Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use Get-Process to see each process’s accumulated CPU time, or sample Windows performance counters with Get-Counter to rank current CPU use. These values mean different things: Get-Process’s CPU field is not a live percentage.

What does the CPU(s) column mean?

Get-Process returns process objects. Its CPU property, shown as CPU(s) in the default display, is the cumulative processor time the process has used across all processors, in seconds—not its current utilization. A long-running process can therefore have a large value even if it is idle now. See Microsoft’s Get-Process documentation.

List processes by accumulated CPU time

This snapshot puts the 15 processes with the greatest accumulated CPU time at the top:

Get-Process |
  Sort-Object CPU -Descending |
  Select-Object -First 15 Name, Id, CPU, TotalProcessorTime

Use Id (the PID) to distinguish processes that share a name. To see which process is using CPU now, take an interval measurement or use performance counters instead.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Calculate CPU use over an interval

For a process that remains running, compare its accumulated processor time before and after a timed interval:

$processId = 1234
$p1 = Get-Process -Id $processId
$t1 = Get-Date
Start-Sleep -Seconds 1
$p2 = Get-Process -Id $processId
$t2 = Get-Date

$cpuSeconds = ($p2.TotalProcessorTime - $p1.TotalProcessorTime).TotalSeconds
$wallSeconds = ($t2 - $t1).TotalSeconds
$logicalCpus = [Environment]::ProcessorCount
[math]::Round(100 * $cpuSeconds / ($wallSeconds * $logicalCpus), 2)

Replace 1234 with the target PID. Dividing by the logical processor count expresses the result as a percentage of the whole machine’s CPU capacity. For a process-relative view where one fully busy logical processor is 100%, omit * $logicalCpus from the denominator and label the result accordingly. The measurement is an average over the interval, not an instantaneous reading.

Rank #2
Sale
PowerShell for Sysadmins: Workflow Automation Made Easy
  • Book - powershell for sysadmins: workflow automation made easy
  • Language: english
  • Binding: paperback

The process must survive both readings. If it exits, the second lookup fails; if Windows reuses its PID during the interval, the readings could refer to different processes. For short-lived or changing processes, performance-counter sampling may be more useful.

Rank processes using Windows performance counters

Get-Counter reads Windows performance-counter data. This example takes three samples, one second apart, and displays up to 15 highest process-instance readings from each sample:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Get-Counter 'Process(*)% Processor Time' -SampleInterval 1 -MaxSamples 3 |
  ForEach-Object { $_.CounterSamples } |
  Where-Object {
    $_.InstanceName -notin @('_Total','Idle')
  } |
  Sort-Object CookedValue -Descending |
  Select-Object -First 15 InstanceName, CookedValue

The counter is Windows-specific. An instance name may include a suffix when several processes have the same name, so it is not always a reliable identifier by itself. When exact identity matters, correlate the instance with its PID. Microsoft documents the cmdlet and the process counter path in Get-Counter.

Counter values are not the same metric as the Get-Process cumulative seconds. Interpret the counter according to its Windows performance-counter definition and sampling context; do not treat the two outputs as interchangeable.

Check system-wide CPU context before blaming a process

A process reading is more useful when compared with overall processor activity. Sample these system counters together:

Get-Counter @(
  'Processor(_Total)% Processor Time',
  'Processor(_Total)% User Time',
  'Processor(_Total)% Privileged Time',
  'Processor(_Total)% Interrupt Time',
  'SystemProcessor Queue Length',
  'SystemContext Switches/sec'
) -SampleInterval 1 -MaxSamples 5

Microsoft’s high-CPU troubleshooting guidance also recommends examining process thread and handle counts. Sustained CPU utilization above 85% indicates a CPU bottleneck under that guidance; a single high sample does not establish a sustained bottleneck.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • High overall processor time alongside a high process reading suggests the process may be contributing materially, but the samples alone do not prove cause.
  • High privileged or interrupt time can point to kernel work, drivers, or hardware-related activity rather than ordinary user-mode application work.
  • A rising processor queue or unusually high context switching can add useful system-level context; interpret these alongside workload and repeated samples.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose the right method

Method Metric and identity Best use Platform and remote notes
Get-Process Cumulative processor seconds; process objects include PID. Quick snapshot or a manually calculated interval change. Available across PowerShell platforms; use remoting for remote collection.
Get-Counter Sampled Windows performance-counter readings; instance names may need disambiguation. Repeated monitoring and ranking on Windows. Windows performance counters; remote counter access depends on the environment and permissions.
Win32_Process through CIM/WMI Windows process properties, including process identity. Windows-specific alternative when querying process details. Windows-specific. Microsoft documents it as an alternative in its WMI guidance.

Collect process data remotely and handle architecture limits

For a remote computer configured for PowerShell remoting, run the process query in the remote session:

Invoke-Command -ComputerName 'Server01' -ScriptBlock {
  Get-Process |
    Sort-Object CPU -Descending |
    Select-Object -First 15 Name, Id, CPU, TotalProcessorTime
}

Replace Server01 with the computer name. Remoting must be enabled and authorized, and the account needs access to the target. For Windows CIM/WMI queries, Win32_Process is another option; remote access likewise depends on permissions and configuration.

Use 64-bit PowerShell when you need complete access to 64-bit process modules and properties. Microsoft notes that a 32-bit PowerShell session can return null for fields such as Path or MainModule when examining 64-bit processes; Win32_Process may be an alternative for relevant process information. This limitation concerns those properties, not a reason to read cumulative CPU seconds as a percentage.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.