Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is resource exhaustion?

Resource exhaustion occurs when a finite capacity - memory, processor, connections, threads, disk, locks, queues or provider quota - is consumed so normal operation cannot continue. It is an outcome, not proof of attack.

Identify consumption and cause

Use performance, process, application, provider, error and traffic records to show which resource reached its limit, what consumed it and when. Determine whether demand was malicious, accidental, legitimate or caused by a software defect.

Small crafted requests may exploit a weak function without high traffic, while a runaway legitimate process can cause the same exhaustion as an attack.

Explain recovery behaviour

Queues, locks and failed dependencies can keep a service unavailable after malicious traffic stops. Record manual intervention and the recovery sequence so total outage time is not attributed automatically to continuing attack.

Cloud, licence and service-plan limits may be the actual constraint. Preserve quota, throttling and billing records and distinguish deliberate triggering from capacity simply being exceeded.

Key takeaway

Establish the exact resource and consuming activity, then distinguish deliberate abuse from defect, legitimate overload and delayed recovery.

Reference: CIM-202Cyber Incidents & Offender Methods