TCP Port 135 – epmap

TCP Port 135 – epmap

About TCP Port 135

Port 135 is registered with the Internet Assigned Numbers Authority (IANA) for epmap. The IANA description reads: ‘DCE endpoint resolution’. This port appears in 10 IDS rules and does not have notable malware activity indicators in our data.

IDS Rule References

10 IDS / security rules reference TCP port 135. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.

Rule categories (top 5): protocol-command-decode (3), attempted-admin (3), attempted-dos (2), attempted-recon (1), misc-activity (1).

Sample rule descriptions for TCP port 135:

  • NETBIOS DCERPC NCACN-IP-TCP srvsvc NetrShareEnum null policy handle attempt
  • SERVER-OTHER Winnuke attack
  • NETBIOS DCERPC invalid bind attempt
  • OS-WINDOWS DCERPC NCACN-IP-TCP lsass DsRolerUpgradeDownlevelServer overflow attempt
  • OS-WINDOWS DCERPC NCACN-IP-TCP ISystemActivator CoGetInstanceFromFile attempt

Data Sources

This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and Snort Community Rules (GPLv2).

© 2002-2026 AuditMyPC.com