Windows Server 2008 – How to use the Query Process command
The Query command returns the process ID, and we can query by process ID, just like in Linux.
Step 1 – Query User
Query Users on a Server
Step 2 – Query Session
Step 3 – Query process
Take a note of the PID
Query process *
To reveal system process – eg PID 456 = CSRSS.exe
Step 4 – Query process PID
The user and session of the PID are reported.
Query PID 456