MeshAgent Suspicious Child Process - Potential Malicious RMM Tool Usage

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Identifies the default installation process executing suspect applications, such as powershell, schtasks, cmd and other applications that can by abused by built in modules.

Attribute Value
Type Hunting Query
Solution Intel471
ID 749f7e2c-5eeb-407d-a5ef-cfcecbe5d810
Tactics CommandAndControl, Execution
Techniques T1059.001, T1059.003, T1219
Required Connectors SecurityEvents, WindowsSecurityEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
SecurityEvent CommandLine has_any "-kvm1"
NewProcessName has "meshagent.exe"
NewProcessName has_any "cmd.exe"
ParentProcessName has "meshagent.exe"
✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries · Back to Intel471