Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Use ps aux to take a one-time snapshot of all processes visible in your current Linux host or PID namespace. Use top for a continuously updating view, pgrep -a process-name to find a process by name, and ps -p PID -f to inspect a known process.
# List all visible processes once
ps aux
# Monitor processes live
top
# Find a process by name
pgrep -a firefox
# Inspect a known PID
ps -p 1234 -f
These commands answer different questions: ps provides a snapshot, top and htop monitor changes, pgrep locates processes, and systemctl provides service-manager context.
What does “running process” mean?
In everyday Linux troubleshooting, “running processes” usually means processes that currently exist, whether they are using the CPU or waiting. In Linux process-state terminology, however, R means running or runnable: a process is executing or ready to be scheduled. Most healthy processes spend much of their time sleeping.
Common state codes include:
| Code | Meaning |
|---|---|
R |
Running or runnable |
S |
Interruptible sleep |
D |
Uninterruptible sleep, often waiting for I/O |
T |
Stopped or traced |
Z |
Zombie process |
I |
Idle kernel thread, on systems that report it |
Every listing is a snapshot or sample. A process can change state or exit immediately after it appears. Visibility also depends on permissions and, inside containers, the current PID namespace.
#1 Best Overall
List processes with ps
Processes attached to your terminal
ps
Plain ps normally shows processes associated with your current effective user and terminal. Typical columns are:
- PID: process ID.
- TTY: controlling terminal.
- TIME: accumulated CPU time.
- CMD: command or executable name.
That is why plain ps may show only a few entries.
All visible processes
ps aux
ps aux uses BSD-style options and is the familiar Linux command for a full process listing. Do not write it as ps -aux; the ambiguous hyphenated form can be interpreted differently. A full-format alternative is:
ps -ef
Neither command means literally every process everywhere. They show processes visible to the caller in the current host or PID namespace. The ps manual documents selection, formatting, sorting, and state behavior.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteUnderstand ps aux output
| Column | Meaning |
|---|---|
USER |
User owning the process |
PID |
Process ID |
%CPU |
CPU usage reported by this snapshot |
%MEM |
Percentage of physical memory |
VSZ |
Virtual memory size |
RSS |
Resident memory currently in RAM |
TTY |
Controlling terminal |
STAT |
Process state and additional flags |
START |
Start time or date |
TIME |
Accumulated CPU time |
COMMAND |
Command and arguments |
The %CPU value from ps is not a permanent measurement. It can differ from the sampled, continuously updated values shown by top or htop.
Choose columns and sort the result
# Useful custom listing
ps -e -o pid,ppid,user,stat,%cpu,%mem,etime,cmd
# Highest CPU first
ps -e -o pid,ppid,user,stat,%cpu,%mem,etime,cmd --sort=-%cpu
# Highest memory first
ps -e -o pid,ppid,user,stat,%cpu,%mem,etime,cmd --sort=-%mem
The -o option lets you select fields such as the parent PID (PPID), state, elapsed time, CPU, memory, and command line.
List only processes in the R state
ps -e -r -o pid,ppid,user,stat,%cpu,%mem,cmd
On Linux procps, -r restricts selection to processes currently running or runnable. The output may be empty or very short because processes frequently sleep, and state can change during sampling.
For a teaching-oriented display filter, you can inspect the state field explicitly:
Recommended Free Tools
ps -e -o pid,stat,cmd | awk '$2 ~ /^R/'
This is not a perfectly synchronized measurement: ps has already taken its snapshot before awk filters it.
Monitor processes live with top
top
top provides a dynamic system summary and repeatedly samples process information. Inside top:
- Press q to quit.
- Press P to sort by CPU usage.
- Press M to sort by memory usage.
- Press 1 to show individual CPU states.
- Press k to enter a PID and send a signal.
- Press c to toggle command name and full command line where supported.
- Press H to toggle thread display on implementations that support it.
For a noninteractive sample suitable for remote diagnostics or scripts:
top -b -n 1
Use multiple samples when investigating a transient spike. A single snapshot can miss it.
Use htop for easier interactive inspection
htop
htop offers scrolling, filtering, tree display, mouse interaction, and convenient process selection. It is not guaranteed to be installed by default, and controls vary by version and configuration. Press F1 or ? inside the program for the applicable help screen.
# Current user's processes
htop -u "$USER"
# Only selected PIDs
htop -p 1234
# Tree view
htop -t
Distribution-specific installation examples are:
# Debian or Ubuntu
sudo apt install htop
# Fedora
sudo dnf install htop
# Arch Linux
sudo pacman -S htop
Package names and package managers differ across Linux distributions. See the htop manual for supported options and process-state details.
Find a process by name with pgrep
# Match the process name and show PID plus name
pgrep -a firefox
# Search the complete command line
pgrep -af 'python.*app.py'
# Limit the search to your user
pgrep -u "$USER" -a
# Find processes in the R state
pgrep -r R -a
pgrep prints matching PIDs directly, making it more suitable for scripts than a pipeline through grep. Without -f, it matches the process name rather than the complete command line. Its patterns are regular expressions, so quote patterns when needed. See the pgrep manual.
Rank #3
Avoid the fragile beginner pattern:
ps aux | grep firefox
It can match the grep command itself and can miss a process when the desired text appears only in its arguments. If a pipeline is unavoidable, grep '[f]irefox' avoids matching that exact grep command, but pgrep is the preferred solution.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallView parent-child relationships
# Show a process tree with PIDs
pstree -p
# Start at a particular PID
pstree -p 1234
# Alternative using ps
ps -e --forest
A tree reveals which shell, wrapper, supervisor, script, or service launched a process and which worker processes it created. This is often more useful than a flat list when diagnosing service restarts or unexpectedly inherited processes. See the pstree manual.
