LMIGuardianSvc.exe

by GoTo / LogMeIn
Remote Accessmedium risk

Sources: 300M+ executions observed in the wild.

Summary

LogMeIn Guardian Service - monitors agent health and maintains persistent connectivity to LogMeIn servers.

LMIGuardianSvc.exe is the 202nd most commonly executed Windows program in EchoTrail's dataset, observed 70,553 times across enterprise environments. It typically runs from C:\Program Files (x86)\LogMeIn\x64 and it is most often launched by LogMeIn.exe.

Get this in your tools

The same record for lmiguardiansvc.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/lmiguardiansvc.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

202nd
most commonly executed Windows program
70,553
observed endpoint executions

Behavior

Top Paths

  • C:\Program Files (x86)\LogMeIn\x6499.89%
  • C:\Users\...0.1%
  • C:\Program Files (x86)\LogMeIn Ignition0.01%

Top Hashes (SHA256)

  • ba63f94f564c3c7f3ce89b8d09bd63656f4c44d8a2c171318e1f3a1bd1f4998355.3%
  • e90b937fedbc9a23f2e29f01eb9b10113db0d25b2c7a9d92fcbb5ef920a0625125.71%
  • c86d3c3d43531db6c3e9b1e377cbf4c2d6ff181d3eb9afb472780943ac1f52c310.63%
  • a985dc7d1e0b40fd7f9968fa222254a9d1b7a8c9337af05b776f5869fc9ff6ae5.87%
  • 8073d791afc2f032d48ba2153c69654f53ff12d5d17e6d0c595425cda78f254f2.24%
  • 1af8bcd673f56d2c064906b67c6bf10a181ee960d0ac0f7420ad06521f3deea20.1%
  • b2cf609c766b857292eabdffe9e5a43a78eec89e19d802975754e0ed2c3be2460.09%
  • 52e3f9a07b35b23910763e7ea76fe476632c828b3dd747b87fa1e2f0921295c70.03%
  • 5aaca87020e9ef0435536ab151966c8ec054438fd26413d6cb39bb749668ffd10.02%
  • ca1fa6006c88fafb2900fabc71fa5e1f06444666f08fc0aae336f6a5f9305e950.01%

Process Ancestry

Top Grandparents

Top Parents

Security Analysis

What does LMIGuardianSvc.exe normally do?

Commercial remote access tool used by IT teams for remote support and administration. Maintains persistent connection to LogMeIn cloud infrastructure.

When is LMIGuardianSvc.exe suspicious?

Installation on systems not managed by IT. Running in environments that use a different remote access solution. Newly installed without IT approval.

How do attackers abuse LMIGuardianSvc.exe?

Remote access tools like LogMeIn can be installed by attackers as a persistent backdoor. Verify installations are authorized by IT.

Detection guidance

Maintain an inventory of authorized remote access tools. Alert on new LogMeIn installations.

False positive notes

Legitimate in organizations using LogMeIn for remote support.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about LMIGuardianSvc.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for LMIGuardianSvc.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.