Windows MeshAgent Remote Access Tool Command Line Execution Indicators

Flags Windows processes invoking MeshAgent with --meshServiceName, indicating potential remote access tool execution.

FreeUnreviewedSigmamediumv1
title: Windows MeshAgent Remote Access Tool Command Line Execution Indicators
id: 05f5fa5a-dc01-493c-9772-b6c8189dc4ae
related:
  - id: 22c45af6-f590-4d44-bab3-b5b2d2a2b6d9
    type: similar
  - id: 2fbbe9ff-0afc-470b-bdc0-592198339968
    type: derived
status: experimental
description: This rule flags Windows process creation where the command line contains the MeshAgent-specific argument "--meshServiceName". Attackers may use MeshAgent for persistent remote access and may rename binaries to avoid simple name-based detections, so command-line usage is used as the indicator. It relies on process creation telemetry that includes the full command line.
references:
  - https://www.huntress.com/blog/know-thy-enemy-a-novel-november-case-on-persistent-remote-access
  - https://thecyberexpress.com/ukraine-hit-by-meshagent-malware-campaign/
  - https://wazuh.com/blog/how-to-detect-meshagent-with-wazuh/
  - https://www.security.com/threat-intelligence/medusa-ransomware-attacks
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_remote_access_tools_meshagent_arguments.yml
author: Norbert Jaśniewicz (AlphaSOC), Huntrule Team
date: 2025-05-19
tags:
  - attack.command-and-control
  - attack.t1219.002
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains: --meshServiceName
  condition: selection
falsepositives:
  - Environments that legitimately use MeshAgent
level: medium
license: DRL-1.1

What it detects

This rule flags Windows process creation where the command line contains the MeshAgent-specific argument "--meshServiceName". Attackers may use MeshAgent for persistent remote access and may rename binaries to avoid simple name-based detections, so command-line usage is used as the indicator. It relies on process creation telemetry that includes the full command line.

Known false positives

  • Environments that legitimately use MeshAgent

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.