971 commands · 58 cheat sheets · 7 subcategories

Windows master quick reference — Page 5

Browse 168 commands from 10 focused cheat sheets on page 5 of 5. Each example opens its matching detailed section.

DiskPart · 16 commands

DiskPart Legacy Dynamic Disks and Volumes Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
List diskslist diskView examples
Select a dynamic diskselect disk 2View examples
Inspect disk membershipdetail diskView examples
List dynamic volumeslist volumeView examples
Convert a basic disk to dynamicconvert dynamicView examples
Create a simple volumecreate volume simple size=20480 disk=2View examples
Span onto another diskextend disk=3 size=10240View examples
Create a striped volumecreate volume stripe size=10240 disk=2,3View examples
Create a mirrored volumecreate volume mirror size=10240 disk=2,3View examples
Add a mirror plexadd disk=3View examples
Break a mirrorbreak disk=3View examples
Create a RAID-5 volumecreate volume raid size=10240 disk=2,3,4View examples
Repair a RAID-5 volumerepair disk=5View examples
Recover a disk grouprecoverView examples
Import foreign disksimportView examples
Convert an empty disk to basicconvert basicView examples

DiskPart · 18 commands

DiskPart UEFI/GPT Windows Partitioning Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Select the destination diskselect disk 3View examples
Inspect destination identitydetail diskView examples
Erase the partition layoutcleanView examples
Initialize GPTconvert gptView examples
Create a 300 MB ESPcreate partition efi size=300View examples
Format the ESPformat quick fs=fat32 label="System"View examples
Mount the ESP in WinPEassign letter=SView examples
Create the MSRcreate partition msr size=16View examples
Create the Windows partitioncreate partition primaryView examples
Reserve 1500 MB for recoveryshrink desired=1500 minimum=1500View examples
Format Windows as NTFSformat quick fs=ntfs label="Windows"View examples
Mount Windows in WinPEassign letter=WView examples
Create the recovery partitioncreate partition primaryView examples
Format recovery as NTFSformat quick fs=ntfs label="Recovery"View examples
Set the Windows RE typeset id=de94bba4-06d1-4d40-a16a-bfd50179d6acView examples
Protect the recovery partitiongpt attributes=0x8000000000000001View examples
List the final partitionslist partitionView examples
List deployment volumeslist volumeView examples

DiskPart · 16 commands

DiskPart VHD and VHDX Create, Attach, and Resize Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Create an expandable VHDXcreate vdisk file="C:\VHDs\Data.vhdx" maximum=65536 ` type=expandableView examples
Create a fixed VHDXcreate vdisk file="C:\VHDs\Fixed.vhdx" maximum=65536 ` type=fixedView examples
Create a differencing childcreate vdisk file="C:\VHDs\Lab-child.vhdx" ` parent="C:\VHDs\Lab-base.vhdx"View examples
Create a VHD copycreate vdisk file="C:\VHDs\Data-copy.vhdx" ` source="C:\VHDs\Data.vhdx"View examples
Select a virtual disk fileselect vdisk file="C:\VHDs\Data.vhdx"View examples
Inspect the selected VHDdetail vdiskView examples
List virtual diskslist vdiskView examples
Attach read-onlyattach vdisk readonlyView examples
Attach read-writeattach vdiskView examples
Detach the virtual diskdetach vdiskView examples
Compact an expandable VHDcompact vdiskView examples
Expand virtual capacityexpand vdisk maximum=131072View examples
Merge one parent levelmerge vdisk depth=1View examples
Find the attached disklist diskView examples
Verify attached disk identitydetail diskView examples
Exit DiskPartexitView examples

