Loading date…
LinkedIn Twitter Instagram YouTube WhatsApp
Malwarebytes - Cybersecurity for Everyone

Linux Mount Commands Cheat Sheet: Secure Mounts (2026)

Linux terminal showing the mount command with ro, nosuid, nodev, and noexec options on a USB drive

Linux Mount Commands Cheat Sheet: Mount, Unmount, and Harden Filesystems Like a SOC Analyst

Picture a SOC analyst at 2 AM. A server has been flagged for suspicious outbound traffic, and the incident commander wants a copy of its data disk examined on a separate Linux workstation. The analyst plugs in the disk and types a plain mount command out of habit. Nothing visibly breaks, but the disk is now mounted read-write with executables allowed. Timestamps may have changed, and any script on that disk is one careless click away from running on the analyst's own machine. (This is an illustrative scenario, but it is a mistake that happens in real investigations.)

Mount options are one of the cheapest and most overlooked controls in Linux server hardening. This cheat sheet covers the commands you need every day: viewing mounts, mounting devices and images, working with /etc/fstab, and unmounting safely. It also shows how to apply the security options that auditors and benchmarks such as the CIS Linux benchmarks ask about.

Table of Contents

Viewing Mounted Filesystems

Before you change anything, look at the current state. Whether you are doing troubleshooting or incident response, that habit prevents most mistakes.

mount

Lists currently mounted filesystems and their mount points. On a modern system the output is long because it includes virtual filesystems such as proc, sysfs, and cgroup.

mount | column -t

Aligns the same output into columns showing device, mount point, filesystem type, and options. This is much easier to scan on a narrow terminal.

findmnt

Displays mounts as a tree, which makes it easy to spot a filesystem mounted inside another one. This is usually the better starting point than raw mount.

findmnt /mnt
findmnt -T /mnt

The first command shows what is mounted exactly at /mnt. The second shows the filesystem that contains the given path, even if the path is only a subdirectory of a mount.

findmnt -no SOURCE /mnt
findmnt -no FSTYPE /mnt
findmnt -no OPTIONS /mnt
findmnt -no TARGET /mnt

These return a single field (source device, filesystem type, active options, or target) with no header. They are ideal for scripts and quick checks.

df -h /mnt

Shows used and available space. Note that mount | column -t does not show usage. It lists devices, types, options, and mount points. Use df -h when you need capacity.

ls -ld /mnt

Shows the ownership and permissions of the mount-point directory. When a filesystem is mounted, the permissions of its own root directory apply instead, so check this before and after mounting.

Identifying Devices by UUID and Label

Device names like /dev/sdb1 can change between boots or when another disk is attached. UUIDs are stable, which is why production configurations should use them.

lsblk -f

Lists block devices with filesystem type, label, UUID, and mount point. It is also the quickest way to see whether a USB drive was detected and auto-mounted.

blkid /dev/sdb1

Prints the UUID, label, and filesystem type of one device. You may need sudo to get complete output.

sudo mount UUID=xxxx-xxxx /mnt
sudo mount LABEL=DATA /mnt

Mounts by UUID or label instead of device name. Replace xxxx-xxxx with the real value from blkid. Labels can be duplicated or set by anyone who formats a drive, so UUIDs are the more dependable choice.

Mounting and Remounting Basics

sudo mkdir -p /mnt/data
sudo mount /dev/sdb1 /mnt/data

Creates a dedicated mount point and mounts the device there. Using a named directory instead of /mnt keeps your work organized. Mounting requires elevated privileges, hence sudo.

Warning: if the directory you mount onto already contains files, they become hidden while the mount is active. They are not deleted, but they are invisible until you unmount. Always mount on an empty directory.

sudo mount -t ext4 /dev/sdb1 /mnt

Specifies the filesystem type. Usually mount detects it automatically, but being explicit helps when detection fails.

sudo mount -o ro /dev/sdb1 /mnt
sudo mount -o rw /dev/sdb1 /mnt

Mounts read-only or read-write. Use ro any time you only need to look at data.

sudo mount -o remount /mnt
sudo mount -o remount,ro /mnt
sudo mount -o remount,rw /mnt

Changes options on an already mounted filesystem without unmounting it. Remounting read-only is a handy way to freeze a filesystem quickly. It can fail if processes have files open for writing.

