The "Process Hacker" tool that this article refers to seems quite useful. It can be found here: https://processhacker.sourceforge.io (free GPL software)
Yes, +1 for Process Hacker, it's basically an open source alternative to Sysinternals Process Explorer[0]. The service alerts noted in this article in particular led me to getting spooked and discovering that Windows Defender likes creating fun malware-like driver service names like MpKslasdfas3.sys. I'm at the point where it's always open to increase system awareness, and for quick filehandle views when I forget what application is stopping me from ejecting a USB.