Container Overlay Filesystem Enumeration via Mount - Linux

Rule Info

Name
Container Overlay Filesystem Enumeration via Mount - Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects processes enumerating overlay filesystems by piping mount output through grep for "overlay". This technique is used by attackers to detect if they are running inside a container (e.g., Docker, Podman), which is a common precursor to container escape attempts or environment-aware malware behaviour.
Date
2026-08-07 00:00:00
Modified
None
Id
3f7a2d91-b5e4-4c18-a832-6d9e0f1c7b45
Tags
attack.discovery attack.t1082 attack.t1613
Type
Nextron Sigma feed only (private)

Rule History