Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0428 — Detection Strategy for Bind Mounts on Linux
DET0428

Detection Strategy for Bind Mounts on Linux

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1196 Analytic 1196
Linux

Abuse of bind mounts to obscure process directories. Defender perspective: detecting anomalous mount operations where a process’s /proc entry is remapped to another directory, often hiding malicious activity from native utilities (ps, top). Behavior chain includes: (1) execution of `mount` with `-o bind` or `-B` flags, (2) modification of /proc entries inconsistent with expected process lineage, and (3) subsequent anomalous activity from processes whose metadata no longer matches execution context.

auditd:SYSCALL mount system call with bind or remap flags auditd:PATH mount target path within /proc/* linux:osquery process metadata mismatch between /proc and runtime attributes
[BindMountFlags] Flags or options used in mount commands (e.g., -o bind, -B). Can vary across distributions and kernels.
[WatchedProcPaths] List of /proc paths to monitor. Tunable to reduce noise from benign bind mounts used in containers or chroot environments.
[CorrelationWindow] Timeframe to correlate bind mount creation with anomalous process or file activity.

Detected Techniques

1

Details

MITRE ID
DET0428
STIX ID
x-mitre-detection-strategy--b79f47ca-4c42-4658-ba71-a6374778eb98
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.