{"id":8949,"date":"2025-06-10T02:24:49","date_gmt":"2025-06-10T02:24:49","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=8949"},"modified":"2025-06-10T02:24:50","modified_gmt":"2025-06-10T02:24:50","slug":"excessive-number-of-failed-connections-from-127-0-0-1","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/excessive-number-of-failed-connections-from-127-0-0-1","title":{"rendered":"Excessive number of failed connections from 127.0.0.1"},"content":{"rendered":"\n<p>Ran the following Advanced Hunting KQL<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code class=\"\">_Im_NetworkSession(eventresult='Failure')\n| take 100<\/code><\/pre>\n\n\n\n<p>Was due to Labtech upgrades<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>SrcIpAddr<\/p>\n\n\n\n<p>127.0.0.1<em>?<\/em><\/p>\n\n\n\n<p>SrcPortNumber<\/p>\n\n\n\n<p>59615<em>?<\/em><\/p>\n\n\n\n<p>DstIpAddr<\/p>\n\n\n\n<p>127.0.0.1<em>?<\/em><\/p>\n\n\n\n<p>DstPortNumber<\/p>\n\n\n\n<p>42013<em>?<\/em><\/p>\n\n\n\n<p>SrcDvcId<\/p>\n\n\n\n<p>7<\/p>\n\n\n\n<p>SrcUsername<\/p>\n\n\n\n<p>nt authority\\system<\/p>\n\n\n\n<p>NetworkProtocol<\/p>\n\n\n\n<p>TCP<em>?<\/em><\/p>\n\n\n\n<p>EventOriginalResultDetails<\/p>\n\n\n\n<p>ConnectionFailed<\/p>\n\n\n\n<p>ASimMatchingIpAddr<\/p>\n\n\n\n<p>&#8211;<em>?<\/em><\/p>\n\n\n\n<p>SrcDvcIdType<\/p>\n\n\n\n<p>MDEid<\/p>\n\n\n\n<p>SrcUsernameType<\/p>\n\n\n\n<p>Windows<\/p>\n\n\n\n<p>EventCount<\/p>\n\n\n\n<p>1<\/p>\n\n\n\n<p>7<\/p>\n\n\n\n<p>EventSchema<\/p>\n\n\n\n<p>NetworkSession<\/p>\n\n\n\n<p>EventSchemaVersion<\/p>\n\n\n\n<p>0.2.3<\/p>\n\n\n\n<p>EventVendor<\/p>\n\n\n\n<p>Microsoft<\/p>\n\n\n\n<p>EventProduct<\/p>\n\n\n\n<p>M365 Defender for Endpoint<\/p>\n\n\n\n<p>EventType<\/p>\n\n\n\n<p>NetworkSession<\/p>\n\n\n\n<p>NetworkDirection<\/p>\n\n\n\n<p>Outbound<\/p>\n\n\n\n<p>Src<\/p>\n\n\n\n<p>127.0.0.1<\/p>\n\n\n\n<p>Dst<\/p>\n\n\n\n<p>127.0.0.1<\/p>\n\n\n\n<p>7<\/p>\n\n\n\n<p>IpAddr<\/p>\n\n\n\n<p>127.0.0.1<\/p>\n\n\n\n<p>DvcId<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>SrcAppName<\/p>\n\n\n\n<p>ltsvc.exe<\/p>\n\n\n\n<p>Type<\/p>\n\n\n\n<p>DeviceNetworkEvents<em>?<\/em><\/p>\n\n\n\n<p>SrcAppType<\/p>\n\n\n\n<p>Process<\/p>\n\n\n\n<p>DvcIdType<\/p>\n\n\n\n<p>MDEid<\/p>\n\n\n\n<p>DvcIpAddr<\/p>\n\n\n\n<p>127.0.0.1<em>?<\/em><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>User<\/p>\n\n\n\n<p>nt authority\\system<\/p>\n\n\n\n<p>ASimMatchingHostname<\/p>\n\n\n\n<p>&#8211;<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>SrcUserIdType<\/p>\n\n\n\n<p>SID<em>?