is the configured port on a particular system.

Security Information

exposure of :5364

risk score

8/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

remote access averages 3.8 across 210 ports — this one sits 4.2 above.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

A working kernel-debugging session can inspect and alter kernel state, so an exposed KDNET endpoint represents powerful remote control of the target. Normal setup uses a shared key to protect the debugging connection, but the endpoint should still be restricted to a trusted debugging network and the key kept secret; it is not intended for public-internet exposure.

the 8 most looked-up other ports in remote access — 210 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted