- Advanced use of tasklist and taskkill to audit and close processes with filters, CSV, and remote execution.
- Comprehensive service management with sc: creation, query, start, stop and deletion locally and remotely.
- Best practices: least privileges, remote precautions, and responsible use of /F and filters.
If you work with Windows daily, controlling what runs and how to react when something gets stuck makes all the difference between a fast and a sluggish machine. Fortunately, with a handful of native commands like tasklist, taskkill, and sc, you can audit, filter, stop, and automate processes and services, both locally and on remote machines.
In this practical guide, I'll explain, step by step, how to list processes in different formats, how to apply advanced filters, how to safely close frozen applications, and how to precisely manage system services. All of this is covered with real-world examples ready to copy and paste , remote access warnings, and helpful tips and tricks to make navigating the console a breeze.
Processes and services: how they are similar and how they are different
In Windows, a process is a running program that can have threads, execute tasks, and terminate when it finishes its work. A service, on the other hand, is a system component that typically runs in the background, can be started, stopped, resumed, or restarted , and by design remains active until the system or an administrator decides otherwise.
Key differences include: processes can run in the foreground or background and are terminated when necessary, while services are managed with states (start, stop, pause, continue) and are designed to persist. A process can create or control services, and a service can, in turn, launch child processes.
If you prefer a graphical interface, Task Manager (taskmgr.exe) provides a snapshot of your current system: a Processes tab for CPU, memory, GPU, network, and status (including the classic "Not Responding"), and a Services tab to view their PID, status, startup type, and manufacturer. But when you need precision, automation, and remote access, the command line is your best friend.
Key tools for managing the system from the console
The essential utilities you need to know are: tasklist (to list processes), taskkill (to terminate processes by PID or image name), and sc (to manage services using the Service Control Manager). Also very useful are WMIC (to query WMI via the console) and the query/qprocess commands for inspecting processes by session or user.
With these commands you can generate CSV reports for Excel, create headerless lists, apply filters by memory usage or status, and act with surgical precision: from terminating a rogue notepad.exe to closing a whole tree of child processes launched by a cmd.exe console.
Listing processes with tasklist: filters, formats, and examples
The most direct command to see what's running is `tasklist` . Without any options, you'll get the image name, PID, session, and memory usage. But the interesting part comes with its modifiers, which allow you to filter and customize the output to your liking.
Very practical parameters: /V (detailed), /SVC (shows services hosted by each process), /M (which processes load a specific DLL/EXE), /FO ("TABLE", "LIST", "CSV"), /NH (hides headers in TABLE/CSV), and /FI (filters). There are also /S , /U , and /P for remote execution with credentials.
With these commands you can generate CSV reports for Excel, create headerless lists, apply filters by memory usage or status, and act with surgical precision: from terminating a rogue notepad.exe to closing a whole tree of child processes launched by a cmd.exe console.
To view the complete help on your Desktop, you can copy the output with: "TASKLIST /? >%userprofile%/Desktop/uso.txt" . This way, you'll have all the explained options at hand and won't have to rely on memory when dealing with complex filters.
tasklist
tasklist /v
tasklist /svc
tasklist /m ntdll.dll
The CSV output is ideal for opening in Excel or processing with scripts. You can generate a highly detailed report like this: CSV + detailed file to Desktop, ready for analysis with filters and pivot tables.
tasklist /v /fo csv >%userprofile%/Desktop/list.csv
If you're looking for something more concise, with hosted services and in text format: LIST + TXT redirected to the Desktop. It's perfect for a quick review in Notepad and for easily sharing with a colleague.
tasklist /svc /fo list >%userprofile%/Desktop/list.txt
The filtering is incredibly powerful. You can, for example, keep only the running applications and view them in detail: this helps you focus on what's currently active, leaving out tasks that are paused or suspended in some editions.
tasklist /v /fi "STATUS eq running"
Another classic: locating which processes are loading a specific DLL, such as ntdll.dll . Very useful for diagnostics or when investigating dependencies.
tasklist /m ntdll.dll
Filtering by memory usage using ranges is also possible. For example, to see processes using more than 15000 KB and less than 19000 KB of RAM, you can concatenate two /FI commands and obtain the exact segment you're interested in.
tasklist /fi "memusage gt 15000" /fi "memusage lt 19000"
Another recurring pattern involves combining listings : listing notepad.exe and firefox.exe with two chained calls using the & operator , which leaves both results on screen in a single pass.
tasklist /fi "IMAGENAME eq notepad.exe" & tasklist /fi "IMAGENAME eq firefox.exe"
Do you need CSV files directly in the console, but only for processes with PID > 1000 ? No problem: with filtering and formatting, everything is ready to be redirected or processed in another program.
tasklist /v /fi "PID gt 1000" /fo csv
If you want to export that CSV file, simply add the redirect. This is very convenient when you're building perimeter reports or collecting incident data.
tasklist /v /fi "PID gt 1000" /fo csv > procs.csv
Filtering by user and status, while excluding system authority, is useful when searching for live "user" processes . This view sifts through system noise and lets you focus on what typically causes problems in office environments.
tasklist /fi "USERNAME ne NT AUTHORITY\SYSTEM" /fi "STATUS eq running"
In remote scenarios, tasklist shines. You can query a server called srvmain using your current or custom credentials, and also filter by loaded modules and services. Keep in mind that the WINDOWTITLE and STATUS filters do not apply remotely.
tasklist /s srvmain
tasklist /s srvmain /u maindom\hiropln /p p@ssW23
tasklist /s srvmain /svc /fi "MODULES eq ntdll*"
Quick tip: If you want the command prompt window to stay open after running a list, use the command CMD /K . It's a simple way to "see and stay" in the console without having to relaunch it each time.
