Ports·5985
5985
winrm
TCP · 0x1761

Port 5985 — winrm

Remote access

Port 5985 carries WinRM HTTP over TCP. Above 1023, so an ordinary user can open it. Its encrypted twin is 5986.

1024–49151. Meant to be applied for, though some numbers here are custom by habit.

Where it sits in 65535

A port number is 16 bits, so it stops at 65535. The narrow band at the left is everything up to 1023.

065535
Service
WinRM HTTP (winrm)
Kind
Remote access
Protocol
TCP
Range
Registered
Root needed
No
Hexadecimal
0x1761
Binary
0001011101100001
Two bytes
23 · 97
Encrypted twin
5986

Same kind

Running commands or watching a screen on someone else’s machine.

Ports next to it

How to read this

  • A port number is 16 bits, so it runs 0 to 65535. There is no port 65536.
  • Opening anything at or below 1023 needs root on Unix.
  • Plain and encrypted often live on different numbers — 80 and 443, for one.
  • Numbers like 3000 and 8080 were never registered; those are marked as custom.

Frequently asked questions

Q. What is port 5985 used for?

WinRM HTTP (winrm) uses it, over TCP.

Q. Does opening port 5985 need root?

No. It is above 1023, so an ordinary user can open it.

Q. Which range does port 5985 fall in?

Registered (1024–49151). In hex it is 0x1761.

Q. Is there an encrypted version of port 5985?

Port 5986 does the same thing wrapped in TLS.