Command library / tasklist
tasklist
List running processes
Lists every running process with its PID, memory use, and (with /svc) which Windows services it's hosting. Pairs directly with netstat -ano: netstat gives you a suspicious PID, tasklist tells you what program that PID actually is.
Practice tasklistUsage
Options and flags
/fiFILTERfilter the results, e.g. "PID eq 4444" or "IMAGENAME eq chrome.exe"
/svcshow the Windows services hosted inside each process
/vverbose: also show status, user name and CPU time
/mshow which DLL modules each process has loaded
Examples
tasklistEvery running process with its PID and memory usage.
tasklist /svcWhich services each process (especially svchost.exe) is actually hosting.
tasklist /fi "PID eq 4444"Which program owns PID 4444 — exactly what you need after spotting it in netstat.
tasklist /fi "IMAGENAME eq chrome.exe"Every chrome.exe process and its PID.
Common mistakes
The filter expression has spaces in it, so it must be quoted as ONE argument, or cmd splits it into three separate (meaningless) arguments.