Free passive scan

Free Open Ports Scan (Non-Intrusive)

Free tool

Opens TCP connections to 38 database, admin and service ports (RDP, VNC, MySQL, Postgres, Redis, Mongo, Docker) on your host. No exploitation, results in about a minute.

  • TCP connect check
  • Database and admin ports
  • No exploitation
No credit card requiredRead-only, no exploitationNo setup or code required
Used by 5,000+ developers and engineering teams
Oracle logoShopify logoGoDaddy logoChubb logoToshiba logoMAPFRE logoBelfius logoHolcim logo

A scan shows the surface. A pentest tests what gets in.

Passive scan

  • Reads what your app already exposes
  • Never logs in or submits a form
  • Cannot confirm what is exploitable

Active AI pentest

  • Tests your app the way an attacker would
  • Chains requests to confirm real exploits
  • Replays findings against your live app
  • Runs on a schedule or on demand, retests free

Probes for

  • SQL injection
  • Broken access control
  • IDOR
  • SSRF
  • Business-logic abuse

How AI pentesting works

Paid in credits. Free retests of found issues, and expert review from Standard up.

Security Risks of Open Ports

Attack Surface Expansion:
  • Increases potential entry points for attackers
  • Exposes services that may have vulnerabilities
  • Provides reconnaissance information to attackers
  • Enables service-specific attack techniques
Common Vulnerabilities:
  • Service identification and version detection
  • Outdated software versions with known exploits
  • Misconfigured services and unnecessary features
  • Unencrypted data transmission and storage
Compliance & Regulatory Issues:
  • Violates security best practices and standards
  • May breach compliance requirements (PCI DSS, HIPAA)
  • Increases audit findings and remediation costs
  • Demonstrates poor security posture to stakeholders

How to reduce exposure

Priority-Based Remediation:
  • Address Critical and High-risk ports first
  • Follow port-specific security recommendations
  • Use risk categorization to prioritize fixes
  • Implement dynamic scoring to track improvements
Network Security Controls:
  • Implement firewall rules to block unnecessary ports
  • Use network segmentation and VLAN isolation
  • Configure load balancers and reverse proxies
  • Implement IP whitelisting and access controls
Service Hardening:
  • Disable unused services and unnecessary features
  • Update software to latest secure versions
  • Configure strong authentication and access controls
  • Implement encryption for data in transit and at rest

What this scan checks

Ports checked (38):
  • Remote access and directory (3389 RDP, 5900 VNC, 23 Telnet, 389 LDAP)
  • Databases and caches (3306, 5432, 1433, 1521, 6379, 11211, 27017, 27018, 5984, 9042, 7687, 8086)
  • Mail and file sharing (110, 143, 21, 445, 2049, 873)
  • Containers and orchestration (2375 Docker, 2379/2380 etcd, 6443 Kubernetes, 5985 WinRM, 8500 Consul)
  • Search, queues and admin UIs (9200, 9300, 5601, 8983, 5672, 15672, 1883, 7000, 7001, 8888)
Risk Assessment & Categorization:
  • 2-tier risk categorization (critical and high-risk ports)
  • Score deduction per open port, weighted by tier
  • Port-specific security recommendations
  • Attack surface mapping with risk prioritization
Network Exposure Analysis:
  • TCP connect check from outside your network, on the target host only
  • No banner grabbing or exploitation
  • Security recommendations for each exposed service

Across 1,095 recent network scans, 43.6% have at least one externally-reachable port that should be closed.

Implementation examples

Once you've identified the gap, applying the fix is straightforward. Here are the three configurations developers reach for most often to close an unwanted port.

