Linux Mount Commands Cheat Sheet: Mount, Unmount, and Harden Filesystems Like a SOC Analyst
Picture a SOC analyst at 2 AM. A server has been flagged for suspicious outbound traffic, and the incident commander wants a copy of its data disk examined on a separate Linux workstation. The analyst plugs in the disk and types a plain mount command out of habit. Nothing visibly breaks, but the disk is now mounted read-write with executables allowed. Timestamps may have changed, and any script on that disk is one careless click away from running on the analyst's own machine. (This is an illustrative scenario, but it is a mistake that happens in real investigations.)
Mount options are one of the cheapest and most overlooked controls in Linux server hardening. This cheat sheet covers the commands you need every day: viewing mounts, mounting devices and images, working with /etc/fstab, and unmounting safely. It also shows how to apply the security options that auditors and benchmarks such as the CIS Linux benchmarks ask about.
Table of Contents
- Viewing Mounted Filesystems
- Identifying Devices by UUID and Label
- Mounting and Remounting Basics
- Security Mount Options for Endpoint Hardening
- ISO Images, Disk Images, tmpfs, and NFS
- Persistent Mounts with /etc/fstab (Safely)
- Unmounting, Busy Mount Points, and Lazy Unmount
- Detection: What Analysts Should Watch For
- Expert Tips
- FAQ
Viewing Mounted Filesystems
Before you change anything, look at the current state. Whether you are doing troubleshooting or incident response, that habit prevents most mistakes.
mount
Lists currently mounted filesystems and their mount points. On a modern system the output is long because it includes virtual filesystems such as proc, sysfs, and cgroup.
mount | column -t
Aligns the same output into columns showing device, mount point, filesystem type, and options. This is much easier to scan on a narrow terminal.
findmnt
Displays mounts as a tree, which makes it easy to spot a filesystem mounted inside another one. This is usually the better starting point than raw mount.
findmnt /mnt
findmnt -T /mnt
The first command shows what is mounted exactly at /mnt. The second shows the filesystem that contains the given path, even if the path is only a subdirectory of a mount.
findmnt -no SOURCE /mnt
findmnt -no FSTYPE /mnt
findmnt -no OPTIONS /mnt
findmnt -no TARGET /mnt
These return a single field (source device, filesystem type, active options, or target) with no header. They are ideal for scripts and quick checks.
df -h /mnt
Shows used and available space. Note that mount | column -t does not show usage. It lists devices, types, options, and mount points. Use df -h when you need capacity.
ls -ld /mnt
Shows the ownership and permissions of the mount-point directory. When a filesystem is mounted, the permissions of its own root directory apply instead, so check this before and after mounting.
Identifying Devices by UUID and Label
Device names like /dev/sdb1 can change between boots or when another disk is attached. UUIDs are stable, which is why production configurations should use them.
lsblk -f
Lists block devices with filesystem type, label, UUID, and mount point. It is also the quickest way to see whether a USB drive was detected and auto-mounted.
blkid /dev/sdb1
Prints the UUID, label, and filesystem type of one device. You may need sudo to get complete output.
sudo mount UUID=xxxx-xxxx /mnt
sudo mount LABEL=DATA /mnt
Mounts by UUID or label instead of device name. Replace xxxx-xxxx with the real value from blkid. Labels can be duplicated or set by anyone who formats a drive, so UUIDs are the more dependable choice.
Mounting and Remounting Basics
sudo mkdir -p /mnt/data
sudo mount /dev/sdb1 /mnt/data
Creates a dedicated mount point and mounts the device there. Using a named directory instead of /mnt keeps your work organized. Mounting requires elevated privileges, hence sudo.
Warning: if the directory you mount onto already contains files, they become hidden while the mount is active. They are not deleted, but they are invisible until you unmount. Always mount on an empty directory.
sudo mount -t ext4 /dev/sdb1 /mnt
Specifies the filesystem type. Usually mount detects it automatically, but being explicit helps when detection fails.
sudo mount -o ro /dev/sdb1 /mnt
sudo mount -o rw /dev/sdb1 /mnt
Mounts read-only or read-write. Use ro any time you only need to look at data.
sudo mount -o remount /mnt
sudo mount -o remount,ro /mnt
sudo mount -o remount,rw /mnt
Changes options on an already mounted filesystem without unmounting it. Remounting read-only is a handy way to freeze a filesystem quickly. It can fail if processes have files open for writing.
