EC2 instance CPU spiked abnormally — possible compromise or runaway process
- Severity
- High
- Service
- EC2
- Check ID
- EC2_CPU_SPIKE
What this check finds
An EC2 instance that normally runs below 20% CPU utilization had at least one day where CPU exceeded twice the 7-day average and surpassed 40%. Sudden CPU spikes on otherwise idle instances are a strong indicator of crypto-mining malware, a compromised workload, or an unintended process. Investigate before assuming it is benign.
Passing looks like: No abnormal EC2 CPU spikes.
How to fix it
Investigate the spike: check CloudWatch metrics for the exact timestamp, review OS-level process list (ps aux / top) via SSM Session Manager, and check CloudTrail for unusual API calls around the spike time. If the instance is compromised, isolate it by modifying its security group to deny all traffic, take a forensic snapshot, and terminate the instance.
AWS CLI
aws ec2 describe-instances --instance-ids INSTANCE_ID
Names in capitals are placeholders for your own resource. Review a command before you run it.
AWS console
CloudWatch → Metrics → EC2 → Per-Instance Metrics → CPUUtilization.
Compliance controls it is evidence for
A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works
| Framework | Controls |
|---|---|
| NIST SP 800-53 Rev5 (Moderate) |
|
| NIST Cybersecurity Framework 2.0 |
|
| ISO/IEC 27001:2022 Annex A |
|
Checked on every scan
KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs
More EC2 checks
- HighAccount does not block public sharing of EBS snapshots
- HighAMI is publicly shared
- HighEBS snapshot is public
- HighEC2 instance has an IAM role with admin privileges
- MediumAccount default for instance metadata does not require IMDSv2
- MediumEBS default encryption is not enabled for this region
- MediumEBS volume is not encrypted at rest
- MediumEBS volume is unattached and incurring storage cost