Port 5364Windows Kernel Debugging over Network (KDNET)
UDP 5364 is assigned to KDNET, Microsoft's network transport for debugging a Windows kernel remotely.
- transport
- udp
- in transit
- encrypted
- assignment
- official
- risk
- 8/10
- lookups
- 0
single transport
payload protected on the wire
registered with iana
risk
rank 993 of 5,451 · top 18%
also known as kdnet, Microsoft Kernel Debugger
Technical Details
what runs on :5364KDNET carries Windows kernel-debugger traffic over UDP between a target machine and a debugger host running tools such as WinDbg. The target is explicitly configured for network debugging, including a UDP port and a shared key; this is a debugger packet transport, not a general request/response service. Although UDP 5364 is the IANA assignment, KDNET configurations can specify a port, so finding this port does not establish that it is the configured port on a particular system.
Security Information
exposure of :5364risk score
8/ 10risk
treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.
remote access averages 3.8 across 210 ports — this one sits 4.2 above.
in transit
encrypted
payloads are protected on the wire
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
A working kernel-debugging session can inspect and alter kernel state, so an exposed KDNET endpoint represents powerful remote control of the target. Normal setup uses a shared key to protect the debugging connection, but the endpoint should still be restricted to a trusted debugging network and the key kept secret; it is not intended for public-internet exposure.
Related Ports
the 8 most looked-up other ports in remote access — 210 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8000 | Intel Remote Desktop / Alternate HTTP Port | TCP | Web Services | safe | 84.3k |
| :8888 | D2GS Admin Console | TCP | Remote Access | caution | 83.7k |
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :8008 | IBM HTTP Server Admin | TCP | Web Services | caution | 58.3k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :23 | Telnet | TCP | Remote Access | caution | 34.8k |
risk mix of the 8 listed
- safe13%
- caution88%
0 of 8 encrypted