Linux host firewall (ufw)

# Default-deny inbound, allow only what you need
sudo ufw default deny incoming
sudo ufw default allow outgoing

# Public web traffic
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

# SSH only from a trusted admin range
sudo ufw allow from 203.0.113.0/24 to any port 22 proto tcp

# Explicitly close a previously exposed database port
sudo ufw deny 3306/tcp
sudo ufw enable

AWS Security Group (Terraform)

resource "aws_security_group" "web" {
  name        = "web-sg"
  description = "Public web only; admin scoped to office IP"
  vpc_id      = var.vpc_id

  ingress {
    from_port   = 443
    to_port     = 443
    protocol    = "tcp"
    cidr_blocks = ["0.0.0.0/0"]
  }

  ingress {
    from_port   = 22
    to_port     = 22
    protocol    = "tcp"
    cidr_blocks = ["203.0.113.10/32"]
  }

  egress {
    from_port   = 0
    to_port     = 0
    protocol    = "-1"
    cidr_blocks = ["0.0.0.0/0"]
  }
}

GCP firewall rule (gcloud)

# Allow only HTTPS from anywhere
gcloud compute firewall-rules create allow-https \
  --network=default \
  --direction=INGRESS \
  --action=ALLOW \
  --rules=tcp:443 \
  --source-ranges=0.0.0.0/0

# Restrict SSH to a known admin CIDR
gcloud compute firewall-rules create allow-ssh-admin \
  --network=default \
  --direction=INGRESS \
  --action=ALLOW \
  --rules=tcp:22 \
  --source-ranges=203.0.113.0/24

# Deny direct access to the database tier
gcloud compute firewall-rules create deny-db-public \
  --network=default \
  --direction=INGRESS \
  --action=DENY \
  --rules=tcp:3306,tcp:5432,tcp:6379,tcp:27017 \
  --source-ranges=0.0.0.0/0

Tool-specific questions

Is this port scan intrusive or harmful?

No, our port scan is completely non-intrusive and safe. We only perform lightweight connection attempts to common ports and never attempt to exploit vulnerabilities, brute-force credentials, or stress test services. The scan is designed to be respectful of your infrastructure.

Why do some ports appear open intermittently?

Port accessibility can vary due to CDN configurations, WAF rules, autoscaling, load balancing, or network routing changes. This is normal behavior in dynamic cloud environments. Regular monitoring helps track these changes over time.

Which ports are most commonly targeted by attackers?

Attackers frequently target SSH (22), RDP (3389), MySQL (3306), PostgreSQL (5432), Redis (6379), MongoDB (27017), and Oracle (1521). Our scan checks 38 database, admin and service ports, including all of these except SSH, and sorts them into two risk tiers to help you prioritize.

What's the difference between open and filtered ports?

Open ports accept connections, while filtered ports are blocked by firewalls or other security controls. Filtered ports are generally more secure as they prevent external access. This scan reports a port as open only when a TCP connection succeeds, so closed and filtered ports both show as not open.

How often should I scan for open ports?

Regular port scanning is essential, especially after infrastructure changes, deployments, or security updates. Use Barrion's continuous monitoring to track port changes over time and receive alerts when new services become accessible externally.

What should I do if I find unexpected open ports?

Investigate immediately to determine if the service is legitimate and necessary. If not needed, close the port or restrict access. If required, ensure it's properly secured with strong authentication, encryption, and access controls. Document all findings and remediation steps.

Can I use this scan for compliance auditing?

Yes, our port scan results can help with compliance auditing by identifying external service exposure. However, supplement with internal scans and comprehensive security assessments for complete compliance coverage. Document all findings for audit purposes.

What's the best way to secure database ports?

Never expose database ports directly to the internet. Use VPN access, bastion hosts, or application-level connections. Implement strong authentication, encryption, network segmentation, and regular security updates. Monitor all database access and implement least privilege principles.

How does the risk categorization system work?

Our scan sorts open ports into two tiers. Critical ports (databases, caches, container and orchestration APIs) fail the check at high severity. High-risk ports (RDP, VNC, LDAP, rsync) fail it at medium severity. The score drops for each open port, so you can track improvements over time.
Why Barrion

Built for the engineers who already have enough to fix.

Speed

Fast results

Instant analysis with a detailed report. You see findings as the scan runs, not after.
Coverage

Comprehensive checks

The full passive scan runs 18 checks on the free plan, covering TLS, headers and cookies. Paid plans run 35+ and add CORS, DNS, email auth and more.
Action

Step-by-step fixes

Every finding ships with the exact remediation step for your framework. Hand it to the engineer who owns the surface.
FAQ

Frequently asked.

