Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

The fan is loud, the laptop is slow, and Task Manager shows the CPU pinned at 100%. Ending the top process makes the ticket go away until tomorrow. Here's how to lower CPU usage in a way that sticks: find the process, fix the cause, then set the policy that stops it coming back.

Find the Process Before You Fix Anything

A short spike is normal. Opening an app, installing an update or starting a scan pushes the CPU up for a few seconds. Microsoft's own troubleshooting guidance draws the line at usage that stays at 80% or higher for extended periods. Below that, you're looking at a busy PC, not a broken one.

Start with Task Manager. Sort the Processes tab by the CPU column and note the top name. Then open Resource Monitor (resmon), go to the CPU tab and sort by Average CPU. Task Manager shows the current moment. Resource Monitor's average shows what has been busy for the last minute, and that's the number worth acting on.

When the top line is a container, like System or svchost.exe, reach for Process Explorer from Sysinternals. Open the process properties, go to the Threads tab and look at which thread is busy and what it's running. That's how you tell a driver from a service from a scan.

On a remote PC, PowerShell gets you the top five without a session:

powershell
Get-Counter '\Process(*)\% Processor Time' -SampleInterval 5 -MaxSamples 3 |
  ForEach-Object { $_.CounterSamples | Where-Object InstanceName -notin '_total','idle' |
    Sort-Object CookedValue -Descending | Select-Object -First 5 InstanceName,
    @{n='CPU%';e={[math]::Round($_.CookedValue / $env:NUMBER_OF_PROCESSORS, 1)}} }

The per-process counter adds up across cores, so one process on an 8-core machine can read 400%. Dividing by the core count puts it back on roughly the same scale as Task Manager.

Darien's Tips walks through Process Explorer, the Sysinternals tool Microsoft points to for this job.

The Usual Culprits and the Fix for Each

Once you have a name, the fix depends on what owns it. Each row pairs the fix for today with the policy that stops the repeat.

ProcessWhat it isFix todayPolicy so it doesn't return
MsMpEng.exe (Antimalware Service Executable)Microsoft Defender scanningLet the scan finish, check what it's scanningCap scan CPU, schedule scans off-hours, add tested exclusions
TiWorker.exe (Windows Modules Installer Worker)Windows Update installingLet it finish, then rebootActive hours and a patch window outside the workday
SearchIndexer.exeWindows Search building its indexPause indexing or rebuild a corrupt indexClassic indexing instead of Enhanced
chrome.exe, msedge.exeTabs and extensionsFind the heavy tab with the browser's own task manager (Shift+Esc)Extension allowlist, sleeping tabs
svchost.exeA group of Windows servicesSplit the group to find the serviceFix or disable that service
System interruptsHardware interrupts and driversUpdate the driver, unplug devices one at a timeDriver and firmware baseline
Unknown name at 100% on every corePossibly a cryptominerIsolate the device and scan itApplication allowlisting

For svchost, Microsoft's method is to break each service into its own process with sc config <service> type= own, then watch which one stays busy. Our svchost.exe guide walks through it, including how to spot a fake one.

For browsers, one runaway tab can hold a core by itself. The Chrome memory guide covers the fleet-side settings, and they help CPU as much as RAM.

Windows Search has two modes under Settings, Privacy & security, Search. Microsoft describes Enhanced as indexing the entire PC, which "may use more system resources". Classic covers Documents, Pictures, Music and the desktop, and that's enough for a typical office user.

Defender: Cap the Scan, Then Check for a Loop

Defender's scheduled scans already have a limit. The ScanAvgCPULoadFactor setting defaults to 50, so a scan aims to average no more than half the CPU. Microsoft calls it guidance for the engine, not a hard limit. By default it applies to scheduled scans only, so a custom scan started from a console runs without it. On older hardware, lower the cap and run scans at low priority:

powershell
Set-MpPreference -ScanAvgCPULoadFactor 30 -EnableLowCpuPriority $true

When Defender stays busy outside a scan, that's a different problem. In this r/sysadmin thread from October 2024, MsMpEng used 30-60% CPU on IIS servers for weeks. Microsoft's product group eventually traced it to network inspection activity.

