Definition · Open Ports & Services

What is Port Scanning?

Port scanning is the technique of sending probes to a range of TCP or UDP ports on a host to discover which ones are open — that is, which have a service listening and accepting connections. It is the foundational reconnaissance step for attackers and the foundational visibility step for defenders: both start by asking “what is this host exposing?”

Common scan types

  • TCP connect scan — completes the full three-way handshake; reliable but easily logged
  • SYN (half-open) scan — sends a SYN and interprets the response (SYN-ACK means open, RST means closed) without completing the handshake; the default for tools like Nmap
  • UDP scan — harder and slower, because open UDP ports often respond with silence
  • Internet-wide scanning — tools such as Masscan and ZMap can sweep the entire IPv4 address space for a single port in hours, which is why any newly exposed service is found quickly

Legality and ethics

Port scanning infrastructure you do not own or have permission to test may be unlawful in many jurisdictions and is typically against providers’ acceptable use policies. Defensive scanning of your own assets is standard practice and expected by most security frameworks.

Port scanning in EASM

External attack surface management platforms combine port scanning with service fingerprinting and banner grabbing to turn “port 8080 is open” into “an outdated management interface is internet-facing”. SurfaceLoop scans discovered hosts for open ports continuously, flagging new exposures as they appear.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.