Skip to content

Commit

Permalink
Refactor MeshCentral detection description
Browse files Browse the repository at this point in the history
  • Loading branch information
tsale committed Sep 21, 2024
1 parent dc951b2 commit df55dc7
Showing 1 changed file with 0 additions and 1 deletion.
1 change: 0 additions & 1 deletion yaml/meshcentral.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
Name: MeshCentral
Description: >
MeshCentral is a remote monitoring and management (RMM) tool. MeshAgent used along with MeshCentral to remotely manage computers. MeshAgent can execute commands on the target host by leveraging win-console to obscure their activities and win-dispatcher to run malicious code through IPC with child processes.
To reduce the number of false positives in environments that already use MessAgent as their remote management tool, investigations should focus on the grandparent parent command, MessAgent.exe, and focus on the child processes created as a result of the interactive suspicious commands to the target host.
Author: '@kostastsale'
Created: '2024-09-20'
LastModified: '2024-09-20'
Expand Down

0 comments on commit df55dc7

Please sign in to comment.