Suspicious MeshAgent Spawning Command Interpreter (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-03
Updated
2026-10-03

ATT&CK techniques

Persistence → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. Exfiltration

  11. Impact

What it detects

This rule detects the MeshAgent remote management binary spawning a command interpreter or scheduling utility such as PowerShell, cmd or schtasks. Adversaries abusing MeshCentral use the agent to execute follow-on commands and establish persistence, so an interpreter child under MeshAgent indicates hands-on-keyboard misuse of the RMM tool.

Related detections9 linkedT1219 — drag to rearrange
Suspicious Velociraptor DFIR Agent Spawning Encoded PowerShell
Suspicious RustDesk Remote Access Service Installation via sc (via process_creation)
Suspicious TightVNC Server Installation as a Service
Suspicious AnyDesk Execution from Temporary or System Directory (via process_creation)
Suspicious AnyDesk Unattended Access Password Set via Command Line (via process_creation)
Suspicious Kernel Driver Written to AppData Temp Linked to RansomHub EDR Killers
Suspicious PowerShell Spawned by Komari Monitoring Agent
Malicious Command Shell Spawned by Bomgar Remote Support Client
Suspicious Winpty Agent Spawned by Net Monitor Employee Monitoring Process
Suspicious MeshAgent Spawning Command Interpreter (via process_creation)
Pivot detection · T1219 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.