A practical reference for sysadmins using top to detect CPU spikes, memory exhaustion, and anomalous processes on Linux servers.

What is top?

The top command is an interactive, real-time process viewer built into virtually every Linux distribution. Unlike ps aux, which takes a static snapshot, top continuously refreshes its output — by default every 3 seconds — giving sysadmins a live view of CPU usage, memory consumption, load averages, and individual process activity. For security purposes, top is most valuable during active incident response when you need to observe a system under load in real time: watching a cryptominer consume CPU, identifying a process that is exhausting memory before the OOM killer fires, or confirming that a service restart resolved a resource spike. Its interactive interface allows sorting, filtering, and killing processes without leaving the terminal, making it faster than any GUI tool for rapid triage on a remote server.

Syntax

top
top -u www-data
top -p 1234,5678
top -bn1
top -bn1 | head -20

Run top with no arguments for the interactive dashboard. Use -u to filter by a specific user — useful for auditing web server or database processes. The -p flag monitors specific PIDs. The -bn1 combination runs top in batch mode for one iteration, producing machine-parseable output suitable for logging or scripting.

Key Options and Interactive Commands

Flag / ParameterDescriptionSecurity Note
-u <user>Show only processes owned by the specified userUse to audit what a specific service account (e.g. www-data, postgres) is running
-p <pid>Monitor specific process IDs only—
-bBatch mode — non-interactive output, suitable for logging or scripting—
-n <num>Number of iterations before exiting (use with -b)—
P (interactive)Sort by CPU usage while top is runningFirst action during a CPU spike incident — identifies the offending process instantly
M (interactive)Sort by memory usage while top is runningUse before OOM killer fires to identify the memory-exhausting process
k (interactive)Kill a process by PID from within the top interface—
1 (interactive)Toggle per-CPU core display to see individual core utilisationReveals asymmetric CPU load — one saturated core can indicate a single-threaded attack or cryptominer

Common Use Cases

Identify a Memory-Exhausting Process Before OOM Killer Fires

When available memory drops rapidly and the system becomes unresponsive, the OOM killer will terminate processes arbitrarily — often killing critical services rather than the offending process. Running top sorted by memory (M) gives you the window to identify and kill the offending process manually before the kernel intervenes.

top
# Press M to sort by memory
# Press k to kill the top process by PID

Detect Anomalous CPU Consumption in Real Time

Cryptominers, fork bombs, and runaway application processes all manifest as sustained high CPU usage. Running top sorted by CPU with the per-core view enabled (1) lets you see both which process is consuming CPU and whether it is saturating all cores or just one — a pattern that helps distinguish a cryptominer (often single-threaded) from a legitimate multi-threaded workload.

top
# Press 1 to show per-core CPU
# Press P to sort by CPU usage

Log a Snapshot for Incident Documentation

During incident response, capturing a timestamped record of system state is essential for post-incident analysis. Batch mode produces clean, parseable output that can be redirected to a log file without the interactive display.

top -bn1 > /var/log/top_snapshot_$(date +%Y%m%d_%H%M%S).txt

Security Relevance: Real-Time Anomaly Detection During Active Incidents

Resource exhaustion attacks — whether deliberate DoS attempts, cryptomining malware, or misconfigured applications — all produce a common signature: abnormal CPU or memory consumption visible in top. The critical advantage of top over ps aux in these scenarios is its live refresh rate. You can watch a process ramp up in real time, observe whether it is spawning child processes, and track memory growth across refresh cycles. During an active intrusion, an attacker running a reverse shell or staging a lateral movement tool will typically cause a brief but visible CPU or memory spike. The load average displayed at the top of the screen is also a rapid sanity check: values consistently above the number of CPU cores indicate sustained saturation. For DoS response, top combined with ss or netstat provides a complete picture — resource consumption on one side, network connections on the other.

  • A process showing 100% CPU on a single core with a generic or obfuscated name is a primary cryptominer indicator
  • Rapid memory growth in a web server process (Apache, nginx, PHP-FPM) can indicate a memory leak exploit or a large payload attack
  • Load average above CPU core count during off-peak hours warrants immediate investigation — this pattern is abnormal
  • top itself consumes minimal resources but running it in a tight loop with -d 0.1 can add measurable overhead on a loaded system

Practical Examples

Monitor only web server processes in real time

top -u www-data

Restricts the display to processes owned by the web server user. Useful for confirming that nginx or Apache worker counts are within expected bounds and that no unexpected processes are running under the web server account.

Capture a non-interactive snapshot for log archiving

top -bn1 > /var/log/top_snapshot_$(date +%Y%m%d_%H%M%S).txt

Batch mode with one iteration writes the full top output to a file. Run this immediately when investigating an alert to preserve the system state at the time of detection.

Watch specific PIDs for a targeted investigation

top -p $(pgrep -d',' nginx)

Uses pgrep to dynamically resolve all nginx PIDs and passes them to top for targeted monitoring. Useful when you want to watch a specific service without the noise of all other processes.

Troubleshooting Common Issues

Problem: top shows high CPU but you cannot identify the process by name

Solution: Press c in the top interface to toggle the full command path. Cryptominers and malware often use short, generic names in the COMMAND column but reveal their full path (often under /tmp or /dev/shm) when the full command line is displayed.

Problem: top shows 100% CPU but the server feels responsive

Solution: Check if the process is running in a container or cgroup with CPU limits. Also press 1 to see per-core utilisation — if only one core is at 100% but others are idle, overall system load may still be low. The bottleneck is localised.

Problem: top output in a script or cron job is garbled or contains escape codes

Solution: Always use -b (batch mode) when capturing top output non-interactively. Without it, top emits terminal escape codes intended for an interactive display, which corrupt log files and pipeline output.

Summary

The top command is the standard first response tool for any Linux server showing signs of resource exhaustion or unexpected behaviour. Its real-time refresh makes it uniquely suited for observing dynamic situations — actively running attacks, memory leaks, and CPU spikes — where a static snapshot from ps aux would miss the pattern. Combine it with per-core CPU view and memory sorting for the fastest possible triage.

  • Press P to sort by CPU and M to sort by memory — these two shortcuts cover 90% of incident triage use cases
  • Use top -bn1 in scripts and cron jobs to capture system state snapshots without interactive output
  • A process at sustained 100% CPU with an obfuscated name or a path under /tmp is a high-confidence cryptominer indicator

Is Your Linux Server Monitored 24/7?

INTRAM provides managed Linux hosting with continuous process and performance monitoring. We detect anomalies before they become incidents — so your team can focus on building, not firefighting.

Explore Managed Hosting

Let’s assess what your business actually needs.

We will use these details only to understand your request and reply appropriately.