971 commands · 58 cheat sheets · 7 subcategories
Windows master quick reference — Page 5
Browse 168 commands from 10 focused cheat sheets on page 5 of 5. Each example opens its matching detailed section.
DiskPart · 16 commands
DiskPart Legacy Dynamic Disks and Volumes Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| List disks | list disk | View examples |
| Select a dynamic disk | select disk 2 | View examples |
| Inspect disk membership | detail disk | View examples |
| List dynamic volumes | list volume | View examples |
| Convert a basic disk to dynamic | convert dynamic | View examples |
| Create a simple volume | create volume simple size=20480 disk=2 | View examples |
| Span onto another disk | extend disk=3 size=10240 | View examples |
| Create a striped volume | create volume stripe size=10240 disk=2,3 | View examples |
| Create a mirrored volume | create volume mirror size=10240 disk=2,3 | View examples |
| Add a mirror plex | add disk=3 | View examples |
| Break a mirror | break disk=3 | View examples |
| Create a RAID-5 volume | create volume raid size=10240 disk=2,3,4 | View examples |
| Repair a RAID-5 volume | repair disk=5 | View examples |
| Recover a disk group | recover | View examples |
| Import foreign disks | import | View examples |
| Convert an empty disk to basic | convert basic | View examples |
DiskPart · 18 commands
DiskPart UEFI/GPT Windows Partitioning Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Select the destination disk | select disk 3 | View examples |
| Inspect destination identity | detail disk | View examples |
| Erase the partition layout | clean | View examples |
| Initialize GPT | convert gpt | View examples |
| Create a 300 MB ESP | create partition efi size=300 | View examples |
| Format the ESP | format quick fs=fat32 label="System" | View examples |
| Mount the ESP in WinPE | assign letter=S | View examples |
| Create the MSR | create partition msr size=16 | View examples |
| Create the Windows partition | create partition primary | View examples |
| Reserve 1500 MB for recovery | shrink desired=1500 minimum=1500 | View examples |
| Format Windows as NTFS | format quick fs=ntfs label="Windows" | View examples |
| Mount Windows in WinPE | assign letter=W | View examples |
| Create the recovery partition | create partition primary | View examples |
| Format recovery as NTFS | format quick fs=ntfs label="Recovery" | View examples |
| Set the Windows RE type | set id=de94bba4-06d1-4d40-a16a-bfd50179d6ac | View examples |
| Protect the recovery partition | gpt attributes=0x8000000000000001 | View examples |
| List the final partitions | list partition | View examples |
| List deployment volumes | list volume | View examples |
DiskPart · 16 commands
DiskPart VHD and VHDX Create, Attach, and Resize Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Create an expandable VHDX | create vdisk file="C:\VHDs\Data.vhdx" maximum=65536 `
type=expandable | View examples |
| Create a fixed VHDX | create vdisk file="C:\VHDs\Fixed.vhdx" maximum=65536 `
type=fixed | View examples |
| Create a differencing child | create vdisk file="C:\VHDs\Lab-child.vhdx" `
parent="C:\VHDs\Lab-base.vhdx" | View examples |
| Create a VHD copy | create vdisk file="C:\VHDs\Data-copy.vhdx" `
source="C:\VHDs\Data.vhdx" | View examples |
| Select a virtual disk file | select vdisk file="C:\VHDs\Data.vhdx" | View examples |
| Inspect the selected VHD | detail vdisk | View examples |
| List virtual disks | list vdisk | View examples |
| Attach read-only | attach vdisk readonly | View examples |
| Attach read-write | attach vdisk | View examples |
| Detach the virtual disk | detach vdisk | View examples |
| Compact an expandable VHD | compact vdisk | View examples |
| Expand virtual capacity | expand vdisk maximum=131072 | View examples |
| Merge one parent level | merge vdisk depth=1 | View examples |
| Find the attached disk | list disk | View examples |
| Verify attached disk identity | detail disk | View examples |
| Exit DiskPart | exit | View examples |
Monitoring, Policy, and Maintenance · 19 commands
