🔹 Windows System Processes
Understanding parent-child process relationships is crucial for system monitoring, malware analysis, and forensic investigations. Here are some important processes and their typical parent-child
🔹 Windows System Processes
1️⃣ System Idle Process (PID 0)
2️⃣ System Process (PID 4)
3️⃣ smss.exe (Session Manager Subsystem)
4️⃣ csrss.exe (Client/Server Runtime Subsystem)
5️⃣ wininit.exe (Windows Initialization Process)
6️⃣ services.exe (Service Control Manager)
7️⃣ lsass.exe (Local Security Authority Subsystem)
8️⃣ explorer.exe (Windows Explorer)
9️⃣ cmd.exe (Command Prompt)
🔟 powershell.exe
1️⃣1️⃣ rundll32.exe
1️⃣2️⃣ wmiprvse.exe (WMI Provider Host)
1️⃣3️⃣ taskhost.exe / taskhostw.exe
🔹 Additional Critical Windows Processes
1️⃣ winlogon.exe (Windows Logon Application)
2️⃣ userinit.exe
3️⃣ explorer.exe
4️⃣ msiexec.exe (Windows Installer)
5️⃣ wscript.exe & cscript.exe (Windows Scripting Hosts)
6️⃣ rundll32.exe
7️⃣ regsvr32.exe (Registry Server)
8️⃣ conhost.exe (Console Window Host)
9️⃣ dllhost.exe (COM Surrogate)
🔟 werfault.exe (Windows Error Reporting)
1️⃣1️⃣ consent.exe (UAC Prompt)
1️⃣2️⃣ taskeng.exe (Task Scheduler Engine)
Last updated