Enumerating these tools identifies which product is present and its version, which drives both the authentication attack and the product-exploit choice. Detection is by the characteristic ports the clients use, TeamViewer on TCP 5938 (falling back to 443/80), AnyDesk on 7070, Splashtop and others on their own, and by the vendor relay traffic, plus client artefacts (processes, installed files, registry) on a host you can inspect. Version detection then matters because these products patch frequently and many attacks (brute-force feasibility, specific exploits) are version-dependent.
nmap -p5938,7070,6568,443 -sV <target> # TeamViewer, AnyDesk, Splashtop, relay
# on a host: identify the client and version from processes/installed files
tasklist | findstr /i 'teamviewer anydesk splashtop' # Windows
Subtopics#
- Service detection: identifying the product by port and traffic.
- Version detection: determining the client version.