Port 5986WS-Management over HTTPS
Encrypted WS-Management and WinRM remote administration traffic over HTTPS.
- transport
- tcp · udp
- in transit
- encrypted
- assignment
- official
- risk
- 7/10
- lookups
- 0
2 transports registered
payload protected on the wire
registered with iana
risk
rank 994 of 1,941 · top 51%
also known as wsmans, WinRM HTTPS, WS-Man HTTPS, port 5986
Technical Details
what runs on :5986WS-Management uses SOAP/XML messages transported over HTTP; on port 5986, the HTTP session is protected by TLS, normally beginning with a TLS handshake followed by HTTP requests and SOAP envelopes. The service supports operations such as resource enumeration, command invocation, and event subscription, with authentication negotiated through mechanisms such as Kerberos, NTLM, or certificate authentication depending on configuration. Port 5985 is the conventional unencrypted HTTP counterpart; although the registry lists both TCP and UDP for this assignment, normal HTTPS and WS-Management operation uses TCP.
Security Information
exposure of :5986risk score
7/ 10risk
treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.
remote access averages 3.7 across 138 ports — this one sits 3.3 above.
in transit
encrypted
payloads are protected on the wire
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Internet exposure provides a remote administration surface that should normally be restricted to trusted management networks or VPNs. Attackers may probe for the listener, attempt password or credential-based authentication, exploit weak authorization or certificate configuration, and use valid credentials for remote command execution or system inventory; TLS protects contents in transit but does not make unrestricted exposure safe.
Related Ports
the 8 most looked-up other ports in remote access — 138 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8000 | Intel Remote Desktop / Alternate HTTP Port | TCP | Web Services | safe | 84.3k |
| :8888 | D2GS Admin Console | TCP | Remote Access | caution | 83.7k |
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :8008 | IBM HTTP Server Admin | TCP | Web Services | caution | 58.3k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :23 | Telnet | TCP | Remote Access | caution | 34.8k |
risk mix of the 8 listed
- safe13%
- caution88%
0 of 8 encrypted