tasklist - List Running Processes

Maintained on

When your PC feels slow, when you want to find the process using lots of memory, or when you want to check whether a specific application is running, the tasklist command is handy.

tasklist shows detailed information about all running processes (tasks) from the command prompt.

This article explains the basics of tasklist, how to filter and format the output, and how to use it in batch files.

If you only want to know whether an app is running, see Checking whether a specific process is running.

What is the tasklist command?

The tasklist command displays a list of processes currently running on the local or a remote computer.

It is like operating Task Manager from the command line, and shows information such as:

  • Image name: the name of the running program (e.g. chrome.exe, notepad.exe)
  • PID (process ID): a unique number that identifies the process
  • Session name: the session the process runs in
  • Memory usage: the amount of memory the process uses
  • Service information: the services the process hosts

Basic usage

The basic syntax of the tasklist command is as follows.

tasklist [/S system] [/U user] [/P password] [/M module | /SVC | /V] [/FO format] [/NH] [/FI filter]

/V, /SVC and /M cannot be used together.

The simplest usage is to run tasklist without options.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist
Image Name PID Session Name Session# Mem Usage
========================= ======== ================ =========== ============
System Idle Process 0 Services 0 8 K
System 4 Services 0 140 K
explorer.exe 2344 Console 1 95,248 K
chrome.exe 3456 Console 1 523,456 K
notepad.exe 5678 Console 1 3,124 K
C:\users\user>

This displays all running processes in a table.

About process IDs

A PID (process ID) is a unique identification number assigned to each process. You use it, for example, when terminating a specific process. Note that the examples show thousands separators in the memory usage for readability, but the PID itself is not displayed with commas.

Options of the tasklist command

tasklist has options to show more detail or change the output format.

OptionDescription
/VShows detailed information (status, window title, etc.)
/SVCShows the services hosted by each process
/MShows processes that have loaded the specified DLL module
/FOSpecifies the output format (TABLE, LIST, CSV)
/NHHides the column headers
/FIFilters the processes to show
/SSpecifies a remote computer
/USpecifies the user name to run the command as
/PSpecifies the password of the user account

The /V option - show details

The /V option shows more detailed information.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /V
Image Name PID Session Name Session# Mem Usage Status User Name CPU Time Window Title
explorer.exe 2344 Console 1 95,248 K Running USER\user 0:02:15 N/A
chrome.exe 3456 Console 1 523,456 K Running USER\user 0:15:42 Google Chrome
notepad.exe 5678 Console 1 3,124 K Running USER\user 0:00:03 *Untitled - Notepad
C:\users\user>
おすすめ書籍※ 広告を含む場合があります
中小企業経営者のためのRPA入門 RPA導入を成功させる方法

中小企業経営者のためのRPA入門 RPA導入を成功させる方法

60分でわかる! AIエージェント 超入門

60分でわかる! AIエージェント 超入門

コマンドラインの黒い画面が怖いんです。

コマンドラインの黒い画面が怖いんです。

知識・才能ゼロでもらく~に月10万円稼ぐ! よくわかるAI副業超入門

知識・才能ゼロでもらく~に月10万円稼ぐ! よくわかるAI副業超入門

Additional information such as status, user name, CPU time and window title is displayed.

Useful for troubleshooting

With /V, it is easy to identify unresponsive processes and processes that have been running for a long time.

The /SVC option - show services

The /SVC option shows the services each process hosts.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /SVC
Image Name PID Services
========================= ======== ============================================
svchost.exe 1024 DcomLaunch, PlugPlay, Power
svchost.exe 1156 RpcEptMapper, RpcSs
C:\users\user>

This helps when troubleshooting Windows services.

The /FO option - output format

You can choose the output format from TABLE, LIST and CSV (comma-separated).

Output in CSV format

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /FO CSV
”Image Name”,“PID”,“Session Name”,“Session#”,“Mem Usage"
"System Idle Process”,“0”,“Services”,“0”,“8 K"
"explorer.exe”,“2344”,“Console”,“1”,“95,248 K”
C:\users\user>
Handy for data analysis

CSV output is easy to analyze in Excel or Python scripts. It is also useful for recording process information periodically to track memory usage over time.

Output in LIST format

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /FO LIST
Image Name: explorer.exe
PID: 2344
Session Name: Console
Session#: 1
Mem Usage: 95,248 K
C:\users\user>

The /NH option - hide headers

The /NH option omits the column headers. It works with the TABLE and CSV formats and is useful when passing the results to other commands.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /FO CSV /NH
”System Idle Process”,“0”,“Services”,“0”,“8 K"
"explorer.exe”,“2344”,“Console”,“1”,“95,248 K”
C:\users\user>

Filtering

With the /FI option you can show only the processes that match a condition.