Inspect a specific PID
ps -p 1234 -f
ps -p 1234 -o pid,ppid,user,stat,lstart,etime,%cpu,%mem,cmd
For lower-level kernel-exposed details, inspect the process’s numeric directory under /proc:
cat /proc/1234/status
tr ' ' ' ' < /proc/1234/cmdline
readlink -f /proc/1234/exe
readlink -f /proc/1234/cwd
ls -l /proc/1234/fd
status contains structured metadata, cmdline contains the argument list, exe points to the executable, cwd identifies the working directory, and fd lists open file descriptors. Access can be restricted by ownership, security policy, mount options, or namespaces. See the proc(5) and proc_pid(5) documentation.
A PID identifies a process instance, not a permanent application identity. The process may exit between commands, and a PID can eventually be reused. Before acting on a PID obtained earlier, verify its command line or executable if the operation matters.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Check processes belonging to a systemd service
# Inspect a known service
systemctl status nginx
# List currently running service units
systemctl list-units --type=service --state=running
# Show the service's main PID
systemctl show nginx -p MainPID
Systemd services and Linux processes are related but not identical. A service unit may supervise a main process plus workers, and a process may exist without being managed by systemd. Systemd groups service processes in cgroups, allowing status output to show the unit’s associated process group.
systemctl list-units concerns units currently loaded and, by default, active, failed, or pending units. systemctl list-unit-files --type=service answers a different question: which service unit files are installed.
Rank #4
# Discover installed service names
systemctl list-unit-files --type=service
# Check a user-level service
systemctl --user status service-name
If a service is “not found,” it may have a different unit name, may not be managed by systemd, may belong to a user session, or the distribution may use another init system. The systemctl manual documents the available unit and process views.
Shell jobs are different from system processes
To see background and stopped jobs launched by the current shell, use:
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →sleep 300 &
jobs -l
fg %1
bg %1
jobs -l reports the shell’s job-control table, not every process on the system. A job can contain a process group, while ps and top provide broader process views.
List numeric process directories in /proc
printf '%sn' /proc/[0-9]*
Numeric directory names correspond to PIDs visible in the current /proc mount. This demonstrates the underlying interface but is not a replacement for ps: it does not format metadata, shell globbing can be awkward if there are no matches, and processes may disappear while you inspect them. The /proc filesystem may also be restricted with options such as hidepid.
Troubleshoot missing or unexpected processes
Only a few processes appear
Use ps aux or ps -ef instead of plain ps. If information about another user’s processes is still missing, permissions, hidepid, SELinux, ptrace restrictions, or container isolation may be responsible. Administrative access may reveal more, but it should not be assumed to bypass every security policy.
A process is missing inside a container
PID namespaces control process visibility. A process list inside a container may show only processes in that namespace, while the host can see additional processes. Therefore, “all processes” always means all processes visible from the current namespace and subject to its permissions.
pgrep finds nothing
The executable name may differ from the name you searched for, the text may appear only in arguments, the process may have exited, or your permissions may limit visibility. Try a full-command-line search:
Best Value
pgrep -af 'full-or-partial-command-line'
top shows high CPU but ps does not
This can be normal. ps reports a snapshot, while top and htop calculate changing values from samples over time. Capture repeated snapshots:
ps -eo pid,ppid,user,stat,%cpu,%mem,etime,cmd --sort=-%cpu | head
sleep 1
ps -eo pid,ppid,user,stat,%cpu,%mem,etime,cmd --sort=-%cpu | head
The process disappeared or the PID changed
Processes can terminate between discovery and inspection. A PID refers to one process instance and may eventually be reused. Scripts should handle missing PIDs and verify /proc/PID/cmdline or /proc/PID/exe before sending a signal.
The process is a zombie
A Z process has already exited but remains as an entry until its parent collects the exit status. Killing the zombie itself is generally ineffective. Investigate the parent process and its reaping behavior rather than treating the zombie like a live worker.
Threads appear as separate tasks
A process can contain multiple threads. Depending on command options and configuration, ps, top, and htop can display threads as well as processes. Do not automatically interpret every displayed task as a separate application.
Quick command reference
| Task | Command | What it shows |
|---|---|---|
| Current terminal processes | ps |
One-time snapshot |
| All visible processes | ps aux |
BSD-style full listing |
| All visible processes, full format | ps -ef |
Full-format listing |
| Live resource view | top |
Continuously updating display |
| Interactive viewer | htop |
Scrollable and filterable view |
| Find by name | pgrep -a name |
Matching PIDs and names |
| Search full command line | pgrep -af pattern |
Arguments included in matching |
| Process hierarchy | pstree -p |
Parent-child tree with PIDs |
| Current shell jobs | jobs -l |
Jobs known to this shell |
Only R-state processes |
ps -e -r ... |
Running or runnable snapshot |
| Known systemd service | systemctl status name |
Unit state and associated processes |
| Kernel-level details | /proc/PID/* |
Raw process metadata |
Stopping a process: proceed carefully
Listing a process is harmless; sending it a signal can interrupt work or stop a service. If you have confirmed the PID and need to act:
kill PID
kill -TERM PID
kill -KILL PID
SIGTERM is the normal graceful request. SIGKILL prevents cleanup and should be reserved for cases where a process will not respond to safer signals. Recheck the PID immediately before acting, particularly in scripts or automated troubleshooting.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

