Skip to main content
Curated port reference

Port 5985: WinRM over HTTP / wsman (UDP reference coverage)

Port 5985 supports WinRM over HTTP and wsman (UDP reference coverage) across distinct transports. Review each protocol before writing firewall or monitoring policy.

5985TCP

WinRM over HTTP

Default Windows Remote Management listener over HTTP transport.

Typical use

Windows administration, Server Manager, automation and PowerShell remoting.

Traffic direction

Client to server

Security considerations

WinRM can encrypt message content after authentication, but HTTPS is preferred across weaker trust boundaries. Restrict administrators and source networks.

5985UDP

wsman (UDP reference coverage)

wsman (UDP reference coverage) is documented as a network service convention for port 5985 over UDP.

Typical use

Use this reference entry when identifying or validating systems documented to use 5985/UDP.

Traffic direction

Varies

Security considerations

Confirm the listening process and current vendor documentation before permitting traffic; a listed convention does not prove the active service or its security posture.