Security Mount Options for Endpoint Hardening

These options are where mounting becomes a security control. They restrict what a filesystem is allowed to do, regardless of what files it contains.

OptionWhat it doesTypical use
roRead-only accessEvidence, untrusted media
noexecBlocks direct execution of binaries/tmp, /var/tmp, /dev/shm, data volumes
nosuidIgnores setuid/setgid bitsAnything not holding system binaries
nodevIgnores device filesAll non-root data filesystems
sudo mount -o noexec /dev/sdb1 /mnt
sudo mount -o nodev /dev/sdb1 /mnt
sudo mount -o nosuid /dev/sdb1 /mnt

Each command applies one restriction. noexec prevents running programs directly from the filesystem, nodev stops device files on it from being interpreted, and nosuid disables privilege-elevating bits.

sudo mount -o ro,nosuid,nodev,noexec /dev/sdb1 /mnt

This is the combination to memorize for unknown USB drives, disk copies, and anything from an untrusted source. Expected result: you can read files but cannot modify them or execute them directly.

sudo mount -o rw,noexec /dev/sdb1 /mnt

Read-write access while blocking direct execution. This is useful for upload or staging volumes where users need to write but nothing should run.

Be realistic about limits. noexec is a speed bump, not a wall. A user can still run a script by passing it to an interpreter (for example, sh script.sh), because the interpreter itself lives on an executable filesystem. Treat these options as one layer in defense in depth alongside application control and monitoring, not as a guarantee. The CIS benchmarks for common Linux distributions recommend restrictive options on temporary-file locations such as /tmp and /dev/shm, so these settings often appear in compliance audits.

ISO Images, Disk Images, tmpfs, and NFS

sudo mount -o loop,ro image.iso /mnt

Mounts an ISO through a loop device, read-only. ISO images are read-only by nature, but stating ro explicitly is good practice.

sudo mount -o loop disk.img /mnt

Mounts a filesystem image. For anything you care about preserving, add the safe options:

sudo mount -o loop,ro,nosuid,nodev,noexec disk.img /mnt

Note for forensic work: mounting some journaling filesystems read-only may still replay the journal, which can change the source. Investigators typically work on a copy of the evidence, and for ext4 may add the noload option to skip journal replay. Follow your organization's evidence-handling procedures.

sudo mount -t tmpfs tmpfs /mnt
sudo mount -t tmpfs -o size=1G tmpfs /mnt

Mounts a memory-backed filesystem, optionally capped at 1 GB. Contents disappear on unmount or reboot. Attackers also like tmpfs because files leave little trace on disk, which is another reason to monitor for unexpected tmpfs mounts.

sudo mount -t nfs server:/share /mnt

Mounts an NFS network share. For shares you do not fully control, add nosuid,nodev,noexec. Replace server:/share with your actual export.

Persistent Mounts with /etc/fstab (Safely)

A bad /etc/fstab entry can drop a server into emergency mode at boot, which is why a few habits matter here.

cat /etc/fstab

Displays the persistent mount configuration.

sudo cp /etc/fstab /etc/fstab.bak

Always back up before editing. It takes one second and can save an outage.

An example entry using a UUID, security options, and nofail so a missing disk does not block boot:

UUID=xxxx-xxxx  /mnt/data  ext4  defaults,nofail,nodev,nosuid,noexec  0  2
sudo mount -a
sudo mount /mnt/data

The first command mounts everything in fstab that is not already mounted, and it doubles as a syntax test. The second mounts one entry by its mount point alone, since the details come from fstab. Expect silence on success and an error message on failure.

sudo mount -a && findmnt

Tests the configuration and then shows the resulting mounts. Run this before rebooting, never after. If your system has a recent util-linux, sudo findmnt --verify also checks fstab for common problems.

Unmounting, Busy Mount Points, and Lazy Unmount

findmnt /mnt
sudo umount /mnt
sudo umount /dev/sdb1

Confirm what is mounted, then unmount by mount point or by device. Note the spelling: the command is umount, not "unmount".