PowerShell Windows Event Logs Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| List event logs | Get-WinEvent -ListLog * | View examples |
| Find nonempty enabled logs | Get-WinEvent -ListLog * |
Where-Object { $_.IsEnabled -and $_.RecordCount } | View examples |
| List event providers | Get-WinEvent -ListProvider * | View examples |
| Read recent system events | Get-WinEvent -LogName System -MaxEvents 20 | View examples |
| Read one provider | Get-WinEvent -ProviderName `
'Microsoft-Windows-Kernel-General' -MaxEvents 20 | View examples |
| Filter by start time | Get-WinEvent -FilterHashtable @{ LogName='System'; `
StartTime=(Get-Date).AddHours(-1) } | View examples |
| Filter error levels | Get-WinEvent -FilterHashtable @{ LogName='System'; `
Level=1,2,3 } | View examples |
| Filter event identifiers | Get-WinEvent -FilterHashtable @{ LogName='System'; `
Id=41,6008 } | View examples |
| Filter a provider in a log | Get-WinEvent -FilterHashtable @{ LogName='System'; `
ProviderName='Microsoft-Windows-Kernel-General' } | View examples |
| Suppress information events | Get-WinEvent -FilterHashtable @{ LogName='Application'; `
SuppressHashFilter=@{ Level=4 } } | View examples |
| Select core event fields | Get-WinEvent -LogName System -MaxEvents 5 |
Select-Object TimeCreated, Id, LevelDisplayName, ProviderName | View examples |
| Read rendered messages | $event.Message | View examples |
| Inspect event XML | [xml]$xml = $event.ToXml() | View examples |
| Read an archived log | Get-WinEvent -Path 'C:\Evidence\System.evtx' -MaxEvents `
50 | View examples |
| Query a remote computer | Get-WinEvent -ComputerName 'Server01' -LogName System `
-MaxEvents 20 | View examples |
| Count by event ID | Get-WinEvent -LogName System -MaxEvents 500 |
Group-Object Id -NoElement |
Sort-Object Count -Descending | View examples |
| Export selected fields | $events |
Select-Object TimeCreated, Id, ProviderName, Message |
Export-Csv '.\events.csv' -NoTypeInformation -Encoding utf8 | View examples |
| Return oldest first | Get-WinEvent -LogName System -Oldest -MaxEvents 20 | View examples |
| Preserve record identity | $event |
Select-Object LogName, RecordId, TimeCreated, Id, ProviderName | View examples |
Monitoring, Policy, and Maintenance · 16 commands
Windows CIM, WMI, and Hardware Inventory PowerShell Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Discover CIM classes | Get-CimClass -Namespace 'root/cimv2' -ClassName 'Win32_*' |
Select-Object -First 25 CimClassName | View examples |
| Inspect class properties | (Get-CimClass -ClassName 'Win32_ComputerSystem').CimClassProperties |
Select-Object Name, CimType | View examples |
| Inventory Windows version | Get-CimInstance -ClassName 'Win32_OperatingSystem' |
Select-Object Caption, Version, BuildNumber, OSArchitecture, LastBootUpTime | View examples |
| Inventory computer identity | Get-CimInstance -ClassName 'Win32_ComputerSystem' |
Select-Object Manufacturer, Model, Name, Domain, TotalPhysicalMemory | View examples |
| Inventory firmware identity | Get-CimInstance -ClassName 'Win32_BIOS' |
Select-Object Manufacturer, SMBIOSBIOSVersion, ReleaseDate, SerialNumber | View examples |
| Inventory processors | Get-CimInstance -ClassName 'Win32_Processor' |
Select-Object DeviceID, Name, NumberOfCores, NumberOfLogicalProcessors, MaxClockSpeed | View examples |
| Inventory memory modules | Get-CimInstance -ClassName 'Win32_PhysicalMemory' |
Select-Object DeviceLocator, Capacity, Speed, Manufacturer, PartNumber | View examples |
| Inventory physical disks | Get-CimInstance -ClassName 'Win32_DiskDrive' |
Select-Object Index, Model, SerialNumber, InterfaceType, Size, Status | View examples |
| Inventory fixed volumes | Get-CimInstance -ClassName 'Win32_LogicalDisk' -Filter 'DriveType = 3' |
Select-Object DeviceID, VolumeName, FileSystem, Size, FreeSpace | View examples |
| Inventory enabled IP adapters | Get-CimInstance -ClassName 'Win32_NetworkAdapterConfiguration' -Filter 'IPEnabled = TRUE' |
Select-Object Description, MACAddress, IPAddress, DefaultIPGateway | View examples |
