macOS: Detect MeshAgent Remote Access Execution via --meshServiceName
Alerts on macOS process executions containing --meshServiceName, indicating potential MeshAgent remote access usage.
FreeUnreviewedSigmamediumv1
macos-detect-meshagent-remote-access-execution-via-meshservicename-22c45af6
title: "macOS: Detect MeshAgent Remote Access Execution via --meshServiceName"
id: 45bfc75f-3745-4baa-a2d6-be8e90186fd0
related:
- id: 2fbbe9ff-0afc-470b-bdc0-592198339968
type: similar
- id: 22c45af6-f590-4d44-bab3-b5b2d2a2b6d9
type: derived
status: experimental
description: This rule flags process executions on macOS whose command line contains the --meshServiceName argument, indicating potential MeshAgent remote access tool usage. Attackers may rename MeshAgent to evade simpler detections, so argument-based matching helps identify active remote access configuration. It relies on process creation telemetry with the full command line for the spawned process.
references:
- https://www.huntress.com/blog/know-thy-enemy-a-novel-november-case-on-persistent-remote-access
- https://thecyberexpress.com/ukraine-hit-by-meshagent-malware-campaign/
- https://wazuh.com/blog/how-to-detect-meshagent-with-wazuh/
- https://www.security.com/threat-intelligence/medusa-ransomware-attacks
- https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_remote_access_tools_meshagent_arguments.yml
author: Norbert Jaśniewicz (AlphaSOC), Huntrule Team
date: 2025-05-19
tags:
- attack.command-and-control
- attack.t1219.002
logsource:
category: process_creation
product: macos
detection:
selection:
CommandLine|contains: --meshServiceName
condition: selection
falsepositives:
- Environments that legitimately use MeshAgent
level: medium
license: DRL-1.1
What it detects
This rule flags process executions on macOS whose command line contains the --meshServiceName argument, indicating potential MeshAgent remote access tool usage. Attackers may rename MeshAgent to evade simpler detections, so argument-based matching helps identify active remote access configuration. It relies on process creation telemetry with the full command line for the spawned process.
Known false positives
- Environments that legitimately use MeshAgent
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.