Command library / ps
ps
List running processes
Snapshots the processes running right now. -e means every process (not just ones from your own shell session), -f adds full details (PID, parent PID, start time, full command line), and -u filters to one user's processes.
Practice psUsage
ps [-e] [-f] [-u user]
Options and flags
-e, -Ashow every process, from every user (not just this session)
-ffull-format listing: PID, parent PID, start time, full command
-uUSERonly this user's processes
Examples
ps -eEvery process on the system — a wide first look.
ps -efSame, but with full details for each one — PID, parent, start time.
ps -u rootOnly processes owned by root — useful when hunting for something running with elevated rights.
Common mistakes
ps -u ps -u root
-u needs a username right after it to filter by — without one there's nothing to filter for.