REFERENCE, CMD / POWERSELL

Windows Command List

The list of Windows command (cmd) and PowerShell cmdlet with arguments and category filter.

158 out of 158 teams show
core (cmd) modern (powershell) security
CommandCategoryLevelDescriptionMain arguments
dir Files core List directory content with attributes and sizes /a show files with all attributes
/s resource into subdirectories
/b bare format - filenames only
/o sort order (n=name s=size d=date)
/p
/q display owner
cd / chdir Files core Change current working directory cd .. move up one level
cd \ go to drive root
cd /d D:
cd (from arches) print current directory
copy Files core Copy one or more files to another location /y over
/-y prompt before over
/b binary copy
/a ASCII copy
/v verify copy after write
xcopy Files core Extended copy of files and directory tracks /s copy non-empty subdirs
/e copy all subdirs (including empirical)
/i assume destination is directory
/h copy hidden and system files
/y over
/d copy only newer files
/eclude skip patterns from file
robocopy Files modern Robust file copy - mirror, purpose, multi-thread /mirror tree (delete extra at dest)
/e copy subdirs including empty
/z restartable mode
/mt:N multi-threaded copy (default 8)
/r:
/w:
/log:file write log to file
/xo exclude older files
/eta
move Files core Move or rename files and directories /y over
/-y delay on overwrite
move file new rename file
move *.txt D:\arc match move
del /erase Files core Delete files permanently (not to Recycle Bin) /p prompt beforee each delete
/f force delete read-only
/s course subdirectories
/q quot (from prompt) for wildcards
/a filter by repeltes (h, s, r, a)
mkdir / md Files core Create one or more directories mkdir a\b\c created nested pah in one call
md "My Folder"
rmdir / rd Files core Remove an empirical directory or sole tree /s remove directory and all content
/q quot mode (no confirmation)
rd dir remove empy directory only
mklink Files core Create symbolic links, hard links, or challenges /d directory symbolic link
/h hard link (file only)
/j directory junction
mklink link target default fileymlink
attrib Files core Display or change file contributions (R H S A) +r / -r set/clear read-only
+h / -h set/clear hidden
+s / -s set/clear system
/s apply pursuantly
/d also process folders
Get-ChildItem Files modern PowerShell - list filesystem (or register) items with rich properties -Path target pat
-Refund enumerate subdirectories
-Filter fast filesystem-level filter
- Force including hidden/system items
-File / -Directory type filter
-Hidden hidden items only
Copy-Item Files modern PowerShell - copy files, directories, or register items -Path / -Destination source and target
-Refund copy entire
- Force over
-Exclude pattern to skip
-Filter fast provider filter
-PassThru emit crowded object
Remove-Item Files modern PowerShell - delete files, folders, register keys -Refund delete subtree
- Force delete read-only/hidden
- Include / -Exclude patch filters
- Confirm prompt before
-WhatIf dry-run preview only
where Files core Locate executables in PATH where program find first match in PATH
/r dir refund from directory
/q quot
/f quota returned path
/t show size and timing
assoc / ftype Files core Display or modify file extension associations and command handlers assoc list all associations
assoc .txt show association for ext
assoc .txt=txtfile set association
ftype list all file types
ftype txtfile=notepad
Test-Path Files modern Power -Path target pah
-PathType Leaf/Container/ Any
- IsValid check syntax only
- IsAbsolute absolute path check
-OlderThan / -NewerThan time predicate
type Text core Display the contents of a text file on the password type file.txt print file
type a.txt b.txt concatenate
type *.log prints files + content
more Text core Display output one screen at a time (pager) /c clear screen before before each page
/s squeeze multiple blank lines
+N start at line N
Space next page ENTER next line
findstr Text core Search for text patches in files /i case-intensive match
/r treat strings as regular expressions
/s course subdirectories
/n prefix output with line numbers
/v print lines that do NOT match
/c:"phrase' literary multi-word search
/g:
