macOS MeshAgent Execution with Renamed Instance via --meshServiceName
Identifies macOS executions of MeshAgent instances that include --meshServiceName, indicating potential renamed remote access tooling.
FreeUnreviewedSigmahighv1
macos-meshagent-execution-with-renamed-instance-via-meshservicename-bd3b5eaa
title: macOS MeshAgent Execution with Renamed Instance via --meshServiceName
id: 4bb39182-9c28-4cac-9fb4-c81ce181e12d
related:
- id: b471f462-eb0d-4832-be35-28d94bdb4780
type: similar
- id: 22c45af6-f590-4d44-bab3-b5b2d2a2b6d9
type: derived
- id: bd3b5eaa-439d-4a42-8f35-a49f5c8a2582
type: derived
status: experimental
description: This rule flags process creation on macOS where the command line contains "--meshServiceName" and the original filename contains "meshagent". It is aimed at spotting execution of a renamed or substituted MeshAgent binary, a technique that can help an attacker evade detections and maintain remote access. The detection relies on process creation telemetry fields for the process command line and OriginalFileName values.
references:
- https://www.huntress.com/blog/know-thy-enemy-a-novel-november-case-on-persistent-remote-access
- https://thecyberexpress.com/ukraine-hit-by-meshagent-malware-campaign/
- https://wazuh.com/blog/how-to-detect-meshagent-with-wazuh/
- https://www.security.com/threat-intelligence/medusa-ransomware-attacks
- https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_remote_access_tools_renamed_meshagent_execution.yml
author: Norbert Jaśniewicz (AlphaSOC), Huntrule Team
date: 2025-05-19
tags:
- attack.command-and-control
- attack.stealth
- attack.t1219.002
- attack.t1036.003
logsource:
category: process_creation
product: macos
detection:
selection_meshagent:
- CommandLine|contains: --meshServiceName
- OriginalFileName|contains: meshagent
filter_main_legitimate:
Image|endswith:
- /meshagent
- /meshagent_osx64
condition: selection_meshagent and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags process creation on macOS where the command line contains "--meshServiceName" and the original filename contains "meshagent". It is aimed at spotting execution of a renamed or substituted MeshAgent binary, a technique that can help an attacker evade detections and maintain remote access. The detection relies on process creation telemetry fields for the process command line and OriginalFileName values.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.