118 commands · 7 cheat sheets · Windows

Monitoring, Policy, and Maintenance master quick reference

Browse 118 commands from 7 focused cheat sheets on page 1 of 1. Each example opens its matching detailed section.

Monitoring, Policy, and Maintenance · 19 commands

PowerShell Windows Event Logs Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
List event logsGet-WinEvent -ListLog *View examples
Find nonempty enabled logsGet-WinEvent -ListLog * | Where-Object { $_.IsEnabled -and $_.RecordCount }View examples
List event providersGet-WinEvent -ListProvider *View examples
Read recent system eventsGet-WinEvent -LogName System -MaxEvents 20View examples
Read one providerGet-WinEvent -ProviderName ` 'Microsoft-Windows-Kernel-General' -MaxEvents 20View examples
Filter by start timeGet-WinEvent -FilterHashtable @{ LogName='System'; ` StartTime=(Get-Date).AddHours(-1) }View examples
Filter error levelsGet-WinEvent -FilterHashtable @{ LogName='System'; ` Level=1,2,3 }View examples
Filter event identifiersGet-WinEvent -FilterHashtable @{ LogName='System'; ` Id=41,6008 }View examples
Filter a provider in a logGet-WinEvent -FilterHashtable @{ LogName='System'; ` ProviderName='Microsoft-Windows-Kernel-General' }View examples
Suppress information eventsGet-WinEvent -FilterHashtable @{ LogName='Application'; ` SuppressHashFilter=@{ Level=4 } }View examples
Select core event fieldsGet-WinEvent -LogName System -MaxEvents 5 | Select-Object TimeCreated, Id, LevelDisplayName, ProviderNameView examples
Read rendered messages$event.MessageView examples
Inspect event XML[xml]$xml = $event.ToXml()View examples
Read an archived logGet-WinEvent -Path 'C:\Evidence\System.evtx' -MaxEvents ` 50View examples
Query a remote computerGet-WinEvent -ComputerName 'Server01' -LogName System ` -MaxEvents 20View examples
Count by event IDGet-WinEvent -LogName System -MaxEvents 500 | Group-Object Id -NoElement | Sort-Object Count -DescendingView examples
Export selected fields$events | Select-Object TimeCreated, Id, ProviderName, Message | Export-Csv '.\events.csv' -NoTypeInformation -Encoding utf8View examples
Return oldest firstGet-WinEvent -LogName System -Oldest -MaxEvents 20View examples
Preserve record identity$event | Select-Object LogName, RecordId, TimeCreated, Id, ProviderNameView examples

Monitoring, Policy, and Maintenance · 16 commands

Windows CIM, WMI, and Hardware Inventory PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Discover CIM classesGet-CimClass -Namespace 'root/cimv2' -ClassName 'Win32_*' | Select-Object -First 25 CimClassNameView examples
Inspect class properties(Get-CimClass -ClassName 'Win32_ComputerSystem').CimClassProperties | Select-Object Name, CimTypeView examples
Inventory Windows versionGet-CimInstance -ClassName 'Win32_OperatingSystem' | Select-Object Caption, Version, BuildNumber, OSArchitecture, LastBootUpTimeView examples
Inventory computer identityGet-CimInstance -ClassName 'Win32_ComputerSystem' | Select-Object Manufacturer, Model, Name, Domain, TotalPhysicalMemoryView examples
Inventory firmware identityGet-CimInstance -ClassName 'Win32_BIOS' | Select-Object Manufacturer, SMBIOSBIOSVersion, ReleaseDate, SerialNumberView examples
Inventory processorsGet-CimInstance -ClassName 'Win32_Processor' | Select-Object DeviceID, Name, NumberOfCores, NumberOfLogicalProcessors, MaxClockSpeedView examples
Inventory memory modulesGet-CimInstance -ClassName 'Win32_PhysicalMemory' | Select-Object DeviceLocator, Capacity, Speed, Manufacturer, PartNumberView examples
Inventory physical disksGet-CimInstance -ClassName 'Win32_DiskDrive' | Select-Object Index, Model, SerialNumber, InterfaceType, Size, StatusView examples
Inventory fixed volumesGet-CimInstance -ClassName 'Win32_LogicalDisk' -Filter 'DriveType = 3' | Select-Object DeviceID, VolumeName, FileSystem, Size, FreeSpaceView examples
Inventory enabled IP adaptersGet-CimInstance -ClassName 'Win32_NetworkAdapterConfiguration' -Filter 'IPEnabled = TRUE' | Select-Object Description, MACAddress, IPAddress, DefaultIPGatewayView examples
Inventory signed driversGet-CimInstance -ClassName 'Win32_PnPSignedDriver' | Select-Object DeviceName, Manufacturer, DriverVersion, DriverDate, InfNameView examples
Run a WQL projectionGet-CimInstance -Query ` 'SELECT DeviceID,Size,FreeSpace FROM Win32_LogicalDisk WHERE DriveType=3'View examples
Create a Kerberos CIM sessionNew-CimSession -ComputerName 'server01.contoso.com' ` -Authentication KerberosView examples
Query through a CIM sessionGet-CimInstance -CimSession $session -ClassName 'Win32_OperatingSystem' | Select-Object CSName, Caption, Version, LastBootUpTimeView examples
Close a CIM sessionRemove-CimSession -CimSession $sessionView examples
Export selected inventory$inventory | Export-Csv -LiteralPath './hardware-inventory.csv' -NoTypeInformation -Encoding utf8View examples

