Every open port is a decision someone made — and most of those decisions were made without thinking about what an attacker sees. This Cover6 Community session maps the services that run on almost every network to the threats that target them, so that when you read a scan, you’re not just seeing numbers: you’re seeing a threat profile.
Use this post as your read-ahead, then come back to it as a quick reference.
Read a scan like a threat actor
An attacker reading your scan results isn’t impressed by a long list — they’re looking for the one service that’s weak, outdated, or misconfigured. The session uses scanme.nmap.org, a target Nmap provides specifically so people can practice legally, and a basic scan to surface what’s open:
nmap -T4 -sV -Pn --top-ports 15 --open scanme.nmap.org
The -sV service-version flag is the important part: knowing a port is open tells you a little, but knowing what version is running tells you whether there’s a known attack for it. Pair the scan with banner grabbing — using netcat or curl to make a service announce itself — and you often get the software and version straight away.
Scan only targets you own or ones, like scanme.nmap.org, that explicitly permit it.
The ports to know by heart
A handful of services show up on nearly every network, and each carries its own threat profile:
| Port | Service | What it’s for | What the attacker looks for |
|---|---|---|---|
| 21 | FTP | File transfer | Anonymous login, cleartext credentials, old vulnerable versions |
| 22 | SSH | Remote admin | Weak or reused passwords, outdated versions, exposed keys |
| 25 | SMTP | Open relays, user enumeration | |
| 53 | DNS | Name resolution | Zone transfers, information leakage |
| 80 | HTTP | Web (cleartext) | The whole web-app attack surface; traffic readable on the wire |
| 443 | HTTPS | Web (encrypted) | Web-app flaws, weak TLS configuration |
| 445 | SMB | Windows file sharing | Open shares, old protocol versions, a top target for ransomware |
| 3306 | MySQL | Database | Default credentials, direct exposure to the internet |
| 3389 | RDP | Remote desktop | Brute force, exposure to the internet — a favorite entry point |
The pattern across all of them: an attacker reads the version, asks whether a known attack exists, and if the service shouldn’t be exposed at all, that’s a finding before they even touch it.
Each service has an attack path
Mapping the service to the attack is the whole game:
- Cleartext protocols (FTP, HTTP, Telnet) leak whatever they carry — credentials, data — to anyone watching the wire. The first question is always “why isn’t this encrypted?”
- Remote-access services (SSH, RDP) are brute-force magnets when passwords are weak and they’re exposed to the internet.
- File-sharing (SMB) is where a lot of real-world damage happens — open shares, old protocol versions, lateral movement, ransomware.
- Web (HTTP/HTTPS) is an entire discipline of its own: the service is a door into the application behind it.
Knowing the attack path for a service is also knowing the fix: encrypt it, restrict it, patch it, or take it off the internet.
Practice reading services on a lab you own
The way this clicks is to scan a target, read the services, and work out the attack path yourself. First Shell is the free Cover6 lab that runs in your browser — you get an authorized target, so you can scan it, read the open services, and prove which ones are actually weak.
👉 Start here, free: https://www.cover6solutions.com/product/cover6-first-shell-free-access/
Prefer the defender’s seat? First Watch gives you a live Splunk lab and your first SOC shift, free, where those same services show up as things to monitor and harden: https://www.cover6solutions.com/product/cover6-first-watch-free-access/
Where this path leads
Knowing services and their threats is foundational on both the SOC Analyst and Penetration Tester paths on Chrysalus. Build your free profile and add your service analysis as a project.
- Read the Pentester Roadmap 2026 and the SOC Analyst Roadmap 2026.
- Not sure which lane? Take the free career path assessment.
- Keep the Cover6 Field Manual handy as a free reference, and browse every Cover6 course.
- Join The 6, our free newsletter, to catch the next session.
Watch the replay
We ran this live in the Cover6 Community — a legal scan of scanme.nmap.org, the ports to know by heart, and the attack path behind each service. Planning to attend a future meetup? Use this post as your read-ahead, and catch the replay above.
