Remote Access Tool - Potential MeshAgent Execution - MacOS (22c45af6-f590-4d44-bab3-b5b2d2a2b6d9)
Detects potential execution of MeshAgent which is a tool used for remote access. Historical data shows that threat actors rename MeshAgent binary to evade detection. Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.