Skip to content

9. Open Ports and the Ports List

The Ports page mirrors the Software page. The Ports tab shows the open ports your scans discovered; the Ports List tab is your own record of which ports are meant to be open, and which application owns each one. If you have read chapter 8, this will feel familiar — the differences are noted as they come up.

Only genuinely open ports are counted, from the scanner’s port-discovery plugins. The tab has two controls above the grid.

A dropdown labelled Group by: with three choices, each producing a different set of columns.

`Per host : port` — one row per host and port. The most detailed view.

Column What it shows
Host IP, Hostname, OS The machine.
Port The open port number.
Protocol tcp or udp.
Service The service the scanner attributed to the port — www, ssh and so on.
Listener Only with Show listener on: the process actually listening on that port.

`Aggregate by port` — one row per port. This is the view for “who has 3389 open?”

Column What it shows
Port, Protocol, Service The port.
Host Count How many machines expose it.
Listeners With Show listener on: the distinct listening processes across those machines. Placed before the host lists so it is visible without scrolling.
Hostnames, Host IPs Which machines expose it.

`Aggregate by host` — one row per machine. This is the view for “what is this server exposing?”

Column What it shows
Hostname, Host IP, OS The machine.
Port Count How many distinct ports it has open.
Ports The port numbers, in ascending order.
Protocols, Services The distinct protocols and services seen on it.
Listeners With Show listener on: the distinct listening processes on it.

The Show listener switch adds the listener column to whichever view you are in. Listener information comes from the operating-system enumeration plugins and, like software enumeration, requires a credentialed scan.

Clicking a row opens a details panel headed with the host and port, using the standard panel controls from section 2.5 — the field search, ⌃ and ⌄, Copy and the ⋮ field chooser.

Your own list of expected ports. The file controls are the same as the Software List’s: New (suggesting ports-list.json), Load…, a recent-files dropdown, Auto-load on startup and Use Baseline. Section 8.2 describes them; everything there applies here.

A status line beside the buttons tells you what is loaded and what just happened — for example ports-list.json — 42 port(s) (auto-saves), or No list loaded — click New or Load. Appendix B lists every message.

As with software, NESSviewer counts the differences between your list and the scans and offers them for review. Ports are matched on the combination of protocol, port and service.

Control What it does
Add from Scan Review ports the scans found that are not on your list. Tooltip: Review and add ports found in the loaded scans that aren’t on the list.
Remove from Scan Review scan-identified list entries the current scans no longer see. Tooltip: Review and mark scan-identified ports removed when they’re no longer in the loaded scans (manual entries are never flagged).
Add Row Adds a blank entry dated today and opens the editor. Tooltip: Add a blank port entry to edit.

The same amber flags appear when there is something to review: ⚠ {n} scanned port(s) not on the list — Add and ⚠ {n} list port(s) not in the loaded scans — Remove. Clicking either opens the review dialog.

The dialog is titled Add Ports or Remove Ports. Each candidate is listed as 443/tcp with the service — or service · application — on the right. Everything starts ticked; Select All, Select None, the {n} of {total} selected counter and the Apply ({n}) / Cancel buttons work exactly as described in section 8.3.

Column What it holds
Application The application or process that owns the port. This is the column that makes the list useful — a port with no owner is a question, not a record.
Protocol TCP or UDP.
Service The service name.
Ports The port number or numbers for this entry.
Comments Free text — why it is open, who approved it, which ticket.
From Scan Read-only. Ticked when the entry came from a scan.
Date Added / Date Removed When the entry was added, and when it was marked removed.

Clicking a row opens the editor panel, headed Edit Port Entry, with Application, Protocol, Service, Ports and Comments as editable fields, plus read-only Identified by scan, Date Added and Date Removed. The Application field carries the hint The owning application/process. Leave blank to fill in later.

The same three buttons appear at the bottom: Mark Removed, Restore and Delete from list, behaving exactly as in section 8.4.

Tick several rows and use the toolbar’s Update or Remove.

`Update` opens a dialog titled Update Ports with the subtitle {n} selected, offering Application, Protocol (a dropdown of TCP and UDP), Service, Ports and Comments. Only the fields you set are written. The status then reads Updated {n} item(s).

`Remove` permanently deletes the selected rows, after the same confirmation dialog described in section 8.5.

Saving works exactly as it does for the software list: there is no Save button, and every change writes itself to your file — or to the baseline — shortly after you stop editing.