"Moving to E5 has been really good from a security point of view... Now we can get a holistic view of what’s going on, which helps us to make changes and recommendations for future plans."
IT Service Manager
Ian Harkess
Trusted by industry leaders
Kickstart Your FastTrack Journey
Fill out the short form below to express your interest in our FastTrack programme, and we’ll be in touch soon.
Please note: A minimum of 150 enterprise licenses is required for FastTrack eligibility.
“We needed to find solutions to a variety of issues whilst being a complex business, operating in a 24/7 environment. Stripe OLT listened and understood immediately the challenges we faced.”
IT Operations Manager
Simon Darley
Trusted by industry leaders
Let's Talk
Call us on one of the numbers below, we cover the whole of the UK, so call the nearest office.
“We needed to find solutions to a variety of issues whilst being a complex business, operating in a 24/7 environment. Stripe OLT listened and understood immediately the challenges we faced.”
Don't Get Meshed Up: Understanding Mesh VPN Abuse in Modern Attacks
Published: August 21, 2026
Updated: August 25, 2026
Expert:Sebastian Lacatusu
Role:Security Analyst
Specialises in: Security Operations
What you will learn:
Mesh VPN solutions such as Tailscale are trusted technologies used to securely connect devices and services. As attackers increasingly adopt legitimate tools to blend into normal business activity, traditional detection methods become less effective. This intel explores why mesh VPN abuse presents a challenge for defenders and the key behavioural indicators security teams can use to improve detection.
“The challenge isn't detecting malicious software. It's detecting when legitimate software is being used for malicious purposes.”
Remote access technologies have become a staple of modern business operations, enabling secure connectivity for distributed workforces and third-party suppliers. But as cyber defenders have learnt time and time again, threat actors are often quick to adopt the same legitimate tools organisations rely on every day.
One technology increasingly appearing on defenders’ radar is the mesh VPN.
Platforms such as Tailscale have grown in popularity because they offer secure, encrypted connectivity between devices without the complexity of traditional VPN infrastructure. They are trusted, widely deployed, and designed to make remote access simple.
Unfortunately, those same advantages can also make them attractive to attackers.
When Legitimate Tools Become a Security Challenge
It is important to be clear: Tailscale itself is not malicious, rather just an example used to explore the capabilities and behaviour of the wider mesh VPN market.
The platform is a legitimate VPN solution used by organisations and individuals worldwide to securely connect systems and services. The challenge for defenders is not the software itself, but how it can potentially be abused after a system has been compromised.
Once an attacker gains access to an environment, deploying a trusted remote access tool can provide a discreet method of maintaining persistence and communicating with compromised systems. Because the software is legitimate, signed, and commonly used, it may not immediately raise the same alarms as traditional command-and-control infrastructure.
This reflects a wider trend seen across the threat landscape, where adversaries increasingly “live off the land” by using trusted applications and services instead of bespoke malware.
Why Traditional Detection Approaches Fall Short
Historically, many security controls have relied heavily on threat intelligence indicators such as malicious domains, IP addresses, or known malware signatures.
Mesh VPN solutions present a different challenge.
Unlike conventional command-and-control infrastructure, the traffic generated by these platforms often leverages legitimate vendor-owned services and trusted network infrastructure. In the case of Tailscale, communications occur through genuine Tailscale services and use legitimate VPN functionality.
As a result, blocking or detecting activity simply through threat intelligence feeds is unlikely to be effective.
Instead, defenders need to focus on something more fundamental: how the software operates on a system.
Caption:When attackers use trusted tools, reputation-based detection becomes less effective. Defenders must focus on behavioural indicators such as DNS changes, hosts file modifications, CGNAT traffic, and .ts.net activity.
Looking Beyond the Application
Our threat research found that detecting potential mesh VPN abuse is less about identifying the application itself and more about identifying the system and network changes that occur when it is installed and used.
These changes are publicly documented, consistent across deployments, and offer reliable opportunities for detection and monitoring.
Importantly, these behaviours are not unique to Tailscale. Most mesh VPN platforms rely on similar DNS, routing, and networking techniques to establish connections and navigate NAT environments. This means the detection principles outlined in this research can remain effective across a range of mesh VPN solutions, helping defenders focus on behaviour rather than a specific product.
Key indicators include:
Changes to Windows Name Resolution Policy Table (NRPT) settings.
Creation or modification of entries within the Windows hosts file.
Network traffic involving the Carrier Grade NAT (CGNAT) address range commonly used by mesh VPN platforms.
DNS activity associated with the .ts.net domain suffix.
Individually, these indicators do not confirm malicious activity. Many organisations may have entirely legitimate deployments of Tailscale within their environment.
However, when viewed in the context of security monitoring, they provide valuable visibility into where the technology is being used and whether that usage aligns with approved business activity.
Hosted or Self-Hosted: The Security Considerations Remain the Same
Our technical research found that defenders should approach Tailscale and Headscale in much the same way.
Although Headscale is self-hosted and Tailscale is provided as a managed service, the underlying technology and endpoint behaviour are nearly identical. The same DNS changes, routing behaviour, and network artefacts are generated, meaning the same detection and monitoring techniques remain effective.
The biggest difference is who controls the logs. In a Tailscale deployment, logging data sits with the service provider. In a Headscale deployment, those logs are controlled directly by the operator running the platform. Outside of investigations or legal proceedings, that distinction has little practical impact on day-to-day threat detection.
For security teams, the important point is that the same visibility and detection opportunities exist regardless of which platform is being used.
Practical Guidance for Security Teams
The good news is that mesh VPN usage leaves observable artefacts that can be incorporated into existing monitoring strategies.
Defenders should consider:
Monitoring for changes to Windows DNS policy settings.
Tracking unexpected modifications to hosts files.
Looking for usage of CGNAT address ranges associated with mesh networking.
Monitoring for .ts.net domain activity within DNS telemetry.
Investigating unapproved deployments of remote access software as part of shadow IT programmes.
These activities can help identify not only potential malicious use, but also legitimate deployments that may have bypassed established security and change management processes.
Research-Driven Detection Opportunities
A key objective of our research was to move beyond theory and provide practical detection guidance that security teams can apply immediately.
The full research includes example hunting rules, detection logic, and technical artefacts that can assist defenders in identifying evidence of Tailscale and Headscale deployments across both Windows and Linux environments.
Understanding how legitimate tools can be abused is only part of the challenge. Having the visibility, expertise, and monitoring capabilities to detect that activity in practice is what makes the difference.
This website uses cookies. By using this site you agree to our use of cookies. We use cookies to enhance your experience. To understand the specific cookies we use and how we handle your data, see out Cookie Policy, Privacy Policy and Terms & Conditions. Manage your preferences at any time by clicking the 'View Preferences' button.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.