Monitoring, Policy, and Maintenance · 19 commands

PowerShell Windows Event Logs Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
List event logsGet-WinEvent -ListLog *View examples
Find nonempty enabled logsGet-WinEvent -ListLog * | Where-Object { $_.IsEnabled -and $_.RecordCount }View examples
List event providersGet-WinEvent -ListProvider *View examples
Read recent system eventsGet-WinEvent -LogName System -MaxEvents 20View examples
Read one providerGet-WinEvent -ProviderName ` 'Microsoft-Windows-Kernel-General' -MaxEvents 20View examples
Filter by start timeGet-WinEvent -FilterHashtable @{ LogName='System'; ` StartTime=(Get-Date).AddHours(-1) }View examples
Filter error levelsGet-WinEvent -FilterHashtable @{ LogName='System'; ` Level=1,2,3 }View examples
Filter event identifiersGet-WinEvent -FilterHashtable @{ LogName='System'; ` Id=41,6008 }View examples
Filter a provider in a logGet-WinEvent -FilterHashtable @{ LogName='System'; ` ProviderName='Microsoft-Windows-Kernel-General' }View examples
Suppress information eventsGet-WinEvent -FilterHashtable @{ LogName='Application'; ` SuppressHashFilter=@{ Level=4 } }View examples
Select core event fieldsGet-WinEvent -LogName System -MaxEvents 5 | Select-Object TimeCreated, Id, LevelDisplayName, ProviderNameView examples
Read rendered messages$event.MessageView examples
Inspect event XML[xml]$xml = $event.ToXml()View examples
Read an archived logGet-WinEvent -Path 'C:\Evidence\System.evtx' -MaxEvents ` 50View examples
Query a remote computerGet-WinEvent -ComputerName 'Server01' -LogName System ` -MaxEvents 20View examples
Count by event IDGet-WinEvent -LogName System -MaxEvents 500 | Group-Object Id -NoElement | Sort-Object Count -DescendingView examples
Export selected fields$events | Select-Object TimeCreated, Id, ProviderName, Message | Export-Csv '.\events.csv' -NoTypeInformation -Encoding utf8View examples
Return oldest firstGet-WinEvent -LogName System -Oldest -MaxEvents 20View examples
Preserve record identity$event | Select-Object LogName, RecordId, TimeCreated, Id, ProviderNameView examples

Monitoring, Policy, and Maintenance · 16 commands

Windows CIM, WMI, and Hardware Inventory PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Discover CIM classesGet-CimClass -Namespace 'root/cimv2' -ClassName 'Win32_*' | Select-Object -First 25 CimClassNameView examples
Inspect class properties(Get-CimClass -ClassName 'Win32_ComputerSystem').CimClassProperties | Select-Object Name, CimTypeView examples
Inventory Windows versionGet-CimInstance -ClassName 'Win32_OperatingSystem' | Select-Object Caption, Version, BuildNumber, OSArchitecture, LastBootUpTimeView examples
Inventory computer identityGet-CimInstance -ClassName 'Win32_ComputerSystem' | Select-Object Manufacturer, Model, Name, Domain, TotalPhysicalMemoryView examples
Inventory firmware identityGet-CimInstance -ClassName 'Win32_BIOS' | Select-Object Manufacturer, SMBIOSBIOSVersion, ReleaseDate, SerialNumberView examples
Inventory processorsGet-CimInstance -ClassName 'Win32_Processor' | Select-Object DeviceID, Name, NumberOfCores, NumberOfLogicalProcessors, MaxClockSpeedView examples
Inventory memory modulesGet-CimInstance -ClassName 'Win32_PhysicalMemory' | Select-Object DeviceLocator, Capacity, Speed, Manufacturer, PartNumberView examples
Inventory physical disksGet-CimInstance -ClassName 'Win32_DiskDrive' | Select-Object Index, Model, SerialNumber, InterfaceType, Size, StatusView examples
Inventory fixed volumesGet-CimInstance -ClassName 'Win32_LogicalDisk' -Filter 'DriveType = 3' | Select-Object DeviceID, VolumeName, FileSystem, Size, FreeSpaceView examples
Inventory enabled IP adaptersGet-CimInstance -ClassName 'Win32_NetworkAdapterConfiguration' -Filter 'IPEnabled = TRUE' | Select-Object Description, MACAddress, IPAddress, DefaultIPGatewayView examples
Inventory signed driversGet-CimInstance -ClassName 'Win32_PnPSignedDriver' | Select-Object DeviceName, Manufacturer, DriverVersion, DriverDate, InfNameView examples
Run a WQL projectionGet-CimInstance -Query ` 'SELECT DeviceID,Size,FreeSpace FROM Win32_LogicalDisk WHERE DriveType=3'View examples
Create a Kerberos CIM sessionNew-CimSession -ComputerName 'server01.contoso.com' ` -Authentication KerberosView examples
Query through a CIM sessionGet-CimInstance -CimSession $session -ClassName 'Win32_OperatingSystem' | Select-Object CSName, Caption, Version, LastBootUpTimeView examples
Close a CIM sessionRemove-CimSession -CimSession $sessionView examples
Export selected inventory$inventory | Export-Csv -LiteralPath './hardware-inventory.csv' -NoTypeInformation -Encoding utf8View examples

