Tasklist.exe: Your Guide to Windows Task Management Tool

Tasklist.exe is the built-in Windows command that lists every running process, its process ID (PID) and its memory use, on your own PC or on a remote computer.

This guide covers its full syntax, the filters that narrow the list, service and remote queries, exporting results, and fixes for when the command fails.

Microsoft Learn tasklist reference page showing the command's syntax box
Tasklist replaced the older tlist tool and runs on Windows 11, 10 and Windows Server. (Image: Microsoft)

The fastest way to list running processes with tasklist

You need no admin rights and no download for a basic list. The command ships with Windows 11, Windows 10 and Windows Server.

  1. Press Win + R, type cmd and press Enter to open Command Prompt.
  2. Type tasklist and press Enter.
  3. Read the table: each row is one running process with its image name, PID, session and memory usage.
  4. Type tasklist /? and press Enter whenever you need the built-in help for every switch.

The rest of this guide shows how to cut that long list down to the one process you care about.

What Is Tasklist.exe?

Microsoft describes tasklist as a command that displays the currently running processes on the local computer or on a remote computer. It replaced the older tlist tool.

Question Answer
What it does Lists running processes (tasks) with details you can filter and export
Where it runs Windows 11, Windows 10, Windows Server 2016, 2019, 2022 and 2025
Local or remote Both; add /s <computer> to query another machine
What Tasklist.exe can show Image name, PID, session, memory use, status, user name, CPU time, window title, hosted services and loaded DLL modules
Output formats Table (default), list or CSV
Does it change anything? No. It only reads process information; ending a process is the job of taskkill
Is it safe? The genuine command is part of Windows and is read-only

Seeing an unfamiliar system process such as dwm.exe in the output is normal. The guide on what Desktop Window Manager (dwm.exe) does explains one of the most common ones.

Tasklist.exe Syntax and Common Options

The full syntax from Microsoft's reference is: tasklist [/s <computer> [/u [<domain>\]<username> [/p <password>]]] [{/m <module> | /svc | /v}] [/fo {table | list | csv}] [/nh] [/fi <filter> [/fi <filter> [ ... ]]].

Switches are not case-sensitive, and you can combine most of them in one command. Only one of /m, /svc or /v is shown in the syntax braces, with one exception noted below.

Switch What it does Rule to remember
/s <computer> Queries a remote computer by name or IP address Do not type backslashes before the name
/u <domain>\<username> Runs the query with another account's permissions Works only together with /s
/p <password> Supplies the password for the /u account Needs /u
/m <module> Lists tasks that loaded a DLL matching the pattern Without a name it lists every module for each task
/svc Lists the services hosted in each process, untruncated Valid only with table output
/v Shows verbose details such as status, user name, CPU time and window title Use /v with /svc for complete untruncated output
/fo table, /fo list, /fo csv Sets the output format Table is the default
/nh Hides the column headers Valid with table or CSV output
/fi <filter> Includes or excludes processes by a condition Repeat /fi to stack several filters
/? Prints help at the command prompt Safe to run anytime

Viewing and Filtering Running Processes

A filter is written as "NAME operator value" inside double quotes after /fi. The operators are eq (equal), ne (not equal), gt, lt, ge and le.

Text filters such as IMAGENAME accept only eq and ne. Number filters such as PID and MEMUSAGE accept all six operators.

You want to see Run this Filter notes
Every copy of one program tasklist /fi "IMAGENAME eq excel.exe" IMAGENAME takes eq or ne
One process by its ID tasklist /fi "PID eq 1234" PID takes all six operators
Processes using more than about 500 MB tasklist /fi "MEMUSAGE gt 500000" MEMUSAGE is measured in KB
Frozen programs only tasklist /fi "STATUS eq NOT RESPONDING" STATUS values: RUNNING, NOT RESPONDING, UNKNOWN
Processes that used more than one minute of CPU tasklist /fi "CPUTIME gt 00:01:00" CPU time format is HH:MM:SS
Processes run by one account tasklist /fi "USERNAME eq <domain\user>" Takes eq or ne
Everything except SYSTEM processes that are running tasklist /fi "USERNAME ne NT AUTHORITY\SYSTEM" /fi "STATUS eq running" Two stacked /fi filters
A window by its title tasklist /v /fi "WINDOWTITLE eq <title>" Local computer only
Processes in one session tasklist /fi "SESSION eq 1" SESSIONNAME filters by name instead
Detailed CSV of all tasks above PID 1000 tasklist /v /fi "PID gt 1000" /fo csv Example from Microsoft's reference

Using output formats for analysis: /fo list prints one field per line, which is easier to read for a single process. /fo csv produces comma-separated values that Excel opens directly.

