TCP Port 5061 – sips

TCP Port 5061 – sips

About TCP Port 5061

Port 5061 is registered with the Internet Assigned Numbers Authority (IANA) for sips. The IANA description reads: ‘SIP-TLS’. This port appears in 9 IDS rules and does not have notable malware activity indicators in our data.

IDS Rule References

9 IDS / security rules reference TCP port 5061. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.

Rule categories (top 3): bad-unknown (5), attempted-recon (2), attempted-admin (2).

Sample rule descriptions for TCP port 5061:

  • PROTOCOL-VOIP Possible SIP OPTIONS service information gathering attempt
  • OS-OTHER Bash environment variable injection attempt
  • ET SCAN NMAP SIP Version Detection Script Activity
  • ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Server)
  • ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Client)

Data Sources

This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and Snort Community Rules (GPLv2).

© 2002-2026 AuditMyPC.com