Security Mount Options for Endpoint Hardening
These options are where mounting becomes a security control. They restrict what a filesystem is allowed to do, regardless of what files it contains.
| Option | What it does | Typical use |
ro | Read-only access | Evidence, untrusted media |
noexec | Blocks direct execution of binaries | /tmp, /var/tmp, /dev/shm, data volumes |
nosuid | Ignores setuid/setgid bits | Anything not holding system binaries |
nodev | Ignores device files | All non-root data filesystems |
sudo mount -o noexec /dev/sdb1 /mnt
sudo mount -o nodev /dev/sdb1 /mnt
sudo mount -o nosuid /dev/sdb1 /mnt
Each command applies one restriction. noexec prevents running programs directly from the filesystem, nodev stops device files on it from being interpreted, and nosuid disables privilege-elevating bits.
sudo mount -o ro,nosuid,nodev,noexec /dev/sdb1 /mnt
This is the combination to memorize for unknown USB drives, disk copies, and anything from an untrusted source. Expected result: you can read files but cannot modify them or execute them directly.
sudo mount -o rw,noexec /dev/sdb1 /mnt
Read-write access while blocking direct execution. This is useful for upload or staging volumes where users need to write but nothing should run.
Be realistic about limits. noexec is a speed bump, not a wall. A user can still run a script by passing it to an interpreter (for example, sh script.sh), because the interpreter itself lives on an executable filesystem. Treat these options as one layer in defense in depth alongside application control and monitoring, not as a guarantee. The CIS benchmarks for common Linux distributions recommend restrictive options on temporary-file locations such as /tmp and /dev/shm, so these settings often appear in compliance audits.
ISO Images, Disk Images, tmpfs, and NFS
sudo mount -o loop,ro image.iso /mnt
Mounts an ISO through a loop device, read-only. ISO images are read-only by nature, but stating ro explicitly is good practice.
sudo mount -o loop disk.img /mnt
Mounts a filesystem image. For anything you care about preserving, add the safe options:
sudo mount -o loop,ro,nosuid,nodev,noexec disk.img /mnt
Note for forensic work: mounting some journaling filesystems read-only may still replay the journal, which can change the source. Investigators typically work on a copy of the evidence, and for ext4 may add the noload option to skip journal replay. Follow your organization's evidence-handling procedures.
sudo mount -t tmpfs tmpfs /mnt
sudo mount -t tmpfs -o size=1G tmpfs /mnt
Mounts a memory-backed filesystem, optionally capped at 1 GB. Contents disappear on unmount or reboot. Attackers also like tmpfs because files leave little trace on disk, which is another reason to monitor for unexpected tmpfs mounts.
sudo mount -t nfs server:/share /mnt
Mounts an NFS network share. For shares you do not fully control, add nosuid,nodev,noexec. Replace server:/share with your actual export.
Persistent Mounts with /etc/fstab (Safely)
A bad /etc/fstab entry can drop a server into emergency mode at boot, which is why a few habits matter here.
cat /etc/fstab
Displays the persistent mount configuration.
sudo cp /etc/fstab /etc/fstab.bak
Always back up before editing. It takes one second and can save an outage.
An example entry using a UUID, security options, and nofail so a missing disk does not block boot:
UUID=xxxx-xxxx /mnt/data ext4 defaults,nofail,nodev,nosuid,noexec 0 2
sudo mount -a
sudo mount /mnt/data
The first command mounts everything in fstab that is not already mounted, and it doubles as a syntax test. The second mounts one entry by its mount point alone, since the details come from fstab. Expect silence on success and an error message on failure.
sudo mount -a && findmnt
Tests the configuration and then shows the resulting mounts. Run this before rebooting, never after. If your system has a recent util-linux, sudo findmnt --verify also checks fstab for common problems.
Unmounting, Busy Mount Points, and Lazy Unmount
findmnt /mnt
sudo umount /mnt
sudo umount /dev/sdb1
Confirm what is mounted, then unmount by mount point or by device. Note the spelling: the command is umount, not "unmount".
