Security Investigation
Investigate suspicious processes and scheduled activity without destroying evidence.
Unknown process using 90% CPU
Process name
→File location
→Publisher/signature
→Parent process
→Service / Task
→Network activity
→AV/EDR + Logs
Do not kill it first. The process could be Windows, IIS, Plesk, an application, backup, monitoring or another legitimate component.
Scheduled Tasks
taskschd.msc