>>718079604
If you're only talking about the basic Task Manager, then you are correct.
Otherwise, you're not correct at all.
Learn Sysinternals. I haven't relied on Windows Defender ever since I started using that. This shit lists literally anything that isn't hidden by the lowest possible ring.
https://learn.microsoft.com/en-us/sysinternals/
Even if you're talking about a rootkit that manages to hijack processer before the OS can even see them, the toolkit above also has a rootkit detector that supposedly seeks for disk usage discrepancies between the hardware and the OS. Granted I never tried that tool, but the logic is sound.