To search the plain list for a word instead of an exact name, pipe it into findstr: tasklist | findstr /i excel. The /i switch ignores upper and lower case.

Checking Services and Remote System Tasks

Many Windows services share one host process, so a single svchost.exe row can hide several services. The /svc switch shows which services live inside each process.

Remote queries use your current sign-in by default. Add /u and /p only when another account has the rights on that computer.

Task Command What to expect
Viewing services hosted by processes tasklist /svc A services column lists every service in each process
Services inside svchost.exe only tasklist /svc /fi "IMAGENAME eq svchost.exe" One row per svchost.exe instance with its services
Find the process that hosts one service tasklist /svc /fi "SERVICES eq <service name>" Use the service name, not its display name
Checking tasks on a remote computer tasklist /s srvmain Lists processes on srvmain with your current credentials
Remote query with another account tasklist /s srvmain /u maindom\hiropln /p <password> /u is accepted only when /s is present
Combining remote queries with filters and service output tasklist /s srvmain /svc /fi "MODULES eq ntdll*" Services for remote processes that loaded a DLL starting with ntdll
Which programs loaded a given DLL tasklist /m ntdll* Lists matching tasks and the module

The STATUS and WINDOWTITLE filters are not supported when you query a remote system. Filter by IMAGENAME, PID, MEMUSAGE or USERNAME instead.

Practical Tasklist.exe Examples for Troubleshooting

Each row below matches a common problem to the command that answers it. Replace the sample names and numbers with your own.

Problem Command Next step
Find processes using the most memory tasklist /fi "MEMUSAGE gt 1000000" Lower the number (in KB) until the list shows the few heavy processes
Identify a process by PID from an error message or log tasklist /v /fi "PID eq 4820" The verbose row shows its name, user and window title
Check whether a suspicious executable is active tasklist /fi "IMAGENAME eq <name>.exe" /v If a row appears, note the user account and PID before acting
See which DLLs a suspicious program loaded tasklist /m /fi "IMAGENAME eq <name>.exe" Compare the module list with what the program should need
Capture a process snapshot before and after a problem tasklist /v /fo csv > before.csv, then tasklist /v /fo csv > after.csv Open both files in Excel and look for new or grown rows
Program appears hung tasklist /fi "STATUS eq NOT RESPONDING" End it with taskkill /pid <PID>
Excel still running after you closed it tasklist /fi "IMAGENAME eq excel.exe" A leftover row means a background copy is still open

The > symbol writes the output to a file instead of the screen, and >> appends to an existing file. A timestamped log is as simple as running tasklist >> processlog.txt on a schedule.

Never end a process just because its name is unfamiliar. Look up the name first; many Windows components run under generic names.

Tasklist.exe vs Task Manager, PowerShell, and Taskkill

These four tools overlap, but only tasklist and taskkill run in plain Command Prompt scripts on every Windows edition. Pick by what you need to do next.

Your situation Use this Why
You want a live, clickable view with graphs Task Manager It refreshes continuously and ends tasks with a click; see 12 shortcuts to open Task Manager
You need a one-off text list or a CSV for a report tasklist Plain text output that redirects to a file with >
You are writing a batch file or checking a remote server tasklist Works in cmd scripts and supports /s, /u and /p
You want to sort, calculate or chain results PowerShell Get-Process It returns objects, so a pipeline into Where-Object WorkingSet -GT 20MB filters by real numbers
You need the owner of a process in PowerShell Get-Process -IncludeUserName Needs an elevated PowerShell window for processes you do not own
You found the process and want to stop it taskkill taskkill /pid <PID> or taskkill /im <name>.exe; add /f to force and /t for child processes

How Tasklist.exe compares with Taskkill: tasklist only reads, taskkill ends. The two share the same /s, /u, /p and /fi filter syntax, so a filter you tested with tasklist works unchanged with taskkill.

Taskkill always ends remote processes forcefully, whether or not you add /f. Run the matching tasklist query first to confirm exactly what it will hit.

If you prefer the graphical tool, Windows 11 also has a redesigned version; see how to enable or disable the new Task Manager in Windows 11.

How to check your tasklist filter works

Test a filter on a process you control before you trust it in a script or feed it to taskkill.

  1. Open Notepad.
  2. In Command Prompt, run tasklist /fi "IMAGENAME eq notepad.exe".
  3. Confirm that one row appears and note its PID.
  4. Run tasklist /fi "PID eq <that PID>" and confirm it returns the same row.
  5. Close Notepad and run the first command again; the notepad.exe row is gone.
  6. For exports, open the CSV file and check that the first line holds column headers, unless you added /nh.