point Text core Search for a literal text string in files /i case-intensive
/v invert
/c count matching lines
/n show line numbers
fc Text core Compare two files and show differences /a
/b binary compare
/n show line numbers (text)
/u Unicode compare
/w ignore whitespace
comp Text core Byte-by-byte file comparison /a display differences as characters
/l show line numbers of differences
/n=N compare first N lines only
/c case-intensive
short Text core Short lines from /r reverse short order
/+N start at Column N
/m N use N megabytes of memory
/o file write output to file
Select-String Text modern PowerShell - regex search across files (grep equivalent) - Pattern regex to match
-Path / -LiteralPath files to search
- CaseSensitive exact case
-Context A,B N lines before/after
-NotMatch invert
-List one match per file only
-AllMatches all matches per line
Get-Content Text modern PowerShell - read file content (cat/tail/head equivalent) - TotalCount N first N lines (head)
-Tail N last N lines
-Wait follow file (tail-f)
-Encoding UTF8, ASCII, Unicode
-Raw read as single string
-Stream read alternate data stream
Set-Content Text modern PowerShell - write or reply file content with given string -Path target file
-Value content to write
-Encoding UTF8, ASCII, UTF8BOM
- Force over
-NoNewline do not append CRLF
ConvertFrom-Json/ConvertTo-Json Text modern PowerShell - parse JSON into objects and back to text ConvertFrom-Json string → object
-Depth N nesting deep (default 2)
ConvertTo-Json object → string
-Compress from whitespace
-AsHashtable parse into hashtable
doskey Text core Recall and edit command history; defined command macros (cmd.exe) /history print command history
/listsize=N history buffer size
name=command define macro a.k.a
/macros list all macros
/macrofile=fileload macros from file
clip Text core Pipe stdout into the Windows clipboard echo hello √ clip copy text to clipboard
dir
type file √ clip copy file content
takklist Processes core Display all running processes with PID and memory /v verbose (user, status)
/svc show services in each process
/fi apply filter (e.g. "imagename eq chromium.exe")
/fo output format (table, csv, list)
/m show DLLs loved by process
taskkill Processes core Terminate a running process by PID or name /pid N terminate by process ID
/im name.exe terminate by image
/f force termate (from graceful close)
/t also terminate child processes
/fi apply filter (e.g. "status eq not responding")
start Processes core Start a separate window to run a program or command /b start without new window
/
/min/ /max start minimized/maximized
/d path starting directory
/finity N CPU affinity mask
start "
Get-Process Processes modern PowerShell - retrieve process objects with rich properties - ed
-Id N filter by PID
-IncludeUser show owner (admin)
-Module show loved modules
-FileVersionInfo show exe version
√ Sort-Object CPU -Desc top by CPU
Stop-Process Processes modern PowerShell - terminate one or more processes -Id N Terminate by PID
- name
- Force skip confirmation
-PassThru issue termed object
- Confirm prompt beforee kit
Start-Process Processes modern PowerShell - Launch program with detailed control -FilePath external to run
- ArgumentsList command-line argument
-Verb RunAs Elevated (UAC prompt)
-WindowStyle Hidden/Minimized
-Wait block
-RedirectStandardOutput capture stdout
Wait-Process Processes modern PowerShell - block until one or more processes apart - %1
-Id N wait for PID
-Timeout N give up after N seconds
-ErrorAction Silently
Get-Service Processes modern PowerShell - list and inspect Windows services - filter
-Display filter
-Status Running, Stopped, Paused
- Include / -Exclude patch filter
-RequiredServices show scholarships
Procmon (Sysinternals) Processes modern Real-time file, register, network, and process activity monitor /AcceptEula skip EULA prompt
/Quiet start tracking immediately
/BackingFile log to file
/Load
/Terminate stop running instance
shutdown Processes core Shut down, restart, or log off the local or remote computer /s shut down
/r restart
/l log off
/g shutdown + restart apps
/t
/m \host target remote host
/c "msg" comment shown to users
/f force close apps
/a abort pending shutdown