To see what Defender is spending its time on, record it. Run New-MpPerformanceRecording -RecordTo C:\temp\defender.etl, reproduce the slowdown, press Enter, then run Get-MpPerformanceReport -Path C:\temp\defender.etl -TopFiles 10. The report lists the files, paths and processes that cost the most scan time. Exclude only what you've confirmed is safe.

When It's Heat or Power, Not a Process

Sometimes nothing is misbehaving. The CPU is running slow, so ordinary work fills it. Open Task Manager's Performance tab, select CPU and compare Speed with Base speed while the machine is busy. A CPU that sits far below its base speed under load is being held back by heat or a power limit.

That's what one admin found in April 2025 after moving Lenovo laptops to Windows 11 24H2. A power plan pushed through Intune or GPO left Lenovo's thermal service without the Windows 11 power setting it reads. The laptops capped themselves at about 10 W and 500-700 MHz, and removing the policy fixed it.

The lesson carries past Lenovo: test a power plan policy on each hardware model before you push it. Run powercfg /getactivescheme to see which plan is live. Then check the physical side. Blocked vents, a failing fan or dried thermal paste all end in the same throttled clock.

Stop It Coming Back With Fleet Monitoring

The hardest version of this ticket is the one you can't reproduce. The user says the PC sat at 100% all afternoon. You connect, and it's idle.

Monitoring fixes that, as long as it alerts on the right thing. Alert on sustained load, not spikes, with Microsoft's 80% line as the floor. A workable starting point for endpoints:

  1. Trigger at 90% or more for 15 minutes, not on a single sample.
  2. Capture the top five processes when the alert fires, so the ticket arrives with a name in it.
  3. Auto-close the alert if usage drops back, and keep the record.
  4. Review the devices that trip it every week. A repeat offender is either a policy gap or an upgrade conversation.

Then roll the fixes out as policy, not one PC at a time: Defender scan limits, update windows, Classic indexing, a browser extension allowlist and a trimmed startup list. Our guide to debloating Windows 11 covers the startup and preinstalled-app side.

OpenFrame can run the Get-Counter snapshot above as a script across a client's devices and collect the output, so "it was slow yesterday" comes with a list of process names.

The Short Version

To lower CPU usage, find the process first: Task Manager for the name, Resource Monitor for the average, Process Explorer when the name is a container. Fix the cause, whether it's a scan, an update, the indexer, a browser, a service or a driver. If nothing is misbehaving, compare the clock speed with the base speed to catch heat and power limits. Then turn the fix into policy and alert on sustained load, so the next one arrives with the process name attached.

If the busy process turns out to be svchost.exe, the svchost guide linked above is the next read.

Aliaska Varieva

Aliaska Varieva

Head of Platform

Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
Short spikes, even to 100%, are normal when apps open, updates install or a scan starts. Microsoft treats usage that stays at 80% or higher for extended periods as the point to start troubleshooting. Check the average in Resource Monitor rather than a single reading in Task Manager.
Background work is the usual cause: a Microsoft Defender scan (MsMpEng.exe), Windows Update installing (TiWorker.exe) or the Search indexer. Sort Resource Monitor by Average CPU to find it. If no process stands out, compare the CPU speed with its base speed in Task Manager, because a CPU held back by heat or a power limit fills up doing ordinary work.
Lower the scan cap with Set-MpPreference -ScanAvgCPULoadFactor (the default is 50) and enable low CPU priority for scheduled scans, then schedule scans outside working hours. If Defender stays busy outside a scan, record it with New-MpPerformanceRecording and read the top files and processes with Get-MpPerformanceReport before adding any exclusion. Do not turn Defender off to fix performance.
Fix it as policy, not device by device: Defender scan limits, Windows Update active hours, Classic search indexing, a browser extension allowlist and a trimmed startup list. Then alert on sustained load, for example 90% or more for 15 minutes, and capture the top processes when the alert fires so each ticket arrives with a process name.