Does high CPU or GPU use prove cryptomining?¶
No. High CPU or GPU use shows that a resource was busy; it does not identify the workload or whether it was authorised. Rendering, machine learning, compilation, analytics, gaming, backup and security scanning can all create similar utilisation.
Treat a utilisation spike as a lead to correlate with process, network and account evidence.
Find the workload behind the graph¶
Align the rise and fall in resource use with:
- process, service, container or virtual-machine activity;
- command lines, scripts and parent processes;
- user, service or cloud identity records;
- network connections and mining-pool traffic;
- scheduled or orchestration events; and
- approved workload and change records.
A renamed process can disguise mining, while a legitimate-looking executable may have been launched with mining configuration. The relevant finding is what work it performed, not the label displayed in a monitoring console.
Absence of a peak proves little¶
Mining can be throttled, paused while users are active or distributed across many small resources. Short monitoring periods may miss intermittent activity. Conversely, a sudden cloud bill may result from legitimate scaling, price changes or another unauthorised workload rather than mining.
Where cost is relevant, connect the billed resource to the actual image, container, process or function that consumed it. A measured impact strengthens an account of harm but does not replace evidence of the underlying activity.
Key takeaway
Use high utilisation to locate and time a workload, then establish mining from process, configuration, network and deployment evidence; neither a spike nor its absence resolves the question alone.