Monitoring, Policy, and Maintenance · 18 commands

Windows Crash Dumps and WinDbg Troubleshooting Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Read recent WER eventsGet-WinEvent -FilterHashtable @{ LogName='Application'; ` ProviderName='Windows Error Reporting'; ` StartTime=(Get-Date).AddHours(-4) } -MaxEvents 100View examples
Read application crash eventsGet-WinEvent -FilterHashtable @{ LogName='Application'; ` ProviderName='Application Error'; ` StartTime=(Get-Date).AddHours(-4) } -MaxEvents 100View examples
Read bug-check eventsGet-WinEvent -FilterHashtable @{ LogName='System'; ` Id=1001; StartTime=(Get-Date).AddDays(-7) } -MaxEvents ` 50View examples
Inspect kernel dump settingsGet-ItemProperty -LiteralPath ` 'HKLM:/SYSTEM/CurrentControlSet/Control/CrashControl'View examples
Inspect page-file usageGet-CimInstance -ClassName 'Win32_PageFileUsage' | Select-Object Name, AllocatedBaseSize, CurrentUsage, PeakUsageView examples
Inspect MEMORY.DMP metadataGet-Item -LiteralPath (Join-Path $env:SystemRoot 'MEMORY.DMP') | Select-Object FullName, Length, CreationTimeUtc, LastWriteTimeUtcView examples
List recent user dumpsGet-ChildItem -LiteralPath (Join-Path $env:LOCALAPPDATA 'CrashDumps') -Filter '*.dmp' | Sort-Object LastWriteTimeUtc -DescendingView examples
Hash a dump artifactGet-FileHash -LiteralPath ` 'C:/CrashEvidence/App_260812_101500.dmp' -Algorithm ` SHA256View examples
Inspect LocalDumps policyGet-ItemProperty -LiteralPath ` 'HKLM:/SOFTWARE/Microsoft/Windows/Windows Error Reporting/LocalDumps' ` -ErrorAction SilentlyContinueView examples
Inspect per-app LocalDumpsGet-ItemProperty -LiteralPath ` 'HKLM:/SOFTWARE/Microsoft/Windows/Windows Error Reporting/LocalDumps/MyApp.exe' ` -ErrorAction SilentlyContinueView examples
Plan exception captureprocdump.exe -ma -e -n 1 -w 'MyApp.exe' ` 'C:/CrashEvidence'View examples
Cancel ProcDump monitoringprocdump.exe -cancel 4321View examples
Validate dump structuredumpchk.exe 'C:/CrashEvidence/App_260812_101500.dmp'View examples
Open a dump in WinDbgwindbg.exe -z 'C:/CrashEvidence/App_260812_101500.dmp'View examples
Set Microsoft symbol cache.symfix C:\Symbols; .reload /fView examples
Run verbose analysis!analyze -vView examples
Select exception context.ecxr; kvView examples
List loaded moduleslm t nView examples

