DEV Community

jeffrey
jeffrey

Posted on

15,307,587 on Port 5985 and 1,019,437 on Port 5986: Two Windows Remote Management Faces

15,307,587 on Port 5985 and 1,019,437 on Port 5986: Two Windows Remote Management Faces

Windows Remote Management is how modern Windows administration happens at scale. It has two transport faces, and the gap between them is the most interesting part of the measurement.

The measurement

Two ZoomEye queries executed on 25 September 2026 with sub_type=all and pagesize 1 returned the following. The query port="5985" returned 15,307,587 matches. The query port="5986" returned 1,019,437 matches.
Port 5985 is WinRM over HTTP. Port 5986 is WinRM over HTTPS. The match counts differ by roughly fifteen to one.

What the ratio describes

The ratio is not a security verdict, and treating it as one would be a mistake to avoid. A service behind a mutually authenticated segmented network is not made safer by TLS, and a service exposed to the internet is not made safe by it either.
What the ratio describes is a default. Windows enables the HTTP listener far more readily than the HTTPS listener, and the HTTPS listener requires a certificate that has to be provisioned and trusted. Deployments follow the path of least resistance, so the HTTP listener is what is present on the estate in the greatest number.
That matters because WinRM is a full remote command execution interface. Anything that can authenticate to it can run commands as the authenticated user, which in the configuration where it is used is frequently an administrator.

Reading both numbers together

The 15.3 million figure is what a raw port match looks like on a service that ships enabled. The 1.0 million figure is what a raw port match looks like on the same service when a certificate has to exist first.
Neither number tells you whether authentication is required, which authentication method is configured, or whether the listener is reachable from an untrusted network. All three of those decide the risk, and none of them is visible from a port count.
The useful external question is different: which WinRM endpoints are published beyond the administrative segment. In most estates the answer should be none, because WinRM administration belongs on an internal management path, not on the internet.

Making it actionable

Inventory the WinRM listeners that answer from outside the management network, and treat every one of them as a finding rather than a statistic. Externally reachable WinRM is a rare configuration, and where it exists it usually arrived by accident: a host that was moved, a firewall rule opened for a one-off task, a jump host that was never re-scoped.
Where WinRM is used internally, prefer the HTTPS listener with a certificate issued by the organisation's own authority, and constrain who can reach 5985 and 5986 with network policy rather than relying on credentials alone.
Finally, monitor authentication failures on those endpoints. A WinRM listener that receives a large volume of failed authentication from an unexpected source is the observable form of somebody who found the port the same way this measurement did.

References

Top comments (0)