Fix tasklist when it does not work

"tasklist is not recognized" or "tasklist command not found"

The command was mistyped, or it was run outside Windows, where tasklist does not exist.

  1. Check the spelling: the command is one word, tasklist, with no space.
  2. Make sure you are on Windows 10, Windows 11 or Windows Server; tasklist is a Windows command only.
  3. Open a fresh Command Prompt with Win + R, cmd, Enter, and run tasklist again.
  4. If Windows still cannot find it, open Command Prompt as administrator and run sfc /scannow to repair protected system files.
  5. Restart the PC after the scan finishes and try again.

Tasklist.exe application error

A damaged system file, or a file that only uses the tasklist.exe name.

  1. Select Start, type cmd, right-click Command Prompt and choose Run as administrator.
  2. Run sfc /scannow and wait for the scan to reach 100 percent.
  3. Restart Windows and run tasklist again.
  4. If the error names a tasklist.exe running from an unusual folder, scan the PC with Windows Security before doing anything else.

Frequently Asked Questions

What does tasklist do?

Tasklist displays every process currently running on a Windows computer, local or remote, with details such as image name, PID, session and memory use. It is read-only: it reports processes but never ends or changes them. Use taskkill to stop a process it shows.

How do I use the tasklist command?

Open Command Prompt, type tasklist and press Enter to list all processes. Add /fi with a filter, such as tasklist /fi "IMAGENAME eq chrome.exe", to narrow the list, and /fo csv to change the output format. Run tasklist /? for the full switch list.

How do I find a specific running process with Tasklist.exe?

Filter by the exact file name with tasklist /fi "IMAGENAME eq excel.exe", or by ID with tasklist /fi "PID eq 1234". For a partial name, pipe the list into findstr: tasklist | findstr /i excel. The /i switch makes the search ignore case.

Can Tasklist.exe show which Windows services are running inside a process?

Yes. Run tasklist /svc to list the services hosted by each process, which is most useful for svchost.exe. The /svc switch works only with the default table output. To find the host of one service, add /fi "SERVICES eq <service name>".

How do I use Tasklist.exe on a remote computer?

Add /s and the computer name or IP address without backslashes, for example tasklist /s srvmain. To use a different account, add /u domain\user and /p password. The STATUS and WINDOWTITLE filters do not work in remote queries.

What is the best way to export Tasklist.exe results to a file?

Use CSV output and redirect it to a file: tasklist /v /fo csv > processes.csv. Excel opens the file directly, with one column per field. Use >> instead of > to append to an existing file, and /nh to leave out the header row.

How is Tasklist.exe different from Task Manager, PowerShell, and Taskkill?

Task Manager is a live graphical view. Tasklist is a text command for scripts, exports and remote servers. PowerShell's Get-Process returns objects you can sort and calculate with. Taskkill ends the processes that tasklist finds, using the same filter syntax.

How do I use Microsoft task list?

If you mean the Windows tasklist command, open Command Prompt and type tasklist. If you want a to-do list for your own tasks, that is a different product: Microsoft's to-do app is Microsoft To Do, which has nothing to do with running processes.

Is tasklist one word?

Yes. The command is typed as one word, tasklist, and the program file is tasklist.exe. Typing task list with a space makes Windows look for a command named task, which fails with a "not recognized" error.

Bottom Line

Use tasklist with /fi filters whenever you need a process list you can save, script or pull from another computer, and switch to taskkill only after the same filter returns exactly the process you expect. Tasklist is built into every current Windows version, needs no admin rights for a local list, and its filters carry over unchanged to taskkill, so testing with tasklist first prevents ending the wrong process.

Philip Celasco

Philip is a Texas-based technology writer and IT administrator at Techdows.com with more than 10 years of experience creating practical content for everyday users and professionals. He specializes in web browsers, particularly Chromium-based platforms such as Google Chrome, Microsoft Edge, Brave, and Opera. Through his work as an IT administrator, Philip has hands-on experience managing devices, configuring browser policies, troubleshooting software and network issues, and helping people resolve problems that affect productivity and security. His articles are based on practical testing and real-world technical experience. He covers browser settings, extensions, performance problems, privacy controls, security features, and Windows troubleshooting. Outside work, Philip enjoys the quieter side of life in Texas and stepping away from the screen when he can. He has two kids, two cats and loves to play golf with his mother during the weekends.

Leave a Reply

Your email address will not be published. Required fields are marked *