logoff Processes core End a user session (local or terminal services) sesionid log off specific session
/server:
/v verbose
note: combination with quser to find session ID
Restart-Computer Processes modern PowerShell - reboot one or more computers (local or remote) -Computer host1,host2
- Force force shutdown despite locked sessions
-Credential alternative credentials
-Wait -For PowerShell wait until WinRM up
-Delay N retry interval
- Protocol DCOM/WSMan
Stop-Computer Processes modern PowerShell - power off one or more computers -Computer host
- Force force
-Credential alternative credentials
-WsmanAuthentication Default/Basic/Kerberos
Invoke-Command Processes modern Power -Computer host1,host2
-ScriptBlock { }
-FilePath script.ps1
-Credential alternative credentials
-AsJob run as background job
-ThrottleLimit N
Enter-PSSession Processes modern Power -Computer host
-Credential alternative credentials
- Authentication Kerberos/CredSSP
-Configuration name
- UseSSL WinRM over HTTPS
Exit-PSSession leave session
sc System core Control and query the Windows Service Control Manager query list services and status
queryex include PID and flags
start / stop control service
config change start type or path
create name bin
delete remove service
systeminfo System core Display detailed configuration of the local system /s host query remote computer
/u user authentication as user
/fo output format (table, csv, list)
/nh suppress heads (csv/table)
ver System core Display the Windows version string ver print OS version
hostname System core Print the computer NetBIOS hostname hostname prints current hostname
set System core Display, set, or remove environment variables set VAR=value set in current session
set VAR=remove from session
set list all variations
set /p VAR=Prompt: read from user
set/a Var=2*3 aarithmetic evaluation
setx System core Persistently set environment variables (user or machine) setx Var value set for current user
/m set system-wide (admin)
/s host set on remote computer
/k regkey read from register
note:
wmic System core Windows Management Instrumentation command-line (legacy) os get capture,version
cpu get name
logicaldisk get size,freespace,caption
process where name='chrome.exe' get processid
computer get utility,model
note: WMIC is depreciated and not installed by default since Windows 11 24H2 - use Get-CimInstance
Get-CimInstance System modern PowerShell - query WMI/CIM objects (WMIC replacement) -Class WMI class (Win32 *)
-Filter WQL filter
-Property return only listed benefits
-Computer query remote system
- alternate
Get-ComputerInfo System modern PowerShell - retrieve consolidated system information object -Property * show all properties
Os* filter to OS-related properties
Bios* BIOS/firmware info
Cs* computer system info
Set-Service System modern PowerShell - configure a Windows service - service to modify
-Status Running/Stopped
-StartupType Automatic/Manual
- set service description
-Display set display
schtasks System core Task Scheduler CLI /create defined new scheduled task
/run trigger immediately
/end stop running task
/query list all tasks
/delemove task
/sc schedule type (DAILY, ONLOGON, ONSTART)
/tn
git System modern Distributed version control - track and collaborate on code status
log-oneline--graph compact history
diff HEAD changes since last committee
stash push/pop hatche and restore changes
rebase -i interactive squash/reorderer
bisect start/good/bad find bug committee
blame show line-by-line authority
winget System modern Windows Package Manager - install, upgrade, remove apps search
install id install package
upgrade --all update all packages
list show installed packages
uninstall id remove package
source add add
export/import reproduce setup
choco System modern Chocolatey - community Windows package manager install pkg -y install warmly
upgrade all -y update all packages
list --local-only installed packages
uninstall pkg -y remove package
pin add -n=pkg freeze version
feature enabled -n enabled feature
gpupdate System core Refresh Group Policy settings on the local computer /force again all settings
/target:usera
/wait:
/logoff log off if needed by policies
/boot reboot if needed by policies
/sync synchronous