<\/em><\/p>\n\n\n\n<p>TenantId<\/p>\n\n\n\n<p>InitiatingProcessAccountDomain<\/p>\n\n\n\n<p>nt authority<\/p>\n\n\n\n<p>InitiatingProcessAccountName<\/p>\n\n\n\n<p>system<\/p>\n\n\n\n<p>InitiatingProcessFolderPath<\/p>\n\n\n\n<p>c:\\windows\\ltsvc\\ltsvc.exe<\/p>\n\n\n\n<p>InitiatingProcessId<\/p>\n\n\n\n<p>19272<\/p>\n\n\n\n<p>InitiatingProcessMD5<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>ParentProcessName<\/p>\n\n\n\n<p>services.exe<\/p>\n\n\n\n<p>InitiatingProcessParentId<\/p>\n\n\n\n<p>1124<\/p>\n\n\n\n<p>InitiatingProcessSHA1<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><em>?<\/em><em>?<\/em><\/p>\n\n\n\n<p>InitiatingProcessSHA256<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><em>?<\/em><em>?<\/em><\/p>\n\n\n\n<p>InitiatingProcessFileSize<\/p>\n\n\n\n<p>1623832<\/p>\n\n\n\n<p>InitiatingProcessVersionInfoCompanyName<\/p>\n\n\n\n<p>LabTech Software<\/p>\n\n\n\n<p>InitiatingProcessVersionInfoProductName<\/p>\n\n\n\n<p>LabTech MSP<em>?<\/em><\/p>\n\n\n\n<p>InitiatingProcessVersionInfoProductVersion<\/p>\n\n\n\n<p>3.0<em>?<\/em><\/p>\n\n\n\n<p>InitiatingProcessVersionInfoInternalFileName<\/p>\n\n\n\n<p>LTSVC.exe<em>?<\/em><\/p>\n\n\n\n<p>InitiatingProcessVersionInfoOriginalFileName<\/p>\n\n\n\n<p>LTSVC.exe<em>?<\/em><\/p>\n\n\n\n<p>InitiatingProcessVersionInfoFileDescription<\/p>\n\n\n\n<p>LabTech Service<em>?<\/em><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>InitiatingProcessSessionId<\/p>\n\n\n\n<p>0<em>?<\/em><\/p>\n\n\n\n<p>IsInitiatingProcessRemoteSession<\/p>\n\n\n\n<p>false<em>?<\/em><\/p>\n\n\n\n<p>InitiatingProcessUniqueId<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>ParentProcessId<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Process<\/p>\n\n\n\n<p>ltsvc.exe<\/p>\n\n\n\n<p>SrcProcessCommandLine<\/p>\n\n\n\n<p>LTSVC.exe -sLTService -nLabTech<\/p>\n\n\n\n<p>SrcProcessName<\/p>\n\n\n\n<p>ltsvc.exe<\/p>\n\n\n\n<p>SrcProcessIntegrityLevel<\/p>\n\n\n\n<p>System<\/p>\n\n\n\n<p>SrcProcessTokenElevation<\/p>\n\n\n\n<p>TokenElevationTypeDefault<em>?<\/em><\/p>\n\n\n\n<p>SrcProcessCreationTime<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ran the following Advanced Hunting KQL Was due to Labtech upgrades SrcIpAddr 127.0.0.1? SrcPortNumber 59615? DstIpAddr 127.0.0.1? DstPortNumber 42013? SrcDvcId 7 SrcUsername nt authority\\system NetworkProtocol TCP? EventOriginalResultDetails [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-8949","post","type-post","status-publish","format-standard","hentry","category-research"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/8949","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=8949"}],"version-history":[{"count":1,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/8949\/revisions"}],"predecessor-version":[{"id":8950,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/8949\/revisions\/8950"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=8949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=8949"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=8949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}