CMD /K TASKLIST /V
Closing tasks with taskkill: syntax, filters, and real-world examples
When an application becomes unresponsive, consumes resources unnecessarily, or opens too many child processes, taskkill is the answer. It allows you to terminate a process by PID or image name, force termination, and, if needed, bring down the entire child process tree with a single modifier.
The general syntax supports remote execution with a username and password, multiple chained filters, and execution by PID or IMAGE_NAME (with wildcards for names if you add a filter). Note: Remote execution is always forced, and WINDOWTITLE/STATUS filters do not apply.
taskkill <usuario> ]]] { }
Terminating by PID is the most direct approach and reduces the risk of accidentally terminating other processes with similar names. You can kill one or more PIDs in the same command, which is helpful when cleaning up zombie processes that replicate themselves.
taskkill /pid 1230
taskkill /pid 1230 /pid 1241 /pid 1253
Terminating by image name is convenient for "shutting down" a specific application in all its processes, especially if it uses multiprocessing like most modern browsers do. Using /F forces the application to close, and /T removes child processes.
taskkill /f /im notepad.exe
If you want to kill all processes with a PID greater than or equal to 1000, regardless of their name, you can combine a filter with `/im *` . This pattern is for very specific remediation purposes; use it wisely.
taskkill /f /fi "PID ge 1000" /im *
Filters by status and title are very helpful for eliminating bottlenecks . For example, you can force-quit anything that is "not responding," excluding windows whose title doesn't fit your criteria. Remember that these filters don't work remotely.
taskkill /f /fi "STATUS eq NOT RESPONDING"
There are special processes worth knowing: closing wscript.exe cuts off any VBScript scripts that have become stuck, and restarting Windows Explorer gets you out of trouble when the taskbar or shell freezes.
taskkill /f /im wscript.exe
taskkill /f /im explorer.exe & start explorer.exe
If you prefer to give the system a break before relaunching the shell, add a few seconds of ` timeout` . It's a small step that can prevent errors when disk operations are in progress.
taskkill /f /im explorer.exe & timeout /nobreak 05 & start explorer.exe
Another common use: closing the console and everything it might have launched in cascade. Using /T ensures that no child commands are running in the background.
taskkill /f /im cmd.exe /t
Taskkill also supports remote execution with credentials, which is essential when a server is overwhelmed by a resource-guzzling process at startup . Wildcards allow you to target multiple executables with similar names, such as "note*" to locate Notepad and other related programs.
taskkill /s srvmain /u maindom\hiropln /p p@ssW23 /fi "IMAGENAME eq note*" /im *
If you need to act with a safety criterion, you can also kill only what started the system ( NT AUTHORITY\SYSTEM user ) to ensure that you do not close user tools unnecessarily.
taskkill /f /fi "USERNAME eq NT AUTHORITY\SYSTEM" /im notepad.exe
And if you want something even more basic, there's tskill , which allows you to terminate processes at the session level (less flexible than taskkill, but useful in older or very limited environments). Administrators can use it against processes in other sessions.
tskill 1230
tskill explorer /id:1
Automate shutdowns at Windows startup using batch files
There are scenarios where it's useful to kill processes immediately after logging in, for example, to disable unnecessary services that hinder startup. You can do this with a simple batch file in the Startup folder without using Task Scheduler.
Create a .bat file with the taskkill lines you need and move it to the user's Startup folder. You can easily open this folder by typing shell:Startup in the Run dialog box (Win+R) and confirming.
@echo off
taskkill /f /im proceso1.exe
taskkill /f /im proceso2.exe
taskkill /f /im proceso3.exe
Other ways to list: WMIC, query, and qprocess
For advanced inspection and raw data export, WMIC is pure gold and complements tools for detecting malicious processes . You can choose the columns you're interested in (title, command line, PID, etc.) and export them to a file on disk for later analysis or to include in a report.
WMIC /OUTPUT:C:\procs.txt PROCESS get Caption,Commandline,Processid
Furthermore, with `query` and its alias `qprocess`, it's easy to see who is running what, in which session, and with which PID. This is very useful on servers with Remote Desktop Services, where each session can have its own farm of active processes.
query process *
query process /id:1
This family of commands displays, among other data, the owning user, session name, session ID, process name, and PID. Together, they provide a multi-session perspective that tasklist can also show, but with a special focus on Terminal Services.
Manage services with sc: create, query, start, and delete
For managing system services, the `sc` command is the direct route to the Services Control Manager (Services.msc ). With it, you can create a new service, modify its description, start or stop it, pause it, or delete service registry entries. It also works remotely by preceding the command with `\\`.