Monitoring, Policy, and Maintenance · 14 commands

Windows Environment Variables and PATH PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
List process environmentGet-ChildItem Env: | Sort-Object NameView examples
Read one value$env:TEMPView examples
Set for current process$env:APP_MODE = 'development'View examples
Remove from current processRemove-Item Env:APP_MODEView examples
Read persistent user value[Environment]::GetEnvironmentVariable('APP_MODE', ` 'User')View examples
Set persistent user value[Environment]::SetEnvironmentVariable('APP_MODE', ` 'production', 'User')View examples
Remove persistent user value[Environment]::SetEnvironmentVariable('APP_MODE', $null, ` 'User')View examples
Read machine value[Environment]::GetEnvironmentVariable('Path', 'Machine')View examples
Split PATH safely$env:Path -split [IO.Path]::PathSeparatorView examples
Resolve all commandsGet-Command python -AllView examples
Expand percent variables[Environment]::ExpandEnvironmentVariables('%TEMP%\report.log')View examples
Start a fresh processStart-Process pwshView examples
Inspect module search paths$env:PSModulePath -split [IO.Path]::PathSeparatorView examples
Inspect runtime identity[Environment]::UserNameView examples

Monitoring, Policy, and Maintenance · 19 commands

Windows Group Policy Management PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Check the GroupPolicy moduleGet-Module -ListAvailable GroupPolicy | Select-Object Name, Version, PathView examples
List domain GPOsGet-GPO -All -Domain 'corp.example.com' -Server 'dc01.corp.example.com' | Sort-Object DisplayNameView examples
Resolve a GPO by GUIDGet-GPO -Guid '11111111-2222-3333-4444-555555555555' ` -Domain 'corp.example.com' -Server ` 'dc01.corp.example.com'View examples
Export a GPO reportGet-GPOReport -Guid $gpo.Id -ReportType Html -Path ` 'C:\Reports\Pilot-GPO.html' -Domain 'corp.example.com'View examples
Inspect OU inheritanceGet-GPInheritance -Target ` 'OU=Pilot,OU=Workstations,DC=corp,DC=example,DC=com' ` -Domain 'corp.example.com'View examples
Audit GPO permissionsGet-GPPermission -Guid $gpo.Id -All -Domain ` 'corp.example.com' -Server 'dc01.corp.example.com'View examples
Preview one GPO backupBackup-GPO -Guid $gpo.Id -Path 'C:\GPOBackups' -Domain ` 'corp.example.com' -Comment 'Before approved change' ` -WhatIfView examples
Preview all-GPO backupBackup-GPO -All -Path 'C:\GPOBackups' -Domain ` 'corp.example.com' -Server 'dc01.corp.example.com' ` -WhatIfView examples
Preview an unlinked GPONew-GPO -Name 'Pilot - Example Policy' -Comment ` 'CHG-12345; owner: Endpoint' -Domain ` 'corp.example.com' -WhatIfView examples
Read a registry policyGet-GPRegistryValue -Name 'Pilot - Example Policy' -Key ` 'HKLM\Software\Policies\Example' -ValueName 'Mode'View examples
Preview a registry policySet-GPRegistryValue -Name 'Pilot - Example Policy' -Key ` 'HKLM\Software\Policies\Example' -ValueName 'Mode' ` -Type DWord -Value 1 -WhatIfView examples
Preview removing a settingRemove-GPRegistryValue -Name 'Pilot - Example Policy' ` -Key 'HKLM\Software\Policies\Example' -ValueName ` 'Mode' -WhatIfView examples
Preview a disabled pilot linkNew-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled ` No -Domain 'corp.example.com' -WhatIfView examples
Preview enabling a linkSet-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled ` Yes -Enforced No -Domain 'corp.example.com' -WhatIfView examples
Preview unlinking a GPORemove-GPLink -Guid $gpo.Id -Target $pilotOu -Domain ` 'corp.example.com' -WhatIfView examples
Preview read delegationSet-GPPermission -Guid $gpo.Id -TargetName ` 'GG-GPO-Auditors' -TargetType Group -PermissionLevel ` GpoRead -WhatIfView examples
Collect computer RSoPGet-GPResultantSetOfPolicy -Computer ` 'pc042.corp.example.com' -ReportType Html -Path ` 'C:\Reports\PC042-RSoP.html'View examples
Generate local gpresultgpresult.exe /h 'C:\Reports\gpresult.html' /fView examples
Schedule a remote refreshInvoke-GPUpdate -Computer 'pc042.corp.example.com' ` -Target Computer -RandomDelayInMinutes 30 -AsJobView examples

