{"id":"T1564.013","name":"Bind Mounts","url":"https://attack.mitre.org/techniques/T1564/013","tactics":["stealth"],"platforms":["Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0428","stix_id":"x-mitre-detection-strategy--b79f47ca-4c42-4658-ba71-a6374778eb98","name":"Detection Strategy for Bind Mounts on Linux","url":"https://attack.mitre.org/detectionstrategies/DET0428","analytics":[{"id":"AN1196","stix_id":"x-mitre-analytic--d5c81e57-37c4-4393-a202-0955af560983","name":"Analytic 1196","description":"Abuse of bind mounts to obscure process directories. Defender perspective: detecting anomalous mount operations where a process’s /proc entry is remapped to another directory, often hiding malicious activity from native utilities (ps, top). Behavior chain includes: (1) execution of `mount` with `-o bind` or `-B` flags, (2) modification of /proc entries inconsistent with expected process lineage, and (3) subsequent anomalous activity from processes whose metadata no longer matches execution context.","url":"https://attack.mitre.org/detectionstrategies/DET0428#AN1196","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"mount system call with bind or remap flags","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:PATH","channel":"mount target path within /proc/*","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-path"},{"name":"linux:osquery","channel":"process metadata mismatch between /proc and runtime attributes","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"BindMountFlags","description":"Flags or options used in mount commands (e.g., -o bind, -B). Can vary across distributions and kernels."},{"field":"WatchedProcPaths","description":"List of /proc paths to monitor. Tunable to reduce noise from benign bind mounts used in containers or chroot environments."},{"field":"CorrelationWindow","description":"Timeframe to correlate bind mount creation with anomalous process or file activity."}],"live":true,"detection_strategies":["DET0428"],"techniques":["T1564.013"]}],"live":true,"version":"1.0","techniques":["T1564.013"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}