| Inventory signed drivers | Get-CimInstance -ClassName 'Win32_PnPSignedDriver' |
Select-Object DeviceName, Manufacturer, DriverVersion, DriverDate, InfName | View examples |
| Run a WQL projection | Get-CimInstance -Query `
'SELECT DeviceID,Size,FreeSpace FROM Win32_LogicalDisk WHERE DriveType=3' | View examples |
| Create a Kerberos CIM session | New-CimSession -ComputerName 'server01.contoso.com' `
-Authentication Kerberos | View examples |
| Query through a CIM session | Get-CimInstance -CimSession $session -ClassName 'Win32_OperatingSystem' |
Select-Object CSName, Caption, Version, LastBootUpTime | View examples |
| Close a CIM session | Remove-CimSession -CimSession $session | View examples |
| Export selected inventory | $inventory |
Export-Csv -LiteralPath './hardware-inventory.csv' -NoTypeInformation -Encoding utf8 | View examples |
Monitoring, Policy, and Maintenance · 18 commands
Windows Crash Dumps and WinDbg Troubleshooting Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Read recent WER events | Get-WinEvent -FilterHashtable @{ LogName='Application'; `
ProviderName='Windows Error Reporting'; `
StartTime=(Get-Date).AddHours(-4) } -MaxEvents 100 | View examples |
| Read application crash events | Get-WinEvent -FilterHashtable @{ LogName='Application'; `
ProviderName='Application Error'; `
StartTime=(Get-Date).AddHours(-4) } -MaxEvents 100 | View examples |
| Read bug-check events | Get-WinEvent -FilterHashtable @{ LogName='System'; `
Id=1001; StartTime=(Get-Date).AddDays(-7) } -MaxEvents `
50 | View examples |
| Inspect kernel dump settings | Get-ItemProperty -LiteralPath `
'HKLM:/SYSTEM/CurrentControlSet/Control/CrashControl' | View examples |
| Inspect page-file usage | Get-CimInstance -ClassName 'Win32_PageFileUsage' |
Select-Object Name, AllocatedBaseSize, CurrentUsage, PeakUsage | View examples |
| Inspect MEMORY.DMP metadata | Get-Item -LiteralPath (Join-Path $env:SystemRoot 'MEMORY.DMP') |
Select-Object FullName, Length, CreationTimeUtc, LastWriteTimeUtc | View examples |
| List recent user dumps | Get-ChildItem -LiteralPath (Join-Path $env:LOCALAPPDATA 'CrashDumps') -Filter '*.dmp' |
Sort-Object LastWriteTimeUtc -Descending | View examples |
| Hash a dump artifact | Get-FileHash -LiteralPath `
'C:/CrashEvidence/App_260812_101500.dmp' -Algorithm `
SHA256 | View examples |
| Inspect LocalDumps policy | Get-ItemProperty -LiteralPath `
'HKLM:/SOFTWARE/Microsoft/Windows/Windows Error Reporting/LocalDumps' `
-ErrorAction SilentlyContinue | View examples |
| Inspect per-app LocalDumps | Get-ItemProperty -LiteralPath `
'HKLM:/SOFTWARE/Microsoft/Windows/Windows Error Reporting/LocalDumps/MyApp.exe' `
-ErrorAction SilentlyContinue | View examples |
| Plan exception capture | procdump.exe -ma -e -n 1 -w 'MyApp.exe' `
'C:/CrashEvidence' | View examples |
| Cancel ProcDump monitoring | procdump.exe -cancel 4321 | View examples |
| Validate dump structure | dumpchk.exe 'C:/CrashEvidence/App_260812_101500.dmp' | View examples |
| Open a dump in WinDbg | windbg.exe -z 'C:/CrashEvidence/App_260812_101500.dmp' | View examples |
| Set Microsoft symbol cache | .symfix C:\Symbols; .reload /f | View examples |
| Run verbose analysis | !analyze -v | View examples |
| Select exception context | .ecxr; kv | View examples |
| List loaded modules | lm t n | View examples |
Monitoring, Policy, and Maintenance · 14 commands
Windows Environment Variables and PATH PowerShell Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| List process environment | Get-ChildItem Env: | Sort-Object Name | View examples |
| Read one value | $env:TEMP | View examples |
| Set for current process | $env:APP_MODE = 'development' | View examples |
| Remove from current process | Remove-Item Env:APP_MODE | View examples |
| Read persistent user value | [Environment]::GetEnvironmentVariable('APP_MODE', `
'User') | View examples |
| Set persistent user value | [Environment]::SetEnvironmentVariable('APP_MODE', `
'production', 'User') | View examples |
