Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / MALWARE REVERSE / LINUX / CRASH

Process

CommandWhat it doesWhen to use
psList all processesGet initial overview
ps -uShow only user processesReduce noise (hide kernel threads)
ps <name>Find process by nameLocate suspicious process quickly
ps -p <pid>Show parent chain (walk UP)Trace origin of a process
ps -c <pid>Show children (walk DOWN)Find spawned payloads
ps -a <pid>Show arguments/envSee how process was executed
ps -g <pid>Show thread groupAnalyze multi-threaded processes
set <pid>Switch to process contextPrepare for deeper inspection
filesShow open files of current processSee what the process accessed
task <addr>Show task_structLow-level process inspection