Monitoring, Policy, and Maintenance · 18 commands

Windows Crash Dumps and WinDbg Troubleshooting Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Read recent WER eventsGet-WinEvent -FilterHashtable @{ LogName='Application'; ` ProviderName='Windows Error Reporting'; ` StartTime=(Get-Date).AddHours(-4) } -MaxEvents 100View examples
Read application crash eventsGet-WinEvent -FilterHashtable @{ LogName='Application'; ` ProviderName='Application Error'; ` StartTime=(Get-Date).AddHours(-4) } -MaxEvents 100View examples
Read bug-check eventsGet-WinEvent -FilterHashtable @{ LogName='System'; ` Id=1001; StartTime=(Get-Date).AddDays(-7) } -MaxEvents ` 50View examples
Inspect kernel dump settingsGet-ItemProperty -LiteralPath ` 'HKLM:/SYSTEM/CurrentControlSet/Control/CrashControl'View examples
Inspect page-file usageGet-CimInstance -ClassName 'Win32_PageFileUsage' | Select-Object Name, AllocatedBaseSize, CurrentUsage, PeakUsageView examples
Inspect MEMORY.DMP metadataGet-Item -LiteralPath (Join-Path $env:SystemRoot 'MEMORY.DMP') | Select-Object FullName, Length, CreationTimeUtc, LastWriteTimeUtcView examples
List recent user dumpsGet-ChildItem -LiteralPath (Join-Path $env:LOCALAPPDATA 'CrashDumps') -Filter '*.dmp' | Sort-Object LastWriteTimeUtc -DescendingView examples
Hash a dump artifactGet-FileHash -LiteralPath ` 'C:/CrashEvidence/App_260812_101500.dmp' -Algorithm ` SHA256View examples
Inspect LocalDumps policyGet-ItemProperty -LiteralPath ` 'HKLM:/SOFTWARE/Microsoft/Windows/Windows Error Reporting/LocalDumps' ` -ErrorAction SilentlyContinueView examples
Inspect per-app LocalDumpsGet-ItemProperty -LiteralPath ` 'HKLM:/SOFTWARE/Microsoft/Windows/Windows Error Reporting/LocalDumps/MyApp.exe' ` -ErrorAction SilentlyContinueView examples
Plan exception captureprocdump.exe -ma -e -n 1 -w 'MyApp.exe' ` 'C:/CrashEvidence'View examples
Cancel ProcDump monitoringprocdump.exe -cancel 4321View examples
Validate dump structuredumpchk.exe 'C:/CrashEvidence/App_260812_101500.dmp'View examples
Open a dump in WinDbgwindbg.exe -z 'C:/CrashEvidence/App_260812_101500.dmp'View examples
Set Microsoft symbol cache.symfix C:\Symbols; .reload /fView examples
Run verbose analysis!analyze -vView examples
Select exception context.ecxr; kvView examples
List loaded moduleslm t nView examples

Monitoring, Policy, and Maintenance · 14 commands

Windows Environment Variables and PATH PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
List process environmentGet-ChildItem Env: | Sort-Object NameView examples
Read one value$env:TEMPView examples
Set for current process$env:APP_MODE = 'development'View examples
Remove from current processRemove-Item Env:APP_MODEView examples
Read persistent user value[Environment]::GetEnvironmentVariable('APP_MODE', ` 'User')View examples
Set persistent user value[Environment]::SetEnvironmentVariable('APP_MODE', ` 'production', 'User')View examples
Remove persistent user value[Environment]::SetEnvironmentVariable('APP_MODE', $null, ` 'User')View examples
Read machine value[Environment]::GetEnvironmentVariable('Path', 'Machine')View examples
Split PATH safely$env:Path -split [IO.Path]::PathSeparatorView examples
Resolve all commandsGet-Command python -AllView examples
Expand percent variables[Environment]::ExpandEnvironmentVariables('%TEMP%\report.log')View examples
Start a fresh processStart-Process pwshView examples
Inspect module search paths$env:PSModulePath -split [IO.Path]::PathSeparatorView examples
Inspect runtime identity[Environment]::UserNameView examples

