EC2 instance CPU spiked abnormally — possible compromise or runaway process

Severity
High
Service
EC2
Check ID
EC2_CPU_SPIKE

What this check finds

An EC2 instance that normally runs below 20% CPU utilization had at least one day where CPU exceeded twice the 7-day average and surpassed 40%. Sudden CPU spikes on otherwise idle instances are a strong indicator of crypto-mining malware, a compromised workload, or an unintended process. Investigate before assuming it is benign.

Passing looks like: No abnormal EC2 CPU spikes.

How to fix it

Investigate the spike: check CloudWatch metrics for the exact timestamp, review OS-level process list (ps aux / top) via SSM Session Manager, and check CloudTrail for unusual API calls around the spike time. If the instance is compromised, isolate it by modifying its security group to deny all traffic, take a forensic snapshot, and terminate the instance.

AWS CLI

  1. aws ec2 describe-instances --instance-ids INSTANCE_ID

Names in capitals are placeholders for your own resource. Review a command before you run it.

AWS console

CloudWatch → Metrics → EC2 → Per-Instance Metrics → CPUUtilization.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to EC2 instance CPU spiked abnormally — possible compromise or runaway process
FrameworkControls
NIST SP 800-53 Rev5 (Moderate)
  • SI-4 System Monitoring
NIST Cybersecurity Framework 2.0
  • DE.CM-01 Networks are monitored
ISO/IEC 27001:2022 Annex A
  • A.8.16 Monitoring activities

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More EC2 checks

All EC2 checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only