Monitoring, Policy, and Maintenance · 16 commands

Windows Performance Counters and Resource Monitoring PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
List counter setsGet-Counter -ListSet '*' | Sort-Object CounterSetName | Select-Object CounterSetName, CounterSetTypeView examples
Inspect processor pathsGet-Counter -ListSet 'Processor Information' | Select-Object -ExpandProperty PathsWithInstancesView examples
Sample total CPUGet-Counter -Counter ` '\Processor Information(_Total)\% Processor Utility' ` -SampleInterval 2 -MaxSamples 15View examples
Sample memory pressureGet-Counter -Counter ` '\Memory\Available MBytes','\Memory\Pages/sec' ` -SampleInterval 2 -MaxSamples 15View examples
Sample physical disk latencyGet-Counter -Counter ` '\PhysicalDisk(*)\Avg. Disk sec/Read','\PhysicalDisk(*)\Avg. Disk sec/Write' ` -MaxSamples 5View examples
Sample disk queuesGet-Counter -Counter ` '\PhysicalDisk(*)\Current Disk Queue Length' ` -SampleInterval 2 -MaxSamples 15View examples
Sample network throughputGet-Counter -Counter ` '\Network Interface(*)\Bytes Total/sec' ` -SampleInterval 2 -MaxSamples 15View examples
Extract cooked values$samples.CounterSamples | Select-Object Timestamp, Path, InstanceName, CookedValue, StatusView examples
Average valid samples$samples.CounterSamples | Where-Object Status -eq 0 | Group-Object Path | ForEach-Object { $_.Group.CookedValue | Measure-Object -Average }View examples
Snapshot costly processesGet-Process | Sort-Object CPU -Descending | Select-Object -First 15 Id, ProcessName, CPU, WorkingSet64, PrivateMemorySize64View examples
Sample process CPU ratesGet-Counter -Counter '\Process(*)\% Processor Time' ` -SampleInterval 2 -MaxSamples 5View examples
Sample a remote hostGet-Counter -ComputerName 'server01.contoso.com' ` -Counter '\Memory\Available MBytes' -MaxSamples 5View examples
Write a BLG export$samples | Export-Counter -Path './perf-sample.blg' -FileFormat blgView examples
Read a BLG captureImport-Counter -Path './perf-sample.blg' | Select-Object -ExpandProperty CounterSamplesView examples
List collector setslogman.exe queryView examples
Correlate System eventsGet-WinEvent -FilterHashtable @{ LogName='System'; ` StartTime=(Get-Date).AddHours(-1) } -MaxEvents 100View examples

Monitoring, Policy, and Maintenance · 16 commands

Windows Update Management and Troubleshooting Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Record OS buildGet-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber, OsArchitectureView examples
List reported hotfixesGet-HotFix | Sort-Object InstalledOn -DescendingView examples
List servicing packagesdism.exe /Online /Get-Packages /Format:TableView examples
Inspect update servicesGet-Service wuauserv, bits, cryptsvc | Select-Object Name, Status, StartTypeView examples
Read Windows Update policyGet-ItemProperty ` 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' ` -ErrorAction SilentlyContinueView examples
Create WUA searcher$searcher = (New-Object -ComObject ` Microsoft.Update.Session).CreateUpdateSearcher()View examples
Scan for missing updates$result = ` $searcher.Search("IsInstalled=0 and IsHidden=0")View examples
Review scan results$result.Updates | Select-Object Title, MsrcSeverity, IsDownloaded, RebootRequiredView examples
Query WUA history$searcher.QueryHistory(0, 30) | Select-Object Date, Title, Operation, ResultCode, HResultView examples
Read operational eventsGet-WinEvent -LogName ` 'Microsoft-Windows-WindowsUpdateClient/Operational' ` -MaxEvents 50View examples
Build readable update logGet-WindowsUpdateLog -LogPath (Join-Path $PWD ` 'WindowsUpdate.log')View examples
Scan component-store healthdism.exe /Online /Cleanup-Image /ScanHealthView examples
Hash a staged packageGet-FileHash -LiteralPath 'C:\Staging\KB0000000.msu' ` -Algorithm SHA256View examples
Install a staged MSUdism.exe /Online /Add-Package ` /PackagePath:"C:\Staging\KB0000000.msu" ` /PreventPending /NoRestartView examples
Schedule controlled restartshutdown.exe /r /t 900 /d p:2:17 /c ` "Approved Windows Update maintenance"View examples
Cancel scheduled restartshutdown.exe /aView examples
CMDMEMO TERMINALREAD ONLY