| Remove persistent user value | [Environment]::SetEnvironmentVariable('APP_MODE', $null, `
'User') | View examples |
| Read machine value | [Environment]::GetEnvironmentVariable('Path', 'Machine') | View examples |
| Split PATH safely | $env:Path -split [IO.Path]::PathSeparator | View examples |
| Resolve all commands | Get-Command python -All | View examples |
| Expand percent variables | [Environment]::ExpandEnvironmentVariables('%TEMP%\report.log') | View examples |
| Start a fresh process | Start-Process pwsh | View examples |
| Inspect module search paths | $env:PSModulePath -split [IO.Path]::PathSeparator | View examples |
| Inspect runtime identity | [Environment]::UserName | View examples |
Monitoring, Policy, and Maintenance · 19 commands
Windows Group Policy Management PowerShell Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Check the GroupPolicy module | Get-Module -ListAvailable GroupPolicy |
Select-Object Name, Version, Path | View examples |
| List domain GPOs | Get-GPO -All -Domain 'corp.example.com' -Server 'dc01.corp.example.com' |
Sort-Object DisplayName | View examples |
| Resolve a GPO by GUID | Get-GPO -Guid '11111111-2222-3333-4444-555555555555' `
-Domain 'corp.example.com' -Server `
'dc01.corp.example.com' | View examples |
| Export a GPO report | Get-GPOReport -Guid $gpo.Id -ReportType Html -Path `
'C:\Reports\Pilot-GPO.html' -Domain 'corp.example.com' | View examples |
| Inspect OU inheritance | Get-GPInheritance -Target `
'OU=Pilot,OU=Workstations,DC=corp,DC=example,DC=com' `
-Domain 'corp.example.com' | View examples |
| Audit GPO permissions | Get-GPPermission -Guid $gpo.Id -All -Domain `
'corp.example.com' -Server 'dc01.corp.example.com' | View examples |
| Preview one GPO backup | Backup-GPO -Guid $gpo.Id -Path 'C:\GPOBackups' -Domain `
'corp.example.com' -Comment 'Before approved change' `
-WhatIf | View examples |
| Preview all-GPO backup | Backup-GPO -All -Path 'C:\GPOBackups' -Domain `
'corp.example.com' -Server 'dc01.corp.example.com' `
-WhatIf | View examples |
| Preview an unlinked GPO | New-GPO -Name 'Pilot - Example Policy' -Comment `
'CHG-12345; owner: Endpoint' -Domain `
'corp.example.com' -WhatIf | View examples |
| Read a registry policy | Get-GPRegistryValue -Name 'Pilot - Example Policy' -Key `
'HKLM\Software\Policies\Example' -ValueName 'Mode' | View examples |
| Preview a registry policy | Set-GPRegistryValue -Name 'Pilot - Example Policy' -Key `
'HKLM\Software\Policies\Example' -ValueName 'Mode' `
-Type DWord -Value 1 -WhatIf | View examples |
| Preview removing a setting | Remove-GPRegistryValue -Name 'Pilot - Example Policy' `
-Key 'HKLM\Software\Policies\Example' -ValueName `
'Mode' -WhatIf | View examples |
| Preview a disabled pilot link | New-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled `
No -Domain 'corp.example.com' -WhatIf | View examples |
| Preview enabling a link | Set-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled `
Yes -Enforced No -Domain 'corp.example.com' -WhatIf | View examples |
| Preview unlinking a GPO | Remove-GPLink -Guid $gpo.Id -Target $pilotOu -Domain `
'corp.example.com' -WhatIf | View examples |
| Preview read delegation | Set-GPPermission -Guid $gpo.Id -TargetName `
'GG-GPO-Auditors' -TargetType Group -PermissionLevel `
GpoRead -WhatIf | View examples |
| Collect computer RSoP | Get-GPResultantSetOfPolicy -Computer `
'pc042.corp.example.com' -ReportType Html -Path `
'C:\Reports\PC042-RSoP.html' | View examples |
| Generate local gpresult | gpresult.exe /h 'C:\Reports\gpresult.html' /f | View examples |
| Schedule a remote refresh | Invoke-GPUpdate -Computer 'pc042.corp.example.com' `
-Target Computer -RandomDelayInMinutes 30 -AsJob | View examples |
Monitoring, Policy, and Maintenance · 16 commands
Windows Performance Counters and Resource Monitoring PowerShell Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| List counter sets | Get-Counter -ListSet '*' |
Sort-Object CounterSetName |
Select-Object CounterSetName, CounterSetType | View examples |
| Inspect processor paths | Get-Counter -ListSet 'Processor Information' |