If you see "target is busy", something is still using the filesystem. Find it first:
sudo lsof /mnt
sudo fuser -vm /mnt
lsof lists open files under the mount, and fuser -vm shows the processes using it. Stop those processes cleanly, then run sudo umount /mnt again.
sudo umount -l /mnt
Lazy unmount detaches the filesystem immediately and cleans up references once it is no longer busy. Use it with caution. Processes can keep working with files on a filesystem that no longer appears mounted, which can confuse investigations.
sudo umount -f /mnt
Warning: a forced unmount is mainly useful for unreachable network filesystems such as NFS. On local disks, forcing it risks data loss.
findmnt /mnt
Run this after unmounting. No output means the mount is gone.
Detection: What Analysts Should Watch For
Mounts are not only an admin task. They show up in real intrusions and insider incidents, so they belong in your monitoring.
- Unexpected mounts: a new tmpfs, a loop mount of an unfamiliar image, or an NFS share nobody provisioned.
- Option drift: a hardened location suddenly showing
rw,execafter a remount. - Overmounting: a filesystem mounted on top of an existing directory to hide what is underneath. A periodic
findmntcomparison against a known-good baseline catches this. - Removable media: USB storage appearing on servers that should never have it.
On systems running auditd, you can record mount and unmount system calls:
sudo auditctl -a always,exit -F arch=b64 -S mount -S umount2 -k mounts
sudo ausearch -k mounts
The first command adds a temporary rule that logs mount and umount events tagged with the key mounts, and the second searches those events. Make the rule permanent through your audit rules configuration, and feed the events to your SIEM so a mount on a production server generates an alert for review.
Expert Tips
- Default to read-only. Mount
rofirst and remountrwonly when you must write. - Use UUIDs in fstab, never bare device names on systems where disks can change order.
- Disable auto-mount for removable media on servers and sensitive workstations, and mount manually with restrictive options.
- Baseline your mounts. Save
findmntoutput for each server class and diff it during audits. - Never test fstab by rebooting. Test with
mount -awhile you still have a working session. - Document exceptions. If a volume truly needs
execorsuid, write down why. Auditors and your future self will ask.
Related Cybersecurity Topics You Should Explore
- Linux du Command Cheat Sheet: Find Disk Space Hogs Fast
- Linux df Command Cheat Sheet: Fix Full Disk & Missing Logs
- Linux Disk Commands Cheat Sheet: df, du, mount, fsck (2026)
- Linux umask Cheat Sheet: 022 vs 027 vs 077 Explained
- Linux chgrp Cheat Sheet (2026): Commands, Examples & Audit Tips
- Linux chown Command Cheat Sheet: 40+ Examples (2026)
- Linux chmod Cheat Sheet: Stop Using 777 (Safer Fixes)
- OnePlus 15 Root Exploit: Zero-Permission Apps Can Take Full Control
- One Misconfigured chmod Command Gave Attackers Root Access
- How SOC Analysts Use sed to Catch Attacks Before the SIEM Does
- Linux tr Command Tutorial: Fix Messy SOC Logs in Seconds
FAQ
What is the difference between mount and findmnt?
mount lists mounts in a flat format and performs mounting, while findmnt is built for querying and shows a clear tree with single-field output options.
Does noexec stop malware from running?
No. It blocks direct execution from that filesystem, but interpreters and other techniques can still run code. Use it as one layer among several.
How do I mount a USB drive safely?
Identify it with lsblk -f, then mount it with sudo mount -o ro,nosuid,nodev,noexec /dev/sdb1 /mnt. Replace the device name with your own.
Why does umount say the target is busy?
A process has files open or its working directory inside the mount. Use lsof or fuser -vm to find it, and stop it before unmounting.
Is it safe to run mount -a on a production server?
Generally yes, since it only mounts entries not already mounted, but a faulty entry can hang or fail. Back up fstab first and use the nofail option for non-critical volumes.
When should I use a lazy unmount?
Only when a normal unmount fails and you understand why the mount is busy. It detaches the mount point immediately while processes may still be using the filesystem.
Should I mount by UUID or by label?
UUID, in most cases. Labels can be duplicated or changed by anyone who formats a drive.
Conclusion
Mounting looks like routine housekeeping until the day it matters: an evidence disk that must not change, a data volume that should never execute code, or a server that will not boot because of a typo in fstab. Master the basics of mount, umount, and findmnt, make ro,nosuid,nodev,noexec your default for untrusted media, and treat mount changes as events worth monitoring. These small habits make endpoints harder to abuse and investigations easier to defend.
Analysis based on SOC monitoring and public threat intelligence review.
