The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| List registry drives | Get-PSDrive -PSProvider Registry | View examples |
| Use a full hive path | Get-Item -LiteralPath `
'Registry::HKEY_CURRENT_USER\Software' | View examples |
| List immediate subkeys | Get-ChildItem -LiteralPath 'HKCU:\Software' | View examples |
| Find descendant keys | Get-ChildItem -LiteralPath 'HKCU:\Software\Acme' `
-Recurse | View examples |
| Test a key path | Test-Path -LiteralPath 'HKCU:\Software\Acme' | View examples |
| Inspect a key object | Get-Item -LiteralPath 'HKCU:\Software\Acme' | View examples |
| Read key values | Get-ItemProperty -LiteralPath 'HKCU:\Software\Acme' | View examples |
| Read one raw value | Get-ItemPropertyValue -LiteralPath 'HKCU:\Software\Acme' `
-Name 'Theme' | View examples |
| Preview key creation | New-Item -Path 'HKCU:\Software\Acme' -WhatIf | View examples |
| Preview a string value | New-ItemProperty -LiteralPath 'HKCU:\Software\Acme' `
-Name 'Theme' -Value 'Dark' -PropertyType String `
-WhatIf | View examples |
| Preview a DWORD value | New-ItemProperty -LiteralPath 'HKCU:\Software\Acme' `
-Name 'PageSize' -Value 25 -PropertyType DWord -WhatIf | View examples |
| Preview changing a value | Set-ItemProperty -LiteralPath 'HKCU:\Software\Acme' `
-Name 'Theme' -Value 'Light' -WhatIf | View examples |
| Preview renaming a value | Rename-ItemProperty -LiteralPath 'HKCU:\Software\Acme' `
-Name 'Theme' -NewName 'ColorTheme' -WhatIf | View examples |
| Preview clearing data | Clear-ItemProperty -LiteralPath 'HKCU:\Software\Acme' `
-Name 'Theme' -WhatIf | View examples |
| Preview removing a value | Remove-ItemProperty -LiteralPath 'HKCU:\Software\Acme' `
-Name 'Theme' -WhatIf | View examples |
| Preview removing a key | Remove-Item -LiteralPath 'HKCU:\Software\Acme' -Recurse `
-WhatIf | View examples |
| Export a key tree | reg.exe export 'HKCU\Software\Acme' '.\Acme-backup.reg' `
/y | View examples |
| Capture selected state | Get-ItemProperty -LiteralPath 'HKCU:\Software\Acme' |
Select-Object Theme, PageSize | View examples |
PowerShell exposes registry keys as provider items and registry values as item properties. Read exact paths first, work under HKCU when machine-wide state is unnecessary, preserve value kinds, preview mutations with WhatIf, and record recoverable state before consequential changes.
Step by step
Detailed examples
Treat keys as items and values as properties
HKLM: maps HKEY_LOCAL_MACHINE and HKCU: maps HKEY_CURRENT_USER. Registry keys form the provider hierarchy; named registry values are properties on those items, not child items. Provider-qualified Registry:: paths expose full hive names and work even when a convenient drive is not mapped. These commands apply only on Windows.
Get-PSDrive -PSProvider Registry
Get-Item -LiteralPath 'Registry::HKEY_CURRENT_USER\Software' |
Select-Object Name, SubKeyCount, ValueCount # Registry drives normally include HKCU and HKLM.
# The key object reports its full name and counts.Discover exact keys before changing them
Get-ChildItem returns subkeys, while -Recurse can be expensive and may encounter inaccessible keys. LiteralPath prevents wildcard interpretation in names containing bracket characters. Test-Path is useful for branching but state can change afterward, so operations must still handle provider errors.
$root = 'HKCU:\Software'
Get-ChildItem -LiteralPath $root |
Where-Object Name -Like '*Acme*' |
Select-Object Name, SubKeyCount, ValueCount
Test-Path -LiteralPath 'HKCU:\Software\Acme' # Output depends on the current user's registry hive.Read structured values without parsing display text
Get-Item returns the key; Get-ItemProperty returns a PSCustomObject containing its values plus provider metadata. Get-ItemPropertyValue returns one value's raw .NET representation. A value can exist with empty data, so distinguish a missing property from a present empty value through error handling.
$path = 'HKCU:\Software\Acme'
if (Test-Path -LiteralPath $path) {
Get-ItemProperty -LiteralPath $path | Select-Object Theme, PageSize
Get-ItemPropertyValue -LiteralPath $path -Name 'Theme'
} # Existing value data is returned as PowerShell objects.Create keys and typed values explicitly
New-Item creates a key; New-ItemProperty creates a value on it. PropertyType maps to kinds such as String, ExpandString, Binary, DWord, MultiString, and QWord. Choose the kind expected by the consumer and avoid Force unless replacement is intended. Start with WhatIf, then remove it only after reviewing the exact HKCU or HKLM target.
$path = 'HKCU:\Software\Acme'
New-Item -Path $path -WhatIf
New-ItemProperty -LiteralPath $path -Name 'Theme' -Value 'Dark' -PropertyType String -WhatIf
New-ItemProperty -LiteralPath $path -Name 'PageSize' -Value 25 -PropertyType DWord -WhatIf What if: Performing the operation ...
# No registry state changes while WhatIf is present.Preserve semantics when changing data or names
Set-ItemProperty changes data and normally preserves the value kind. Rename-ItemProperty changes the value name, which can immediately break consumers expecting the old name. Capture current data and type first, preview the operation, and coordinate application restarts or policy refresh only when their documentation requires it.
$path = 'HKCU:\Software\Acme'
$current = Get-ItemProperty -LiteralPath $path -Name 'Theme' -ErrorAction Stop
$current | Select-Object Theme
Set-ItemProperty -LiteralPath $path -Name 'Theme' -Value 'Light' -WhatIf
Rename-ItemProperty -LiteralPath $path -Name 'Theme' -NewName 'ColorTheme' -WhatIf # Current data is shown, followed by WhatIf previews.Distinguish clearing data from deleting values or keys
Clear-ItemProperty retains the value but resets its data; Remove-ItemProperty deletes it. Remove-Item targets a key and -Recurse includes descendants, making exact path review essential. Prefer WhatIf and a recoverable export, and never apply a recursive command to a path assembled from unchecked input.
$path = 'HKCU:\Software\Acme'
Clear-ItemProperty -LiteralPath $path -Name 'Theme' -WhatIf
Remove-ItemProperty -LiteralPath $path -Name 'Theme' -WhatIf
Remove-Item -LiteralPath $path -Recurse -WhatIf # Each command reports its proposed target without changing it.Export recoverable state and verify afterward
reg.exe export creates a textual .reg backup of a key tree, but it may contain sensitive configuration and is not a system backup. Check the native exit code immediately and protect the file. After an authorized change, read exact values again and compare their data and kinds with the intended result.
$backup = Join-Path $PWD 'Acme-backup.reg'
reg.exe export 'HKCU\Software\Acme' $backup /y
$exitCode = $LASTEXITCODE
if ($exitCode -ne 0) { throw "Registry export failed with exit code $exitCode" }
Get-Item -LiteralPath $backup | Select-Object FullName, Length # A successful export creates the backup and returns native exit code 0.Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