Select-Object -ExpandProperty PathsWithInstances | View examples |
| Sample total CPU | Get-Counter -Counter `
'\Processor Information(_Total)\% Processor Utility' `
-SampleInterval 2 -MaxSamples 15 | View examples |
| Sample memory pressure | Get-Counter -Counter `
'\Memory\Available MBytes','\Memory\Pages/sec' `
-SampleInterval 2 -MaxSamples 15 | View examples |
| Sample physical disk latency | Get-Counter -Counter `
'\PhysicalDisk(*)\Avg. Disk sec/Read','\PhysicalDisk(*)\Avg. Disk sec/Write' `
-MaxSamples 5 | View examples |
| Sample disk queues | Get-Counter -Counter `
'\PhysicalDisk(*)\Current Disk Queue Length' `
-SampleInterval 2 -MaxSamples 15 | View examples |
| Sample network throughput | Get-Counter -Counter `
'\Network Interface(*)\Bytes Total/sec' `
-SampleInterval 2 -MaxSamples 15 | View examples |
| Extract cooked values | $samples.CounterSamples |
Select-Object Timestamp, Path, InstanceName, CookedValue, Status | View examples |
| Average valid samples | $samples.CounterSamples |
Where-Object Status -eq 0 |
Group-Object Path |
ForEach-Object { $_.Group.CookedValue |
Measure-Object -Average } | View examples |
| Snapshot costly processes | Get-Process |
Sort-Object CPU -Descending |
Select-Object -First 15 Id, ProcessName, CPU, WorkingSet64, PrivateMemorySize64 | View examples |
| Sample process CPU rates | Get-Counter -Counter '\Process(*)\% Processor Time' `
-SampleInterval 2 -MaxSamples 5 | View examples |
| Sample a remote host | Get-Counter -ComputerName 'server01.contoso.com' `
-Counter '\Memory\Available MBytes' -MaxSamples 5 | View examples |
| Write a BLG export | $samples |
Export-Counter -Path './perf-sample.blg' -FileFormat blg | View examples |
| Read a BLG capture | Import-Counter -Path './perf-sample.blg' |
Select-Object -ExpandProperty CounterSamples | View examples |
| List collector sets | logman.exe query | View examples |
| Correlate System events | Get-WinEvent -FilterHashtable @{ LogName='System'; `
StartTime=(Get-Date).AddHours(-1) } -MaxEvents 100 | View examples |
Monitoring, Policy, and Maintenance · 16 commands
Windows Update Management and Troubleshooting Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Record OS build | Get-ComputerInfo |
Select-Object WindowsProductName, WindowsVersion, OsBuildNumber, OsArchitecture | View examples |
| List reported hotfixes | Get-HotFix | Sort-Object InstalledOn -Descending | View examples |
| List servicing packages | dism.exe /Online /Get-Packages /Format:Table | View examples |
| Inspect update services | Get-Service wuauserv, bits, cryptsvc |
Select-Object Name, Status, StartType | View examples |
| Read Windows Update policy | Get-ItemProperty `
'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' `
-ErrorAction SilentlyContinue | View examples |
| Create WUA searcher | $searcher = (New-Object -ComObject `
Microsoft.Update.Session).CreateUpdateSearcher() | View examples |
| Scan for missing updates | $result = `
$searcher.Search("IsInstalled=0 and IsHidden=0") | View examples |
| Review scan results | $result.Updates |
Select-Object Title, MsrcSeverity, IsDownloaded, RebootRequired | View examples |
| Query WUA history | $searcher.QueryHistory(0, 30) |
Select-Object Date, Title, Operation, ResultCode, HResult | View examples |
| Read operational events | Get-WinEvent -LogName `
'Microsoft-Windows-WindowsUpdateClient/Operational' `
-MaxEvents 50 | View examples |
| Build readable update log | Get-WindowsUpdateLog -LogPath (Join-Path $PWD `
'WindowsUpdate.log') | View examples |
| Scan component-store health | dism.exe /Online /Cleanup-Image /ScanHealth | View examples |
| Hash a staged package | Get-FileHash -LiteralPath 'C:\Staging\KB0000000.msu' `
-Algorithm SHA256 | View examples |
| Install a staged MSU | dism.exe /Online /Add-Package `
/PackagePath:"C:\Staging\KB0000000.msu" `
/PreventPending /NoRestart | View examples |
| Schedule controlled restart | shutdown.exe /r /t 900 /d p:2:17 /c `
"Approved Windows Update maintenance" | View examples |
| Cancel scheduled restart | shutdown.exe /a | View examples |