Monitoring, Policy, and Maintenance · 19 commands

Windows Group Policy Management PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Check the GroupPolicy moduleGet-Module -ListAvailable GroupPolicy | Select-Object Name, Version, PathView examples
List domain GPOsGet-GPO -All -Domain 'corp.example.com' -Server 'dc01.corp.example.com' | Sort-Object DisplayNameView examples
Resolve a GPO by GUIDGet-GPO -Guid '11111111-2222-3333-4444-555555555555' ` -Domain 'corp.example.com' -Server ` 'dc01.corp.example.com'View examples
Export a GPO reportGet-GPOReport -Guid $gpo.Id -ReportType Html -Path ` 'C:\Reports\Pilot-GPO.html' -Domain 'corp.example.com'View examples
Inspect OU inheritanceGet-GPInheritance -Target ` 'OU=Pilot,OU=Workstations,DC=corp,DC=example,DC=com' ` -Domain 'corp.example.com'View examples
Audit GPO permissionsGet-GPPermission -Guid $gpo.Id -All -Domain ` 'corp.example.com' -Server 'dc01.corp.example.com'View examples
Preview one GPO backupBackup-GPO -Guid $gpo.Id -Path 'C:\GPOBackups' -Domain ` 'corp.example.com' -Comment 'Before approved change' ` -WhatIfView examples
Preview all-GPO backupBackup-GPO -All -Path 'C:\GPOBackups' -Domain ` 'corp.example.com' -Server 'dc01.corp.example.com' ` -WhatIfView examples
Preview an unlinked GPONew-GPO -Name 'Pilot - Example Policy' -Comment ` 'CHG-12345; owner: Endpoint' -Domain ` 'corp.example.com' -WhatIfView examples
Read a registry policyGet-GPRegistryValue -Name 'Pilot - Example Policy' -Key ` 'HKLM\Software\Policies\Example' -ValueName 'Mode'View examples
Preview a registry policySet-GPRegistryValue -Name 'Pilot - Example Policy' -Key ` 'HKLM\Software\Policies\Example' -ValueName 'Mode' ` -Type DWord -Value 1 -WhatIfView examples
Preview removing a settingRemove-GPRegistryValue -Name 'Pilot - Example Policy' ` -Key 'HKLM\Software\Policies\Example' -ValueName ` 'Mode' -WhatIfView examples
Preview a disabled pilot linkNew-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled ` No -Domain 'corp.example.com' -WhatIfView examples
Preview enabling a linkSet-GPLink -Guid $gpo.Id -Target $pilotOu -LinkEnabled ` Yes -Enforced No -Domain 'corp.example.com' -WhatIfView examples
Preview unlinking a GPORemove-GPLink -Guid $gpo.Id -Target $pilotOu -Domain ` 'corp.example.com' -WhatIfView examples
Preview read delegationSet-GPPermission -Guid $gpo.Id -TargetName ` 'GG-GPO-Auditors' -TargetType Group -PermissionLevel ` GpoRead -WhatIfView examples
Collect computer RSoPGet-GPResultantSetOfPolicy -Computer ` 'pc042.corp.example.com' -ReportType Html -Path ` 'C:\Reports\PC042-RSoP.html'View examples
Generate local gpresultgpresult.exe /h 'C:\Reports\gpresult.html' /fView examples
Schedule a remote refreshInvoke-GPUpdate -Computer 'pc042.corp.example.com' ` -Target Computer -RandomDelayInMinutes 30 -AsJobView examples