Creating a sample service with automatic startup is as simple as specifying a symbolic name, the binary path, and the startup type. Pay attention to spaces after equal signs: they matter in `sc`, so adhere to the exact syntax.
sc create NuevoServicio binpath= c:\windows\system32\NuevoServicio.exe start= auto
To do this on a remote host , precede the machine name. From then on, the rest of the commands (start, stop, delete) will work exactly the same with that service name.
sc create \\miservidor NuevoServicio binpath= c:\windows\system32\NuevoServicio.exe start= auto
Starting, stopping, or changing the administrative status of a newly created service is straightforward. You'll often combine these commands with tasklist/taskkill when a service launches problematic child processes.
sc start NuevoServicio
sc stop NuevoServicio
sc pause NuevoServicio
For auditing, the `sc query` in its various forms is very useful: active services, all services, interactive services, or a specific service with its status. This view complements `tasklist /svc` when you need real-time status and type information .
sc query
sc query type= service
sc query state= all
sc query NuevoServicio
sc query type= service type= interact
And when you no longer need it, you can remove a service from the registry with a simple delete. Keep in mind that it must be stopped; otherwise, the operation will fail or remain pending until resources are freed.
sc delete NuevoServicio
Help, supported filters and nuances of remote mode
Both commands, tasklist and taskkill, display very comprehensive help directly from the console. Take a moment to read it: you'll see supported filters such as PID (eq, ne, gt, lt, ge, le), IMAGENAME (eq, ne), USERNAME , MEMUSAGE , MODULES , or WINDOWTITLE , and status values such as RUNNING, NOT RESPONDING, or UNKNOWN (in some editions, also SUSPENDED).
There are some rules to remember: the wildcard * for /IM is only accepted when you apply a filter; in remote mode, completion is always forced, and the WINDOWTITLE and STATUS filters are not evaluated. If you're going to run remotely, make sure you have valid credentials , that the firewall allows the necessary communication, and that the RPC/WMI services are running.
To save help to a file and refer to it later without getting lost in the console, remember that you can redirect the output to a .txt file on the Desktop, which is especially useful when documenting an internal procedure or sharing playbooks with the team.
TASKLIST /? >%userprofile%/Desktop/uso_tasklist.txt
TASKKILL /? >%userprofile%/Desktop/uso_taskkill.txt
Practical examples of daily administration
Common routines : Monitoring resource-intensive processes, identifying shared DLLs, and preparing a CSV file for later review are all common tasks. Here's a collection of quick operations, all based on the above and ready to be combined and adjusted to suit your environment.
Generating a detailed list and keeping the console open afterward is useful for real-time monitoring without closing the window. Combining CMD /K with tasklist provides a convenient workflow.
CMD /K TASKLIST /V
Locate all processes that have a module loaded with a pattern. The wildcard at the end of the DLL name lets you cover different versions or variants of the same system library.
tasklist /m ntdll*
A combined list of two very common applications, to quickly see how many instances you have open and their memory usage. This can give you an idea of whether there is excessive multiprocessing or browser tabs running indiscriminately.
tasklist /fi "IMAGENAME eq notepad.exe" & tasklist /fi "IMAGENAME eq firefox.exe"
Terminate access by credentials and image name pattern on a remote server. Very useful in corporate environments where remote desktop is often unresponsive due to chained office processes.
taskkill /s srvmain /u maindom\hiropln /p p@ssW23 /fi "IMAGENAME eq note*" /im *
And if you want to be strictly selective by origin, only kill what was launched by the system account. This filter is very effective when investigating service behavior in relation to user processes.
taskkill /f /fi "USERNAME eq NT AUTHORITY\SYSTEM" /im notepad.exe
Safety tips and best practices
Avoid terminating system processes without first verifying their function; this could cause instability or data loss. Before terminating, identify the process using `tasklist /v` and, if possible, try a normal shutdown from the interface. Reserve ` /F` for cases where there is no alternative. Consult the list of Windows 11 services that you should not disable before proceeding.
When working remotely, use accounts with the minimum necessary privileges, and if you manage multiple machines, consider scripts that log what was closed and when. Redirect output to CSV or TXT to leave a trace, and protect files containing passwords or credentials with the same zeal as a production secret.
Finally, remember that sometimes the fastest way is the graphical approach: open Task Manager and manually close the rogue process. The console excels at automation, accurate diagnostics, and repeatable actions ; the GUI comes to the rescue when you need an immediate click.
By now you've mastered how to inventory, filter, and terminate processes with tasklist and taskkill, and how to create, query, and delete services with sc, both locally and remotely. With the examples and warnings in this article, you'll be able to build your own maintenance scripts, respond to crashes in seconds, and generate polished CSV or TXT reports for your team, always applying the principle of minimal intervention and maximum control over what runs on your systems.
Passionate writer about the world of bytes and technology in general. I love sharing my knowledge through writing, and that's what I'll do on this blog, show you all the most interesting things about gadgets, software, hardware, tech trends, and more. My goal is to help you navigate the digital world in a simple and entertaining way.