โ† All cheat sheets

PS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

BASIC USAGE#

ps                                  # Current user's processes (current terminal)
ps -e                               # All processes
ps -f                               # Full format
ps -l                               # Long format
ps aux                              # BSD syntax - all processes, detailed
ps -ef                              # Unix syntax - all processes, full format

COMMON OPTIONS#

# Selection options
-e, -A                              # All processes
-a                                  # All with terminals, except session leaders
-u user                             # Processes by user
-U user                             # Real user ID
-p PID                              # Select by PID
-C command                          # Select by command name
-t tty                              # Select by terminal
-g group                            # Select by group

# Output format options
-f                                  # Full format
-l                                  # Long format
-o format                           # Custom output format
-O format                           # Like -o but with default columns
--forest                            # ASCII art process tree
-H                                  # Show process hierarchy

COMMON COMMAND COMBINATIONS#

ps aux                              # All processes (BSD style)
ps -ef                              # All processes (Unix style)
ps -eF                              # Extra full format
ps -ely                             # Long format with extra info
ps auxf                             # Process tree (BSD)
ps -ef --forest                     # Process tree (Unix)
ps axjf                             # Tree with PPID, PGID, SID
ps -u username                      # User's processes
ps -U root -u root                  # Root's processes
ps -C nginx                         # Processes named nginx
ps -p 1234                          # Specific PID
ps -p 1234,5678                     # Multiple PIDs

OUTPUT COLUMNS#

USER/UID                            # User name or ID
PID                                 # Process ID
PPID                                # Parent process ID
%CPU                                # CPU usage percentage
%MEM                                # Memory usage percentage
VSZ                                 # Virtual memory size (KB)
RSS                                 # Resident set size (KB)
TTY                                 # Controlling terminal
STAT                                # Process state
START/STIME                         # Start time
TIME                                # Cumulative CPU time
COMMAND/CMD                         # Command with arguments
PRI                                 # Priority
NI                                  # Nice value
SZ                                  # Size in pages
WCHAN                               # Kernel function (sleep)
PSR                                 # Processor assigned

PROCESS STATES (STAT COLUMN)#

R                                   # Running
S                                   # Sleeping (interruptible)
D                                   # Sleeping (uninterruptible, I/O)
T                                   # Stopped (signal or traced)
Z                                   # Zombie (defunct)
X                                   # Dead
I                                   # Idle kernel thread

# Additional characters
<                                   # High priority (not nice)
N                                   # Low priority (nice)
L                                   # Pages locked in memory
s                                   # Session leader
l                                   # Multi-threaded
+                                   # Foreground process group

CUSTOM OUTPUT FORMAT (-o)#

ps -eo pid,ppid,user,%cpu,%mem,cmd
ps -eo pid,user,stat,comm
ps -eo pid,ppid,pgid,sid,comm      # Process groups and sessions

# Common format specifiers
pid                                 # Process ID
ppid                                # Parent PID
pgid                                # Process group ID
sid                                 # Session ID
user                                # Username
uid                                 # User ID
group                               # Group name
gid                                 # Group ID
%cpu, pcpu                          # CPU percentage
%mem, pmem                          # Memory percentage
vsz                                 # Virtual memory
rss                                 # Resident memory
tty                                 # Terminal
stat, state                         # Process state
start, lstart                       # Start time
time, cputime                       # CPU time
etime                               # Elapsed time
comm                                # Command name only
args, cmd                           # Full command with args
nice, ni                            # Nice value
pri                                 # Priority
psr                                 # Processor
wchan                               # Wait channel
nlwp                                # Number of threads

SORTING#

ps aux --sort=-%cpu                 # Sort by CPU (descending)
ps aux --sort=-%mem                 # Sort by memory (descending)
ps aux --sort=pid                   # Sort by PID (ascending)
ps aux --sort=-pid                  # Sort by PID (descending)
ps aux --sort=user,-%cpu            # Multiple sort keys

FILTERING WITH GREP#

ps aux | grep nginx                 # Find nginx processes
ps aux | grep -v grep               # Exclude grep from results
ps aux | grep '[n]ginx'             # Pattern trick to exclude grep
ps -ef | grep -E 'nginx|apache'     # Multiple patterns

PRACTICAL EXAMPLES#

# Top CPU consumers
ps aux --sort=-%cpu | head -11

# Top memory consumers
ps aux --sort=-%mem | head -11

# Find zombie processes
ps aux | awk '$8=="Z"'
ps aux | grep defunct

# Find process by port (with lsof)
lsof -i :80 | grep LISTEN

# Count processes per user
ps -eo user | sort | uniq -c | sort -rn

# Show all threads
ps -eLf
ps auxH

# Show process tree
ps auxf
pstree
pstree -p                           # With PIDs

# Long-running processes
ps -eo pid,etime,comm --sort=-etime | head -20

# Memory usage by process
ps -eo pid,user,rss,cmd --sort=-rss | head -20

# Processes using most file descriptors
for pid in $(ps -eo pid --no-headers); do
    echo "$(ls /proc/$pid/fd 2>/dev/null | wc -l) $pid"
done | sort -rn | head -10

# Find process by name and get PID
pgrep nginx
pgrep -f "nginx"                    # Match full command
pidof nginx

# Show specific process details
ps -p $(pgrep nginx) -o pid,ppid,%cpu,%mem,cmd

WATCH PROCESSES#

watch 'ps aux --sort=-%cpu | head -10'
watch -n 1 'ps -eo pid,%cpu,%mem,cmd --sort=-%cpu | head -20'
top                                 # Dynamic process viewer
htop                                # Interactive process viewer
pgrep pattern                       # Find PID by name
pkill pattern                       # Kill by name
pidof process                       # Get PID of process
pstree                              # Process tree
kill PID                            # Kill process
killall name                        # Kill by name

/proc FILESYSTEM#

/proc/PID/status                    # Process status
/proc/PID/cmdline                   # Command line
/proc/PID/environ                   # Environment
/proc/PID/fd/                       # File descriptors
/proc/PID/maps                      # Memory maps
/proc/PID/stat                      # Status info

# Example: Read command line
cat /proc/1234/cmdline | tr '\0' ' '

BSD VS UNIX STYLE#

# BSD style (no dash)
ps aux                              # All processes, user format
ps axjf                             # With hierarchy
ps ax                               # All processes

# Unix/POSIX style (with dash)
ps -ef                              # All processes, full format
ps -eF                              # Extra full format
ps -ely                             # Long format

# Both can be mixed in most implementations
ps aux --forest