I am trying to obtain modules that a process running on a remote computer has loaded

Viewed 294

how to obtain modules that a process running on a remote computer has loaded using PowerShell.

There are some process modules that I am getting error for, like permission denied and cannot enumerate. How can i address these error.

Cannot enumerate the modules of the "services" process.+ CategoryInfo : PermissionDenied: (System.Diagnostics.Process (services):Process) [Get-Process], ProcessCommandException+ FullyQualifiedErrorId : CouldnotEnumerateModules,Microsoft.PowerShell.Comands.GetProcessCommand + PSComputerName

using command:

$Module = Invoke-Command -Session $session -ScriptBlock { Get-Process -Module }
1 Answers

The problem isn't specific to remoting: there are processes whose modules fundamentally[1] cannot be enumerated due to lack of permissions, even when running with elevation (as admin).

Since the errors report are non-terminating errors, you can simply ignore the (all) errors with -ErrorAction Ignore at the source:

Invoke-Command -Session $session -ScriptBlock { Get-Process -Module -ErrorAction Ignore }

If you want to capture the error messages, so you can determine the processes for which enumeration failed, use -ErrorVariable errs -ErrorAction SilentlyContinue, which silences the errors, but collects them in variable $errs for later inspection:

Invoke-Command -Session $session -ScriptBlock { Get-Process -Module } -ErrorVariable errs -ErrorAction SilentlyContinue

Specifically, $errs.TargetObject will list the process objects whose modules couldn't be enumerated.


If the intent is to find (and possibly kill) all processes that use a module (DLL) of interest, use the standard tasklist.exe utility or taskkill.exe utility with the /m parameter.

$moduleOfInterest = 'oleaut32.dll' # example DLL
$pids = (tasklist /m $moduleOfInterest /fo csv | ConvertFrom-Csv).PID

# Alternatively, use `taskkill` in lieu of `tasklist` above in 
# order to kill the processes directly.
if ($pids) { Stop-Process -Id $pids -WhatIf }

Note: The -WhatIf common parameter in the command above previews the operation. Remove -WhatIf, once you're sure the operation will do what you want.

However, with this approach you may run into permission issues as well.

Note that tasklist.exe and taskkill.exe have a built-in remoting feature via parameter /S, allowing a single remote machine to be targeted.

However, using PowerShell's general-purpose remoting (via Invoke-Commands -ComputerName / -Session parameters) gives you more flexibility, notably the ability to target multiple computers in parallel.


[1] At least by default, elevation alone isn't enough; if anyone knows if there's a way to enumerate nonetheless, do let us know. This related question asks for that information specifically.

Related