macOS: Detect MeshAgent Remote Access Execution via --meshServiceName

Alerts on macOS process executions containing --meshServiceName, indicating potential MeshAgent remote access usage.

FreeUnreviewedSigmamediumv1
title: "macOS: Detect MeshAgent Remote Access Execution via --meshServiceName"
id: 45bfc75f-3745-4baa-a2d6-be8e90186fd0
related:
  - id: 2fbbe9ff-0afc-470b-bdc0-592198339968
    type: similar
  - id: 22c45af6-f590-4d44-bab3-b5b2d2a2b6d9
    type: derived
status: experimental
description: This rule flags process executions on macOS whose command line contains the --meshServiceName argument, indicating potential MeshAgent remote access tool usage. Attackers may rename MeshAgent to evade simpler detections, so argument-based matching helps identify active remote access configuration. It relies on process creation telemetry with the full command line for the spawned process.
references:
  - https://www.huntress.com/blog/know-thy-enemy-a-novel-november-case-on-persistent-remote-access
  - https://thecyberexpress.com/ukraine-hit-by-meshagent-malware-campaign/
  - https://wazuh.com/blog/how-to-detect-meshagent-with-wazuh/
  - https://www.security.com/threat-intelligence/medusa-ransomware-attacks
  - https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_remote_access_tools_meshagent_arguments.yml
author: Norbert Jaśniewicz (AlphaSOC), Huntrule Team
date: 2025-05-19
tags:
  - attack.command-and-control
  - attack.t1219.002
logsource:
  category: process_creation
  product: macos
detection:
  selection:
    CommandLine|contains: --meshServiceName
  condition: selection
falsepositives:
  - Environments that legitimately use MeshAgent
level: medium
license: DRL-1.1

What it detects

This rule flags process executions on macOS whose command line contains the --meshServiceName argument, indicating potential MeshAgent remote access tool usage. Attackers may rename MeshAgent to evade simpler detections, so argument-based matching helps identify active remote access configuration. It relies on process creation telemetry with the full command line for the spawned process.

Known false positives

  • Environments that legitimately use MeshAgent

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.