Monitoring, Policy, and Maintenance · 16 commands

Windows Performance Counters and Resource Monitoring PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
List counter setsGet-Counter -ListSet '*' | Sort-Object CounterSetName | Select-Object CounterSetName, CounterSetTypeView examples
Inspect processor pathsGet-Counter -ListSet 'Processor Information' | Select-Object -ExpandProperty PathsWithInstancesView examples
Sample total CPUGet-Counter -Counter ` '\Processor Information(_Total)\% Processor Utility' ` -SampleInterval 2 -MaxSamples 15View examples
Sample memory pressureGet-Counter -Counter ` '\Memory\Available MBytes','\Memory\Pages/sec' ` -SampleInterval 2 -MaxSamples 15View examples
Sample physical disk latencyGet-Counter -Counter ` '\PhysicalDisk(*)\Avg. Disk sec/Read','\PhysicalDisk(*)\Avg. Disk sec/Write' ` -MaxSamples 5View examples
Sample disk queuesGet-Counter -Counter ` '\PhysicalDisk(*)\Current Disk Queue Length' ` -SampleInterval 2 -MaxSamples 15View examples
Sample network throughputGet-Counter -Counter ` '\Network Interface(*)\Bytes Total/sec' ` -SampleInterval 2 -MaxSamples 15View examples
Extract cooked values$samples.CounterSamples | Select-Object Timestamp, Path, InstanceName, CookedValue, StatusView examples
Average valid samples$samples.CounterSamples | Where-Object Status -eq 0 | Group-Object Path | ForEach-Object { $_.Group.CookedValue | Measure-Object -Average }View examples
Snapshot costly processesGet-Process | Sort-Object CPU -Descending | Select-Object -First 15 Id, ProcessName, CPU, WorkingSet64, PrivateMemorySize64View examples
Sample process CPU ratesGet-Counter -Counter '\Process(*)\% Processor Time' ` -SampleInterval 2 -MaxSamples 5View examples
Sample a remote hostGet-Counter -ComputerName 'server01.contoso.com' ` -Counter '\Memory\Available MBytes' -MaxSamples 5View examples
Write a BLG export$samples | Export-Counter -Path './perf-sample.blg' -FileFormat blgView examples
Read a BLG captureImport-Counter -Path './perf-sample.blg' | Select-Object -ExpandProperty CounterSamplesView examples
List collector setslogman.exe queryView examples
Correlate System eventsGet-WinEvent -FilterHashtable @{ LogName='System'; ` StartTime=(Get-Date).AddHours(-1) } -MaxEvents 100View examples

Monitoring, Policy, and Maintenance · 16 commands

Windows Update Management and Troubleshooting Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Record OS buildGet-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber, OsArchitectureView examples
List reported hotfixesGet-HotFix | Sort-Object InstalledOn -DescendingView examples
List servicing packagesdism.exe /Online /Get-Packages /Format:TableView examples
Inspect update servicesGet-Service wuauserv, bits, cryptsvc | Select-Object Name, Status, StartTypeView examples
Read Windows Update policyGet-ItemProperty ` 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' ` -ErrorAction SilentlyContinueView examples
Create WUA searcher$searcher = (New-Object -ComObject ` Microsoft.Update.Session).CreateUpdateSearcher()View examples
Scan for missing updates$result = ` $searcher.Search("IsInstalled=0 and IsHidden=0")View examples
Review scan results$result.Updates | Select-Object Title, MsrcSeverity, IsDownloaded, RebootRequiredView examples
Query WUA history$searcher.QueryHistory(0, 30) | Select-Object Date, Title, Operation, ResultCode, HResultView examples
Read operational eventsGet-WinEvent -LogName ` 'Microsoft-Windows-WindowsUpdateClient/Operational' ` -MaxEvents 50View examples
Build readable update logGet-WindowsUpdateLog -LogPath (Join-Path $PWD ` 'WindowsUpdate.log')View examples
Scan component-store healthdism.exe /Online /Cleanup-Image /ScanHealthView examples
Hash a staged packageGet-FileHash -LiteralPath 'C:\Staging\KB0000000.msu' ` -Algorithm SHA256View examples
Install a staged MSUdism.exe /Online /Add-Package ` /PackagePath:"C:\Staging\KB0000000.msu" ` /PreventPending /NoRestartView examples
Schedule controlled restartshutdown.exe /r /t 900 /d p:2:17 /c ` "Approved Windows Update maintenance"View examples
Cancel scheduled restartshutdown.exe /aView examples
CMDMEMO TERMINALREAD ONLY