Available filters

FilterOperatorsDescription
STATUSeq, neProcess status (RUNNING, NOT RESPONDING, UNKNOWN)
IMAGENAMEeq, neImage name
PIDeq, ne, gt, lt, ge, leProcess ID
SESSIONeq, ne, gt, lt, ge, leSession number
SESSIONNAMEeq, neSession name
CPUTIMEeq, ne, gt, lt, ge, leCPU time
MEMUSAGEeq, ne, gt, lt, ge, leMemory usage (in KB)
USERNAMEeq, neUser name
SERVICESeq, neService name
WINDOWTITLEeq, neWindow title
MODULESeq, neDLL name

Operators

OperatorMeaning
eqEqual to
neNot equal to
gtGreater than
ltLess than
geGreater than or equal to
leLess than or equal to

Searching for a specific process

Example: show only processes with a specific name.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /FI "IMAGENAME eq chrome.exe"
Image Name PID Session Name Session# Mem Usage
========================= ======== ================ =========== ============
chrome.exe 3456 Console 1 523,456 K
chrome.exe 3789 Console 1 124,532 K
C:\users\user>
Wildcards and notes

In string filters such as IMAGENAME and USERNAME, you can use * as a wildcard (e.g. "IMAGENAME eq chrome*"). The STATUS filter cannot be used with a remote computer (/S).

Filtering by memory usage

Example: show processes using 100 MB (100,000 KB) or more of memory.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /FI "MEMUSAGE gt 100000"
Image Name PID Session Name Session# Mem Usage
========================= ======== ================ =========== ============
chrome.exe 3456 Console 1 523,456 K
chrome.exe 3789 Console 1 124,532 K
C:\users\user>
Unit of memory usage

The memory usage in a filter is in KB (kilobytes). To specify 100 MB, enter 100000.

Filtering by process ID

Example: show processes whose process ID is greater than 1000.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /FI "PID gt 1000"

Combining multiple filters

You can specify several /FI options for more detailed conditions.

Example: show running processes using 50 MB or more of memory.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /FI "STATUS eq RUNNING" /FI "MEMUSAGE gt 50000"

Practical examples

Saving to a file in CSV format

Example: save process information to a file in CSV format.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /FO CSV > processes.csv

This saves the process information in the processes.csv file.

Watch the character encoding

On Japanese Windows, a file saved with redirection is encoded in Shift_JIS (CP932). It may be garbled in tools that expect UTF-8, in which case you need to convert the encoding.

Checking whether a specific process is running

Pass the result of tasklist to the find command and judge by its error level.

@echo off
setlocal

tasklist /FI "IMAGENAME eq notepad.exe" /NH | find /I "notepad.exe" >nul
IF %ERRORLEVEL% EQU 0 (
    echo notepad.exe is running.
) ELSE (
    echo notepad.exe is not running.
)

endlocal
Why find is used as well

When no process matches the condition, tasklist still returns exit code 0 and displays “INFO: No tasks are running which match the specified criteria.” That is why find checks whether the process name appears in the output.

Finding unresponsive processes

Example: check for processes that are not responding.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /V /FI "STATUS eq NOT RESPONDING"
Identifying frozen apps

This command quickly identifies unresponsive applications. After checking the PID, you can force-terminate it with the taskkill command.

Showing the processes of a specific user

Example: show the processes run by a specific user.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /FI "USERNAME eq USER\administrator"

Showing non-system processes

Example: show processes other than NT system processes.

- □ ×
Command Prompt Icon
Command Prompt
Microsoft Windows [Version xx.x.xxxxx.xxx]
(c) 2026 Ribbit App Development All rights reserved.
 
C:\users\user>tasklist /FI "USERNAME ne NT AUTHORITY\SYSTEM"

Recording process information periodically

Example: record process information in a batch file.

The date and time format depends on the regional settings. The following example assumes the yyyy/mm/dd format.

@echo off
setlocal

REM Get the current date and time
set datetime=%date:~0,4%%date:~5,2%%date:~8,2%_%time:~0,2%%time:~3,2%%time:~6,2%
set datetime=%datetime: =0%

REM Save the process information to a file
tasklist /V /FO CSV > "process_log_%datetime%.csv"

echo Process information saved: process_log_%datetime%.csv

endlocal
exit

Summary

This article explained how to check running processes with the tasklist command.

Key points:

  • tasklist shows all running processes
  • /V shows details and /SVC shows service information
  • /FO changes the output format (TABLE, LIST, CSV)
  • /FI filters the output to specific processes
  • You can filter by memory usage or process ID
  • Combine tasklist and find to check whether a specific process is running
  • CSV output can be used for data analysis

With tasklist, you can understand the state of the system in detail and perform troubleshooting and performance monitoring efficiently.

For process management, also see the following.

In preparation
The linked page is currently under construction. Please wait a moment.
In preparation
The linked page is currently under construction. Please wait a moment.

Practice questions

Practice Problem

Which option shows detailed information such as process status, user name and CPU time?

回答がサーバーに送信されることはありません
Practice Problem

Which command shows processes using 100 MB or more of memory?

回答がサーバーに送信されることはありません
#Command Prompt #Batch Files #Command Line #Commands