Windows RMM Tool MeshAgent Execution with Renamed MeshServiceName

Identifies renamed MeshAgent executions on Windows by matching --meshServiceName with OriginalFileName containing meshagent.

FreeUnreviewedSigmahighv1
title: Windows RMM Tool MeshAgent Execution with Renamed MeshServiceName
id: ec320da2-e6a3-4774-bea9-0c76987265e3
related:
  - id: bd3b5eaa-439d-4a42-8f35-a49f5c8a2582
    type: similar
  - id: 2fbbe9ff-0afc-470b-bdc0-592198339968
    type: derived
  - id: b471f462-eb0d-4832-be35-28d94bdb4780
    type: derived
status: experimental
description: This rule flags process creation on Windows where the command line contains --meshServiceName and the process has an OriginalFileName containing meshagent. Attackers may rename or disguise RMM components like MeshAgent to evade defenses while still executing the same underlying service mechanism. The detection relies on Windows process creation telemetry fields for CommandLine, OriginalFileName, and Image.
references:
  - https://www.huntress.com/blog/know-thy-enemy-a-novel-november-case-on-persistent-remote-access
  - https://thecyberexpress.com/ukraine-hit-by-meshagent-malware-campaign/
  - https://wazuh.com/blog/how-to-detect-meshagent-with-wazuh/
  - https://www.security.com/threat-intelligence/medusa-ransomware-attacks
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_remote_access_tools_renamed_meshagent_execution.yml
author: Norbert Jaśniewicz (AlphaSOC), Huntrule Team
date: 2025-05-19
tags:
  - attack.command-and-control
  - attack.stealth
  - attack.t1219.002
  - attack.t1036.003
logsource:
  category: process_creation
  product: windows
detection:
  selection_meshagent:
    - CommandLine|contains: --meshServiceName
    - OriginalFileName|contains: meshagent
  filter_main_legitimate:
    Image|endswith: \meshagent.exe
  condition: selection_meshagent and not 1 of filter_main_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule flags process creation on Windows where the command line contains --meshServiceName and the process has an OriginalFileName containing meshagent. Attackers may rename or disguise RMM components like MeshAgent to evade defenses while still executing the same underlying service mechanism. The detection relies on Windows process creation telemetry fields for CommandLine, OriginalFileName, and Image.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.