Retrieving the parent of a process (WinNT)

Did you ever have to find out parent of a process? Well, if so, you'll already have found out that there is no documented relation between processes in Win32 (like there is on UN*X). But, fortunately, the emphasis is on 'documented', as the NT Native API offers LOTS of undocumented APIs that can be useful in a variety of situations. Prototypes and parameter information for about 25 NT API functions can be found in the header files of the NT DDK. The function that serves the basic purpose of this article is 'NtQueryInformationProcess()' and is declared as follows:

    IN HANDLE ProcessHandle,
    IN PROCESSINFOCLASS ProcessInformationClass,
    OUT PVOID ProcessInformation,
    IN ULONG ProcessInformationLength,
When specifying 'ProcessBasicInformation' as the 'ProcessInformationClass' parameter and a valid process handle, 'NtQueryInformationProcess()' fills in a 'PROCESS_BASIC_INFORMATION' structure whose adress has been passed in as the 'ProcessInformation' parameter. The structure member 'InheritedFromUniqueProcessId' holds the process ID of the process that created process specified in 'ProcessHandle'. So, all that has to be done is obtaining a pointer to this function and calling it, supplying the appropriate parameters:

DWORD   GetParentProcessID  (   DWORD   dwPID)
    NTSTATUS                        ntStatus;
    DWORD                           dwParentPID =   0xffffffff;

    HANDLE                          hProcess;
    ULONG                           ulRetLen;

    //  create entry point for 'NtQueryInformationProcess()'
    CREATE_DYNFUNC_5    (   NtQueryInformationProcess,

    //  get process handle
    hProcess    =   OpenProcess (   PROCESS_QUERY_INFORMATION,

    //  could fail due to invalid PID or insufficiant privileges
    if  (   !hProcess)
            return  (   0xffffffff);

    //  gather information
    ntStatus    =   NtQueryInformationProcess   (   hProcess,
                                                    ( void*) &pbi,
                                                    sizeof  (   PROCESS_BASIC_INFORMATION),

    //  copy PID on success
    if  (   !ntStatus)
            dwParentPID =   pbi.InheritedFromUniqueProcessId;

    CloseHandle (   hProcess);

    return  (   dwParentPID);

The only 'fancy' thing in the above code is the 'CREATE_DYNFUNC_5()' convenience macro, which just simplifies the method of typedef'ing a function pointer and loading it by serving as a 'wrapper' ('5' indicates that a pointer to a function taking 5 parameters is created):

#define DYNLOADED_FPTR( ptrname, procname, dllname)\
FPTR_##procname ptrname = \
( FPTR_##procname ) GetProcAddress ( GetModuleHandle (  _TEXT( #dllname)), #procname);

#define CREATE_DYNFUNC_5( ptrname, procname, dllname, rettype, callconv, a1, a2, a3, a4, a5)\
typedef  rettype (callconv *FPTR_##procname) ( a1, a2, a3, a4, a5);\
DYNLOADED_FPTR( ptrname, procname, dllname);
which (in our example) expands to

typedef NTSTATUS (__stdcall *FPTR_NtQueryInformationProcess) ( HANDLE, PROCESSINFOCLASS, PVOID, ULONG, PULONG);
FPTR_NtQueryInformationProcess NtQueryInformationProcess = ( FPTR_NtQueryInformationProcess ) GetProcAddress ( GetModuleHandleA ( "ntdll"), "NtQueryInformationProcess");
NOTE that this may fail if the DLL isn't loaded when the above code is executed! ('ntdll.dll' is loaded for every process running on NT, so this isn't checked here)

Download demo executable - 12.6 KB

Download source - 2.03 KB


  • Command line tool -> getpids

    Posted by xca1019 on 08/12/2007 06:25pm

    Hi, if you are happen write batch files or similar, you can use the getpids tool [1] for retrieving those process ID, parent process ID etc. information. It's output very easy to parse too. [1]

  • To get Parent PID?

    Posted by Legacy on 02/07/2004 12:00am

    Originally posted by: ScratXP

    You do not need to go as far as Nt* APIs to get something as trivial as the Parent PID. While these APIs could be used to find more advanced features, this article does not go into any details and simply shows a useless function of the API.
    Please look at the following APIs:


    These are supported on all platforms.

  • Unsupported

    Posted by Legacy on 09/14/2000 12:00am

    Originally posted by: Michael Quinn

    This is really cool stuff, but it's important to be aware of the following (snipped from the MSDN online help)

    Before I proceed, I’m obligated to point out that NtQueryInformationProcess isn’t part of the Win32 API. Microsoft could change or remove this API in the future. Likewise, this API isn’t available on Windows 95, so be aware of what you’re getting into if you want to use it.

  • Parent Process Info -> stdout

    Posted by Legacy on 07/06/1999 12:00am

    Originally posted by: Hakan Erduman

    ( Cool, if MS does not change these undefined structures 
    and procedures )

    But: Can one possibly use these structs to get
    the parents's standard output / input handles
    (these are not inherited if a console app starts
    a GUI app)

Leave a Comment
  • Your email address will not be published. All fields are required.

Top White Papers and Webcasts

  • This ESG study by Mark Peters evaluated a common industry-standard disk VTl deduplication system (with 15:1 reduction ratio) versus a tape library with LTO-5, drives with full nightly backups, over a five-year period.  The scenarios included replicated systems and offsite tape vaults.  In all circumstances, the TCO for VTL with deduplication ranged from about 2 to 4 times more expensive than the LTO-5 tape library TCO. The paper shares recent ESG research and lots more. 

  • Java developers know that testing code changes can be a huge pain, and waiting for an application to redeploy after a code fix can take an eternity. Wouldn't it be great if you could see your code changes immediately, fine-tune, debug, explore and deploy code without waiting for ages? In this white paper, find out how that's possible with a Java plugin that drastically changes the way you develop, test and run Java applications. Discover the advantages of this plugin, and the changes you can expect to see …

Most Popular Programming Stories

More for Developers

Latest Developer Headlines

RSS Feeds