macOS TeamViewer Remote Session Launch via TeamViewer_Service Command Line

Flags macOS executions of TeamViewer Desktop with the IPC/module command line when launched by the TeamViewer service.

FreeReviewedSigma · Low · v2
Product
macos
Category
process_creation
Author
Josh Nickels, Qi Nan (SigmaHQ), DRL 1.1
Published
2024-03-11
Updated
2026-07-31

ATT&CK techniques

Initial Access → Persistence
  1. Recon

  2. Resource Dev

  3. Execution

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule matches macOS process creation where TeamViewer Desktop is launched with a specific command line while invoked from the TeamViewer_Service process context. Attackers can use TeamViewer for remote access and session establishment, so identifying this startup pattern can help surface unauthorized remote control activity. It relies on process creation telemetry including ParentImage, Image, and CommandLine fields.

Related detections9 linkedT1133 — drag to rearrange
SplashTop Network
Suspicious SoftEther VPN Hamcore Config Written to ProgramData (via file_event)
SplashTop Process
AnyDesk Network
OpenCanary RDP New Connection Attempt on Application Logtype 14001
ArcSOC.exe Creates Suspicious Script/Executable Files on Windows
FortiGate: Addition of VPN SSL Web Portal via Event Logs
FortiGate SSL VPN Settings Edited
Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation
macOS TeamViewer Remote Session Launch via TeamViewer_Service Command Line
Pivot detection · T1133 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.