Linux mount executed with hidepid=2 option

Flags Linux mounts that include hidepid=2, a stealth configuration that hides processes from other users.

FreeReviewedSigma · Medium · v2
Product
linux
Category
process_creation
Author
Joseliyo Sanchez, @Joseliyo_Jstnk (SigmaHQ), DRL 1.1
Published
2023-01-12
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies process creation where the command executed is mount and the command line includes the hidepid=2 option with an output mount argument (" -o "). Attackers can use hidepid to reduce visibility of processes to other users, supporting stealth and defense evasion. Detection relies on Linux process creation telemetry including the executable path and full command line.

Related detections9 linkedT1564 — drag to rearrange
Suspicious Windows Security Spoofing via pin Executable Writing output.txt via process_creation
Obfuscated Extended Rights Backdoor Obfuscation - Via localizationDisplayId Attribute (via security)
Suspicious Process Execution from Public User Media Folders via process_creation
Suspicious Windows Sandbox Configuration Execution for AsyncRAT via Process Creation
System Informer Execution on Windows Process Creation
Windows Process Hacker Execution Identified by Image Metadata and Hashes
Windows File Events: Suspicious Executable File Name Creation
Windows: Suspicious Parent Process Execution From \Users\Public Spawning Scripting/Shell Binaries
Windows Registry: Disable CrashDump via CrashControl DWORD value
Linux mount executed with hidepid=2 option
Pivot detection · T1564 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.