Definition · Open Ports & Services
What is Port Scanning?
Port scanning is the technique of sending probes to a range of TCP or UDP ports on a host to discover which ones are open — that is, which have a service listening and accepting connections. It is the foundational reconnaissance step for attackers and the foundational visibility step for defenders: both start by asking “what is this host exposing?”
Common scan types
- TCP connect scan — completes the full three-way handshake; reliable but easily logged
- SYN (half-open) scan — sends a SYN and interprets the response (SYN-ACK means open, RST means closed) without completing the handshake; the default for tools like Nmap
- UDP scan — harder and slower, because open UDP ports often respond with silence
- Internet-wide scanning — tools such as Masscan and ZMap can sweep the entire IPv4 address space for a single port in hours, which is why any newly exposed service is found quickly
Legality and ethics
Port scanning infrastructure you do not own or have permission to test may be unlawful in many jurisdictions and is typically against providers’ acceptable use policies. Defensive scanning of your own assets is standard practice and expected by most security frameworks.
Port scanning in EASM
External attack surface management platforms combine port scanning with service fingerprinting and banner grabbing to turn “port 8080 is open” into “an outdated management interface is internet-facing”. SurfaceLoop scans discovered hosts for open ports continuously, flagging new exposures as they appear.