Windows Command #34 – sc query (Windows OS)

Realistic Windows service administration workstation showing server racks and service-state monitoring with neon-green technical lighting.

Elementary Overview

In Windows, many important programs run in the background as services. The built-in sc.exe utility talks to the Service Control Manager (SCM), while sc query asks the SCM for the current state of a service or driver. This makes it a natural follow-up to Windows Command #33 — net start: net start can start or list running services, while sc query exposes more diagnostic state information. Microsoft documents sc.exe query for current Windows client and server releases, including Windows 11. The simplest mental model is: net start asks “what is running or can I start it?”; sc query asks “what state is this service actually in?”

Windows service-management demonstration using the sc command-line utility.

Query One Service and Read Its State

Start with a specific service name: sc.exe query wuauserv asks Windows for the status of the Windows Update service. The output includes SERVICE_NAME, service TYPE, STATE, Windows and service exit codes, CHECKPOINT, and WAIT_HINT. A state such as 4 RUNNING means the service is running; 1 STOPPED means it is stopped. CHECKPOINT and WAIT_HINT become especially useful when a service is transitioning and troubleshooting whether it is making progress. Before changing anything, query first—just as a technician should inspect device drivers, processes, and system state before applying a fix.

Command Prompt demonstration of Windows service creation, configuration, starting, and verification.

Enumerate Running, Stopped, and Driver Services

Running sc.exe query with no service name enumerates active services by default. Use sc.exe query state= all to include stopped services, and sc.exe query type= driver to enumerate drivers. Microsoft’s syntax is unusual but important: options such as state= and type= include the equals sign in the option name and require a space before the value. You can also query a remote Windows Server with UNC-style syntax such as sc.exe \\SERVER01 query, assuming the account, firewall, RPC, and remote-service permissions allow it. That connects service inspection directly to broader IT troubleshooting and networking practice.

Windows Services demonstration showing service discovery and management through the Services console.

Use sc query as the Read-Only Step Before Service Changes

sc query is primarily an inspection command; other sc.exe operations can start, stop, configure, create, or delete services. That distinction matters because service changes can disable networking, updates, security agents, storage functions, or application dependencies. A disciplined workflow is identify → query → interpret → change only if justified → query again. The same service state can also be inspected through the graphical Services console or PowerShell commands such as Get-Service, but sc query remains useful in scripts, recovery sessions, remote administration, and minimal command-line environments. Microsoft’s Service Control Manager is the underlying Windows component maintaining installed-service records and status information.

Practical Windows Services troubleshooting demonstration showing service status, startup, stopping, and restarting.

Practical Command Set

  • sc.exe query — list active services.
  • sc.exe query wuauserv — inspect the Windows Update service.
  • sc.exe query state= all — list active and inactive services.
  • sc.exe query type= driver — enumerate drivers.
  • sc.exe query type= all — query services and drivers.
  • sc.exe \\SERVER01 query — query services on a permitted remote Windows computer.
  • sc.exe queryex wuauserv — request extended service information, including process information when available.

How to Read Common State Values

  • 1 STOPPED — the service is not running.
  • 2 START_PENDING — Windows is waiting for the service to finish starting.
  • 3 STOP_PENDING — the service is in the process of stopping.
  • 4 RUNNING — the service is running.
  • 5 CONTINUE_PENDING — a paused service is resuming.
  • 6 PAUSE_PENDING — the service is moving toward a paused state.
  • 7 PAUSED — the service is paused.

Exercises

  1. Open Command Prompt and run sc.exe query. Identify three running services.
  2. Run sc.exe query state= all. Find one stopped service without changing it.
  3. Query wuauserv directly and record its STATE, exit code, checkpoint, and wait hint.
  4. Run sc.exe query type= driver and identify two driver-service names.
  5. Compare sc.exe query with net start from Windows Command #33. Explain which gives richer diagnostic output.
  6. On a lab machine, compare the same service in sc.exe query, Services, and Get-Service.

Knowledge Check + Answers

  1. What does sc.exe query communicate with? The Windows Service Control Manager.
  2. What does STATE : 4 RUNNING mean? The service is currently running.
  3. How do you include stopped services? Use sc.exe query state= all.
  4. How do you enumerate drivers? Use sc.exe query type= driver.
  5. Why query before changing a service? It establishes the current state and reduces unnecessary or harmful configuration changes.
  6. What are CHECKPOINT and WAIT_HINT useful for? Interpreting progress while a service is in a pending transition.

Primary Technical References

BitcoinVersus.Tech

Advertisement

BitcoinVersus.Tech advertisement.

Editor’s Note:

We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support our research initiatives, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb

BitcoinVersus.tech is not a financial advisor. Content is provided for informational purposes.

Leave a comment