A practical reference for sysadmins using htop to inspect process trees, detect lateral movement, and monitor Linux server resources interactively.

What is htop?

htop is an enhanced interactive process viewer for Linux, providing a colour-coded, ncurses-based interface that improves significantly on the standard top command. Its most security-relevant feature is the process tree view, which renders parent-child process relationships as a visual hierarchy. This is critical for detecting web shells: a legitimate Apache or nginx process should only spawn expected child processes. When a web server process spawns a bash or python shell, that anomalous parent-child relationship is immediately visible in htop’s tree view — whereas flat process lists require manual PPID cross-referencing. htop also allows scrolling horizontally to see full command arguments, colour-coded CPU bars per core, and mouse interaction for selecting and killing processes. It is not installed by default on all distributions but is available in standard package repositories on every major Linux distro.

Syntax

htop
htop -u www-data
htop -p 1234,5678
htop -d 10
htop --tree

Run htop with no arguments for the full interactive dashboard. Use -u to filter by user. The -d flag sets the refresh delay in tenths of a second (e.g. -d 10 = 1 second). The --tree flag starts htop with process tree view enabled immediately, without needing to press F5.

Key Options and Interactive Commands

Flag / ParameterDescriptionSecurity Note
-u <user>Filter display to processes owned by the specified userUse to audit service accounts such as www-data, nginx, postgres for unexpected child processes
--tree / F5Enable process tree view showing parent-child hierarchyPrimary tool for detecting web shells — a web server spawning bash is immediately visible
F9Send a signal to the selected process (kill menu)—
F6Sort by column — CPU%, MEM%, PID, USER, etc.—
F4Filter processes by name stringQuickly isolate all processes matching a suspicious name pattern
SpaceTag a process for bulk operations—
-d <delay>Set refresh interval in tenths of a second—
H (interactive)Toggle display of user threadsHide threads to reduce noise when scanning for rogue processes

Common Use Cases

Detect a Web Shell Spawning a Bash Process

A web shell executed through a vulnerable PHP or upload endpoint will cause a web server worker process to spawn an interactive shell. In htop’s tree view, this appears as apache2 or php-fpm with a child bash or sh process — a relationship that should never occur legitimately. This is one of the fastest ways to confirm an active web shell exploitation without log analysis.

htop --tree
# Look for: apache2 -> bash, nginx -> python, php-fpm -> sh

Audit All Processes Under a Service Account

Service accounts such as www-data, postgres, and redis should only run their expected processes. Filtering htop to a single user and enabling tree view gives a complete picture of everything that service account is running — including any processes spawned through exploitation.

htop -u www-data --tree

Trace a Suspicious PID Back to Its Origin

When an alert or log entry references a suspicious PID, htop’s tree view lets you immediately see what spawned it. Navigating up the tree from the suspicious process to its parent and grandparent reveals the initial access vector — whether a cron job, a web request, or an interactive SSH session.

htop --tree
# Use F4 to filter by the suspicious process name, then expand tree

Security Relevance: Web Shell Detection via Process Tree Inspection

The most powerful security use of htop is process tree analysis during incident response. When an attacker exploits a web application vulnerability and drops a web shell, they gain the ability to execute arbitrary commands through the web server process. The resulting process tree is forensically distinctive: a web server daemon (which should only spawn worker processes of its own type) instead spawns a shell interpreter or a network tool. htop makes this anomaly visually obvious — no log parsing required. This is particularly valuable in the early minutes of an incident when speed matters. Beyond web shell detection, htop is useful for identifying cryptominers that spawn multiple child threads, persistence implants that re-spawn after being killed (visible as a parent process continuously creating children), and privilege escalation attempts where a low-privilege process spawns a higher-privilege child through a SUID binary.

  • A web server process (apache2, nginx, php-fpm) spawning bash or sh is a critical indicator of web shell exploitation
  • A process that immediately re-spawns after being killed has a parent maintaining it — kill the parent, not just the child
  • htop is not installed by default on all systems — verify its presence before relying on it during incident response
  • Attackers may rename malicious binaries to mimic legitimate process names — always check the full path by scrolling right in htop

Practical Examples

Start htop with tree view to inspect process parent-child relationships

htop --tree

Immediately shows the full process hierarchy. Scan for web server processes with unexpected shell children — this is the primary web shell detection pattern.

Filter to a specific user and show their full process tree

htop -u www-data --tree

Restricts the view to the web server user and renders all its processes as a tree. Any shell or network tool under www-data is a high-confidence indicator of compromise.

Install htop if not present (Debian/Ubuntu and RHEL/AlmaLinux)

# Debian/Ubuntu
apt install htop -y

# RHEL / AlmaLinux / Rocky
dnf install htop -y

htop is available in standard repositories on all major distributions. Install it immediately on any new server so it is available when needed during an incident.

Troubleshooting Common Issues

Problem: htop is not installed on the system

Solution: Install with apt install htop (Debian/Ubuntu) or dnf install htop (RHEL/AlmaLinux). If package installation is unavailable during an incident, fall back to ps -eo pid,ppid,user,cmd --forest which provides a text-based process tree from the standard ps binary.

Problem: Process tree view shows too many threads, making it hard to read

Solution: Press H to toggle user thread display off. This collapses thread entries and leaves only the main process entries visible, making the tree structure much easier to navigate during triage.

Problem: Cannot see the full command path for a suspicious process

Solution: Scroll right with the arrow keys in htop to see the full command line including arguments and path. Alternatively, once you have the PID, run cat /proc/<PID>/cmdline | tr '\0' ' ' for the complete command string including all arguments.

Summary

htop’s process tree view is the most direct way to detect web shell exploitation on a running Linux server. By making parent-child process relationships visually explicit, it surfaces the anomalous pattern of a web server spawning a shell interpreter — a relationship that is nearly impossible in legitimate operation. Install htop on every server during provisioning so it is available when needed, not after an incident has already begun.

  • Start with htop --tree during any web application incident to check for shell processes spawned by web server workers
  • Use htop -u www-data --tree to audit the complete process footprint of your web server user
  • A process that re-spawns immediately after being killed has a watchdog parent — find and kill the parent process first

Is Your Linux Server Monitored 24/7?

INTRAM provides managed Linux hosting with continuous process and performance monitoring. We detect anomalies before they become incidents — so your team can focus on building, not firefighting.

Explore Managed Hosting

Let’s assess what your business actually needs.

We will use these details only to understand your request and reply appropriately.