tasklist - List Running Processes
When your PC feels slow, when you want to find the process using lots of memory, or when you want to check whether a specific application is running, the tasklist command is handy.
tasklist shows detailed information about all running processes (tasks) from the command prompt.
This article explains the basics of tasklist, how to filter and format the output, and how to use it in batch files.
If you only want to know whether an app is running, see Checking whether a specific process is running.
What is the tasklist command?
The tasklist command displays a list of processes currently running on the local or a remote computer.
It is like operating Task Manager from the command line, and shows information such as:
- Image name: the name of the running program (e.g. chrome.exe, notepad.exe)
- PID (process ID): a unique number that identifies the process
- Session name: the session the process runs in
- Memory usage: the amount of memory the process uses
- Service information: the services the process hosts
Basic usage
The basic syntax of the tasklist command is as follows.
tasklist [/S system] [/U user] [/P password] [/M module | /SVC | /V] [/FO format] [/NH] [/FI filter]
/V, /SVC and /M cannot be used together.
The simplest usage is to run tasklist without options.
This displays all running processes in a table.
A PID (process ID) is a unique identification number assigned to each process. You use it, for example, when terminating a specific process. Note that the examples show thousands separators in the memory usage for readability, but the PID itself is not displayed with commas.
Options of the tasklist command
tasklist has options to show more detail or change the output format.
| Option | Description |
|---|---|
/V | Shows detailed information (status, window title, etc.) |
/SVC | Shows the services hosted by each process |
/M | Shows processes that have loaded the specified DLL module |
/FO | Specifies the output format (TABLE, LIST, CSV) |
/NH | Hides the column headers |
/FI | Filters the processes to show |
/S | Specifies a remote computer |
/U | Specifies the user name to run the command as |
/P | Specifies the password of the user account |
The /V option - show details
The /V option shows more detailed information.

中小企業経営者のためのRPA入門 RPA導入を成功させる方法

60分でわかる! AIエージェント 超 入門

コマンドラインの黒い画面が怖いんです。

知識・才能ゼロでもらく~に月10万円稼ぐ! よくわかるAI副業超入門
Additional information such as status, user name, CPU time and window title is displayed.
With /V, it is easy to identify unresponsive processes and processes that have been running for a long time.
The /SVC option - show services
The /SVC option shows the services each process hosts.
This helps when troubleshooting Windows services.
The /FO option - output format
You can choose the output format from TABLE, LIST and CSV (comma-separated).
Output in CSV format
CSV output is easy to analyze in Excel or Python scripts. It is also useful for recording process information periodically to track memory usage over time.
Output in LIST format
The /NH option - hide headers
The /NH option omits the column headers. It works with the TABLE and CSV formats and is useful when passing the results to other commands.
Filtering
With the /FI option you can show only the processes that match a condition.
Available filters
| Filter | Operators | Description |
|---|---|---|
STATUS | eq, ne | Process status (RUNNING, NOT RESPONDING, UNKNOWN) |
IMAGENAME | eq, ne | Image name |
PID | eq, ne, gt, lt, ge, le | Process ID |
SESSION | eq, ne, gt, lt, ge, le | Session number |
SESSIONNAME | eq, ne | Session name |
CPUTIME | eq, ne, gt, lt, ge, le | CPU time |
MEMUSAGE | eq, ne, gt, lt, ge, le | Memory usage (in KB) |
USERNAME | eq, ne | User name |
SERVICES | eq, ne | Service name |
WINDOWTITLE | eq, ne | Window title |
MODULES | eq, ne | DLL name |
Operators
| Operator | Meaning |
|---|---|
eq | Equal to |
ne | Not equal to |
gt | Greater than |
lt | Less than |
ge | Greater than or equal to |
le | Less than or equal to |
Searching for a specific process
Example: show only processes with a specific name.
In string filters such as IMAGENAME and USERNAME, you can use * as a wildcard (e.g. "IMAGENAME eq chrome*"). The STATUS filter cannot be used with a remote computer (/S).
Filtering by memory usage
Example: show processes using 100 MB (100,000 KB) or more of memory.
The memory usage in a filter is in KB (kilobytes). To specify 100 MB, enter 100000.
Filtering by process ID
Example: show processes whose process ID is greater than 1000.
Combining multiple filters
You can specify several /FI options for more detailed conditions.
Example: show running processes using 50 MB or more of memory.
Practical examples
Saving to a file in CSV format
Example: save process information to a file in CSV format.
This saves the process information in the processes.csv file.
On Japanese Windows, a file saved with redirection is encoded in Shift_JIS (CP932). It may be garbled in tools that expect UTF-8, in which case you need to convert the encoding.
Checking whether a specific process is running
Pass the result of tasklist to the find command and judge by its error level.
@echo off
setlocal
tasklist /FI "IMAGENAME eq notepad.exe" /NH | find /I "notepad.exe" >nul
IF %ERRORLEVEL% EQU 0 (
echo notepad.exe is running.
) ELSE (
echo notepad.exe is not running.
)
endlocal
When no process matches the condition, tasklist still returns exit code 0 and displays “INFO: No tasks are running which match the specified criteria.” That is why find checks whether the process name appears in the output.
Finding unresponsive processes
Example: check for processes that are not responding.
This command quickly identifies unresponsive applications. After checking the PID, you can force-terminate it with the taskkill command.
Showing the processes of a specific user
Example: show the processes run by a specific user.
Showing non-system processes
Example: show processes other than NT system processes.
Recording process information periodically
Example: record process information in a batch file.
The date and time format depends on the regional settings. The following example assumes the yyyy/mm/dd format.
@echo off
setlocal
REM Get the current date and time
set datetime=%date:~0,4%%date:~5,2%%date:~8,2%_%time:~0,2%%time:~3,2%%time:~6,2%
set datetime=%datetime: =0%
REM Save the process information to a file
tasklist /V /FO CSV > "process_log_%datetime%.csv"
echo Process information saved: process_log_%datetime%.csv
endlocal
exit
Summary
This article explained how to check running processes with the tasklist command.
Key points:
tasklistshows all running processes/Vshows details and/SVCshows service information/FOchanges the output format (TABLE, LIST, CSV)/FIfilters the output to specific processes- You can filter by memory usage or process ID
- Combine
tasklistandfindto check whether a specific process is running - CSV output can be used for data analysis
With tasklist, you can understand the state of the system in detail and perform troubleshooting and performance monitoring efficiently.
Related commands
For process management, also see the following.