• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    MeshAgent RMM Renamed to mvtcs.exe Deployed by Settra Ransomware

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•1

    Detects the execution of the MeshAgent remote management tool when renamed to 'mvtcs.exe'. This technique is often used by adversaries to maintain persistent remote access while evading basic file-name based detections.

    Sigma

    Tags

    T1219 - Remote Access ToolsProcess CreationRemote Access SessionWindowsWindows Sysmonattack.t1219attack.t1071.001

    Found in

    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 21 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 21 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 21 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 21 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 21 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?