What is Barrion?
Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden. A free passive scan is the quickest way to start.
How safe is Barrion to use for security testing?
AI pentests send real test requests, so they're rate-limited and non-destructive, and you approve the exact scope before a single request goes out. You can point them at staging too. The free passive scan only reads your live app. It never submits forms, brute-forces endpoints or touches anything that changes state, so it's safe to run against production.
What types of security issues does Barrion identify?
AI pentests look for the issues an attacker could exploit, like SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity. The passive scan catches misconfigurations in TLS and HTTPS, security headers, cookie flags, CORS policy, DNS records, email authentication (SPF, DKIM, DMARC) and network exposure.
What specific security checks does Barrion perform?
Barrion covers two surfaces. AI pentesting is the active part: specialist agents chain requests to find exploitable flaws such as SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. The passive scan is read-only and safe to point at production. On paid plans it runs 35+ checks (18 on the free plan): transport security (HTTPS, HSTS, TLS version, cipher suites, certificate expiry, hostname and chain validity, OCSP stapling), HTTP response headers (Referrer-Policy, Permissions-Policy, X-Content-Type-Options, Content-Type, server information disclosure), CSP and framing (Content-Security-Policy, bypass detection, Trusted Types, X-Frame-Options), cross-origin policy (COOP, COEP, CORP and the full CORS header set), cookie flags and anti-CSRF tokens, mixed content, vulnerable JavaScript libraries, DNS records including DNSSEC and CAA, email authentication (SPF, DKIM, DMARC), open ports and subdomain takeover. Findings from both are ranked by severity and come with step-by-step remediation.
Will my auditor or enterprise customers accept the pentest report?
The report maps every finding to OWASP WSTG, a security engineer reviews it from Standard up and signs it off from Deep up, and a free retest shows what you fixed. Teams use it as evidence for SOC 2, ISO 27001 and NIS2 work. Whether it's accepted is up to your auditor.
How often does Barrion test my app?
Continuously or on demand. On the Business plan you save a pentest and it reruns daily, weekly, monthly, quarterly, every six months, yearly or on your own rhythm. On any plan you can start a pentest or a passive scan on demand. A passive scan also runs on a schedule and alerts you when something new shows up.
Is Barrion suitable for security testing of all business sizes?
Yes. Solo developers often start with the free passive scan and a single pentest. Teams with several apps run pentests on a schedule, and it fits alongside the tools you already run.
How does Barrion handle data security and privacy during security testing?
Passive scans are read-only: they only look at what your app already exposes publicly. For AI pentests we keep the findings in your report, and confirmed findings include the request and response behind them, so you can review and reproduce them. Test credentials you add are encrypted. Barrion is hosted in Sweden, data is stored in the EU and AI processing runs in the EU. Our trust page lists every subprocessor. Pentests are rate-limited and only run inside the scope you approve.
What if I'm not satisfied with Barrion's security testing service?
You can cancel anytime in the dashboard, and paid plans carry a 14-day refund window from the first charge. If something isn't right, contact us and we'll make it work for your team.
How does Barrion help with SOC 2, ISO 27001, NIS2, and other compliance frameworks?
Barrion's pentest reports come as PDF, XLSX and JSON, mapped to all 97 OWASP WSTG test cases, with engineer review from Standard up, sign-off from Deep up and a free retest after fixes. Teams use them as evidence that supports SOC 2, ISO 27001, PCI DSS and NIS2 work. Whether a report is accepted is up to your auditor or customer.

Anything else? Email contact@barrion.io.

Keep it covered

Fix it once, then watch it stay fixed.

A pentest shows what is exploitable today. A scheduled passive scan re-checks this tool's results and alerts you when a deploy undoes the fix.

What you get for free

18 core security checks via this tool, passive scans, step-by-step remediation, security score on every result.

What Essential adds from €199/mo

Pentest credits every month, +17 advanced checks, weekly passive scans, email alerts and audit-ready PDFs for SOC 2 / ISO 27001 / PCI.