{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/system-monitoring/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["threat-detection","impact","system-monitoring","resource-abuse","cryptomining"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis rule provides a mechanism for identifying malicious processes by correlating endpoint security alerts with system-level resource utilization data. By monitoring for processes that trigger security alerts while simultaneously consuming 70% or more of CPU cycles, security teams can distinguish between standard administrative alerts and potentially active threats, such as unauthorized cryptominers or exploit payloads that impose significant system load.\u003c/p\u003e\n\u003cp\u003eThe detection requires the Elastic Agent 'System' integration to collect CPU metrics, which are then evaluated alongside existing security alerts in the Elastic Security index. This higher-order correlation helps reduce the noise associated with isolated security alerts by highlighting processes that are both suspicious and demonstrably active in a way that impacts host performance. The rule includes built-in filters for common high-resource benign processes such as ESET security agents and UiPath compiler tools.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful attacks involving high-resource abuse can lead to performance degradation of critical business systems, potential exfiltration of credentials during process injection, or unauthorized utilization of cloud compute resources. This detection helps identify these scenarios early, allowing for host isolation before broader compromise or resource exhaustion occurs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Elastic Agent with the 'System' integration to all critical endpoints to collect host CPU metrics.\u003c/li\u003e\n\u003cli\u003eEnable the 'system.cpu' and 'system.process' datasets in the integration policy to provide the necessary telemetry for high-CPU correlation.\u003c/li\u003e\n\u003cli\u003eUtilize the provided detection logic to monitor for processes that concurrently generate a security alert and exceed 70% normalized CPU usage.\u003c/li\u003e\n\u003cli\u003eTune the detection by adding specific organizational baseline software that performs intensive but benign tasks to the exclusion list defined in the rule logic.\u003c/li\u003e\n\u003cli\u003eEstablish an automated response workflow to isolate hosts identified by this rule for forensic analysis if malicious activity is confirmed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:18:17Z","date_published":"2026-09-18T19:18:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cpu-spike-alert/","summary":"A cross-platform detection methodology correlates security alerts with processes exhibiting sustained high CPU utilization to identify potential resource abuse or post-compromise activity.","title":"Detection of Security Alerts Correlated with High CPU Utilization","url":"https://feed.craftedsignal.io/briefs/2026-09-cpu-spike-alert/"}],"language":"en","title":"CraftedSignal Threat Feed - System-Monitoring","version":"https://jsonfeed.org/version/1.1"}