Suspicious Root Filesystem Remount as Writable on Appliance via Mount (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-06-27
Updated
2026-08-28

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the mount command remounting the root filesystem as read-write on Linux-based appliances. Actors exploiting Ivanti Connect Secure zero-days remounted the normally read-only appliance filesystem to tamper with installers and plant webshells. Making a hardened appliance root writable is an abnormal precursor to persistence and integrity tampering.

Related detections8 linkedT1554 — drag to rearrange
Malicious Backdoored liblzma XZ Utils Library File via file_event
Malicious Backdoored liblzma Loaded by sshd (CVE-2024-3094)
Windows TanStack Supply-Chain File Creation Indicators via router_init.js and router_runtime.js
Linux setcap sets cap_setgid on binaries (Setgid capability assignment)
Linux setcap sets cap_setuid on a binary via setcap utility
Windows Security Event 4697: HybridConnectionManager Service Installation
Azure Hybrid Connection Manager DNS Queries for servicebus.windows.net (Windows)
Windows Hybrid Connection Manager Service Activity (Event IDs 40300-40302)
Suspicious Root Filesystem Remount as Writable on Appliance via Mount (via process_creation)
Pivot detection · T1554 · 8 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.