PS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
BASIC USAGE#
ps # Current user's processes (current terminal) ps -e # All processes ps -f # Full format ps -l # Long format ps aux # BSD syntax - all processes, detailed ps -ef # Unix syntax - all processes, full format
COMMON OPTIONS#
# Selection options -e, -A # All processes -a # All with terminals, except session leaders -u user # Processes by user -U user # Real user ID -p PID # Select by PID -C command # Select by command name -t tty # Select by terminal -g group # Select by group # Output format options -f # Full format -l # Long format -o format # Custom output format -O format # Like -o but with default columns --forest # ASCII art process tree -H # Show process hierarchy
COMMON COMMAND COMBINATIONS#
ps aux # All processes (BSD style) ps -ef # All processes (Unix style) ps -eF # Extra full format ps -ely # Long format with extra info ps auxf # Process tree (BSD) ps -ef --forest # Process tree (Unix) ps axjf # Tree with PPID, PGID, SID ps -u username # User's processes ps -U root -u root # Root's processes ps -C nginx # Processes named nginx ps -p 1234 # Specific PID ps -p 1234,5678 # Multiple PIDs
OUTPUT COLUMNS#
USER/UID # User name or ID PID # Process ID PPID # Parent process ID %CPU # CPU usage percentage %MEM # Memory usage percentage VSZ # Virtual memory size (KB) RSS # Resident set size (KB) TTY # Controlling terminal STAT # Process state START/STIME # Start time TIME # Cumulative CPU time COMMAND/CMD # Command with arguments PRI # Priority NI # Nice value SZ # Size in pages WCHAN # Kernel function (sleep) PSR # Processor assigned
PROCESS STATES (STAT COLUMN)#
R # Running S # Sleeping (interruptible) D # Sleeping (uninterruptible, I/O) T # Stopped (signal or traced) Z # Zombie (defunct) X # Dead I # Idle kernel thread # Additional characters < # High priority (not nice) N # Low priority (nice) L # Pages locked in memory s # Session leader l # Multi-threaded + # Foreground process group
CUSTOM OUTPUT FORMAT (-o)#
ps -eo pid,ppid,user,%cpu,%mem,cmd ps -eo pid,user,stat,comm ps -eo pid,ppid,pgid,sid,comm # Process groups and sessions # Common format specifiers pid # Process ID ppid # Parent PID pgid # Process group ID sid # Session ID user # Username uid # User ID group # Group name gid # Group ID %cpu, pcpu # CPU percentage %mem, pmem # Memory percentage vsz # Virtual memory rss # Resident memory tty # Terminal stat, state # Process state start, lstart # Start time time, cputime # CPU time etime # Elapsed time comm # Command name only args, cmd # Full command with args nice, ni # Nice value pri # Priority psr # Processor wchan # Wait channel nlwp # Number of threads
SORTING#
ps aux --sort=-%cpu # Sort by CPU (descending) ps aux --sort=-%mem # Sort by memory (descending) ps aux --sort=pid # Sort by PID (ascending) ps aux --sort=-pid # Sort by PID (descending) ps aux --sort=user,-%cpu # Multiple sort keys
FILTERING WITH GREP#
ps aux | grep nginx # Find nginx processes ps aux | grep -v grep # Exclude grep from results ps aux | grep '[n]ginx' # Pattern trick to exclude grep ps -ef | grep -E 'nginx|apache' # Multiple patterns
PRACTICAL EXAMPLES#
# Top CPU consumers
ps aux --sort=-%cpu | head -11
# Top memory consumers
ps aux --sort=-%mem | head -11
# Find zombie processes
ps aux | awk '$8=="Z"'
ps aux | grep defunct
# Find process by port (with lsof)
lsof -i :80 | grep LISTEN
# Count processes per user
ps -eo user | sort | uniq -c | sort -rn
# Show all threads
ps -eLf
ps auxH
# Show process tree
ps auxf
pstree
pstree -p # With PIDs
# Long-running processes
ps -eo pid,etime,comm --sort=-etime | head -20
# Memory usage by process
ps -eo pid,user,rss,cmd --sort=-rss | head -20
# Processes using most file descriptors
for pid in $(ps -eo pid --no-headers); do
echo "$(ls /proc/$pid/fd 2>/dev/null | wc -l) $pid"
done | sort -rn | head -10
# Find process by name and get PID
pgrep nginx
pgrep -f "nginx" # Match full command
pidof nginx
# Show specific process details
ps -p $(pgrep nginx) -o pid,ppid,%cpu,%mem,cmd
WATCH PROCESSES#
watch 'ps aux --sort=-%cpu | head -10' watch -n 1 'ps -eo pid,%cpu,%mem,cmd --sort=-%cpu | head -20'
RELATED COMMANDS#
top # Dynamic process viewer htop # Interactive process viewer pgrep pattern # Find PID by name pkill pattern # Kill by name pidof process # Get PID of process pstree # Process tree kill PID # Kill process killall name # Kill by name
/proc FILESYSTEM#
/proc/PID/status # Process status /proc/PID/cmdline # Command line /proc/PID/environ # Environment /proc/PID/fd/ # File descriptors /proc/PID/maps # Memory maps /proc/PID/stat # Status info # Example: Read command line cat /proc/1234/cmdline | tr '\0' ' '
BSD VS UNIX STYLE#
# BSD style (no dash) ps aux # All processes, user format ps axjf # With hierarchy ps ax # All processes # Unix/POSIX style (with dash) ps -ef # All processes, full format ps -eF # Extra full format ps -ely # Long format # Both can be mixed in most implementations ps aux --forest