If you see "target is busy", something is still using the filesystem. Find it first:

sudo lsof /mnt
sudo fuser -vm /mnt

lsof lists open files under the mount, and fuser -vm shows the processes using it. Stop those processes cleanly, then run sudo umount /mnt again.

sudo umount -l /mnt

Lazy unmount detaches the filesystem immediately and cleans up references once it is no longer busy. Use it with caution. Processes can keep working with files on a filesystem that no longer appears mounted, which can confuse investigations.

sudo umount -f /mnt

Warning: a forced unmount is mainly useful for unreachable network filesystems such as NFS. On local disks, forcing it risks data loss.

findmnt /mnt

Run this after unmounting. No output means the mount is gone.

Detection: What Analysts Should Watch For

Mounts are not only an admin task. They show up in real intrusions and insider incidents, so they belong in your monitoring.

  • Unexpected mounts: a new tmpfs, a loop mount of an unfamiliar image, or an NFS share nobody provisioned.
  • Option drift: a hardened location suddenly showing rw,exec after a remount.
  • Overmounting: a filesystem mounted on top of an existing directory to hide what is underneath. A periodic findmnt comparison against a known-good baseline catches this.
  • Removable media: USB storage appearing on servers that should never have it.

On systems running auditd, you can record mount and unmount system calls:

sudo auditctl -a always,exit -F arch=b64 -S mount -S umount2 -k mounts
sudo ausearch -k mounts

The first command adds a temporary rule that logs mount and umount events tagged with the key mounts, and the second searches those events. Make the rule permanent through your audit rules configuration, and feed the events to your SIEM so a mount on a production server generates an alert for review.

Expert Tips

  • Default to read-only. Mount ro first and remount rw only when you must write.
  • Use UUIDs in fstab, never bare device names on systems where disks can change order.
  • Disable auto-mount for removable media on servers and sensitive workstations, and mount manually with restrictive options.
  • Baseline your mounts. Save findmnt output for each server class and diff it during audits.
  • Never test fstab by rebooting. Test with mount -a while you still have a working session.
  • Document exceptions. If a volume truly needs exec or suid, write down why. Auditors and your future self will ask.

Related Cybersecurity Topics You Should Explore

FAQ

What is the difference between mount and findmnt?

mount lists mounts in a flat format and performs mounting, while findmnt is built for querying and shows a clear tree with single-field output options.

Does noexec stop malware from running?

No. It blocks direct execution from that filesystem, but interpreters and other techniques can still run code. Use it as one layer among several.

How do I mount a USB drive safely?

Identify it with lsblk -f, then mount it with sudo mount -o ro,nosuid,nodev,noexec /dev/sdb1 /mnt. Replace the device name with your own.

Why does umount say the target is busy?

A process has files open or its working directory inside the mount. Use lsof or fuser -vm to find it, and stop it before unmounting.

Is it safe to run mount -a on a production server?

Generally yes, since it only mounts entries not already mounted, but a faulty entry can hang or fail. Back up fstab first and use the nofail option for non-critical volumes.

When should I use a lazy unmount?

Only when a normal unmount fails and you understand why the mount is busy. It detaches the mount point immediately while processes may still be using the filesystem.

Should I mount by UUID or by label?

UUID, in most cases. Labels can be duplicated or changed by anyone who formats a drive.

Conclusion

Mounting looks like routine housekeeping until the day it matters: an evidence disk that must not change, a data volume that should never execute code, or a server that will not boot because of a typo in fstab. Master the basics of mount, umount, and findmnt, make ro,nosuid,nodev,noexec your default for untrusted media, and treat mount changes as events worth monitoring. These small habits make endpoints harder to abuse and investigations easier to defend.

Analysis based on SOC monitoring and public threat intelligence review.

Shubham Chaudhary

Shubham Chaudhary is a cybersecurity specialist and founder of Xpert4Cyber. He shares practical tutorials, guides and the latest news on Networking, Windows Server, Linux Server, Ethical Hacking, Digital Forensics, Malware Analysis, Threat Hunting and Monitoring, OSINT, Cloud Computing and AI, with a focus on defense and security awareness. Educational and defensive use only.

Post a Comment

Previous Post Next Post