Process Explorer: what it does and who it is for
What Process Explorer shows
Process Explorer is the tool people reach for when Task Manager is not answering the question. Its default view is not a flat list but a tree organised by parent and child, which immediately shows that a window belongs to a helper process rather than to the program the user launched. The upper pane lists processes with CPU, private bytes, working set, commit size, I/O counters, a description and the company name, and it can replace Task Manager entirely so that the familiar key combination opens this view instead. The lower pane is the part that turns it from a monitor into a diagnostic instrument: switch it between handles, DLLs and threads, and the selected process reveals exactly which file, registry key, event or mutex it holds open.
How the workflow fits together
Nothing needs installing. Extract the archive, run the executable, and accept the licence on first use; running elevated is necessary for handle inspection of processes owned by other users. The workflow starts with a culprit: a folder that will not eject, a process consuming CPU, or a file that appears locked. Find the process in the tree, look at the lower pane, and read the handle names directly. The properties dialog adds the tabs that matter for triage, including the signing certificate, the command line that launched the process, its environment, and its network connections. A search command answers the reverse question by name: typing the name of a file, a handle or a DLL finds every process that has it loaded or open.
Configuration, limits and trade-offs
Column selection and update speed are adjustable, and a highlighted-duration setting colours processes that have started within the last few seconds, which is a fast way to catch a short-lived helper. The VirusTotal integration uploads the selected file's hash for a lookup, which is useful but is a network request and should be a conscious choice on a sensitive machine. Symbols can be resolved from Microsoft's store to turn a module offset into a function name, at the cost of a download on first use. The limitations are structural rather than accidental: the tool observes a system that is already running, so an event that lasts milliseconds may be missed unless the tracing tools in the same suite are used, and a process protected by a kernel driver may expose almost nothing to inspection from user mode.
Who should choose something else
For everyday use Task Manager and the Settings app are enough, and Resource Monitor covers a single locked file or a network question without any download. On a heavily loaded server, an always-on monitoring or endpoint agent that records history is more useful than a snapshot tool you open after the fact, because the evidence you need has usually already scrolled away. And anyone whose actual question is what changed on the filesystem or in the registry should reach for a trace-based tool from the same vendor instead of a process viewer, since process state and file activity are different kinds of evidence.
- Best for
- Anyone who needs to know which process owns a locked file or port, what a process has loaded, and whether its binary is properly signed.
- Good to know
- Handle inspection needs elevation, it reports only what the running system exposes, and the hash lookup is a network request that should be a deliberate choice.
Process Explorer replaces the task list with a full process tree and a handle inspector. The lower pane is what turns a process list into an answer, because it shows the handles and modules each process holds.
How to get started
- Download ProcessExplorer.zip and extract it.
- Run the executable and accept the licence prompt.
- Start it elevated if you need to inspect system processes.
- Set the lower pane to Handles to see open files and keys.
- Use Find Handle or DLL to trace a name to its owner.
- Optionally replace Task Manager from the Options menu.
Questions & answers
Can it tell me which process locks a file?
Yes. Set the lower pane to Handles and search for the file name, or use Find Handle or DLL.
Does it need installing?
No. It is a portable executable from Microsoft's Sysinternals collection.
What does virus total integration do?
It submits the selected file's hash for a reputation lookup, which is a network request you choose to make.