reg System core Read, write, import, export, and company Windows Registry entities query KEY /s returnable list
query KEY /v VALUE
add KEY /v name /t REG SZ / d
delete KEY /v name / f
export KEY file.reg
import file.reg
save KEY file.hiv raw hive
load HKLM\Tmp file.hiv
regedit System core Registry Editor - GUI for browsing and modifying the register regedit open GUI
regedit /s file.reg silently applicable .reg
/e file.reg HKLM\path export branch
note: prefer 'reg' for scripting
msiexec System core Install, uninstall, or repair MSI/MSP packages i pkg.msi install
/x pkg.msi uninstall
/qn silent (from UI)
/qb basic UI
/norestart do not auto-reboot
/l*v log.txt verbose login
ALLUSERS=1 machine-wide
TRANSFORMS= applicable .mst
sfc System core System File Checker - scan and repair protected OS files /scannow scan and repair all system files
/verifyly scan without repair
/scanfile=path check single file
/offbootdir / /offwindir offline image scan
note:
dysm System core Employment Image Service and Management - online and image service /Online target running OS
/Image:
/Cleanup-Image /RestoreHealth Repair
/Get-Features list features
/Enable-Feature /Feature
/Get-Packages list installed updates
/Add-Driver /Driver:path
/Export-Image export WIM
bcdedit System core Boot Configuration Data store editor - boot loader configuration /enum list boot entries
/default {GUID} set default OS
/timeout
/set {GUID} description "name"
/copy {GUID} /d "copy"
/export file back up BCD
/import file repairer BCD
note:
driverquery System core List installed device drivers and their properties /v verbose
/si signed driver info
/fo output format (table, list, csv)
/nh suppress heads
/s host /u user remote query
pnputil System core Manage driver packages in the driver store /enum-drivers list staged drivers
/add-driver in addition and install
/delete-driver oem##.inf /uninstall
/scan-doses rescan for new devices
/disable-device / /enable-device
/restart-device
powercfg System core Query and configure power plans, sweep, hibernation, battery /list list power schemes
/setactive GUID
/h on
/lastwake show last wake source
/devicequery wake armed who can wake
/batteryreport HTML battery report
/energy power efficiency audit
/requests active power requests
net share / net use System core Manage SMB shares and folderd network drives net share list local shares
net share name=C:
/grant:user, read
net use Z:
net use Z:
/user:
/persistent:yes
net start / net stop System core Start or stop a Windows service net start list running services
net start name start service
next
note:
Restart-Service / Start-Service / Stop-Service System modern PowerShell - lifecycle control for Windows services - %1
- Force override grants
-PassThru issue resulting object
- Confirm prompt before
-WhatIf dry-run preview
Get-HotFix System modern PowerShell - list installed Windows updates (KB articles) -Id KB#######
-Computer host remote
- Hotfix/Update/Security
InstalledOn by date
Get-ItemProperty System modern PowerShell - read property values (e.g. history values) -Path HKLM:\Software\name
- value
Set-ItemProperty write value
New-ItemProperty created value
Remove-ItemProperty delete value
Get-WindowsFeature / Install-WindowsFeature System modern PowerShell - Server Manager - management rules and features (Windows Server) Get-Windows
- Web-Server filter
Install-Windows
-IncludeManagementTools
-IncludeAllSubFeature
-Restart reboot if needed
Uninstall-WindowsFeature remove
icacls Rights core Display, modification, and back up NTFS access control players (ACLs) /grant user:perm grant permission (F, M, RX, R, W)
/deny user:perm explicit deny
/remove user remove all ACEs for user
/t resource into subdirectories
/c continue on machines
/inheritance:e/d/r enable/disable/reset
/save file back up ACLs
/restore file restore ACLs
takeown Rights core Take ownership of a file or bear (typically as admin) /f file target file or directory
/r returnive
/d Y/N default answer for prompt
/a give ownership to Administrator group
/skipsl skipymlinks
speeches Rights core Run a program under a different user account /user: DOMAIN\user specify user
/profile load user profile
/savecred save criticals in Vault
/neonly remote-only criticals
/noprofile from profile (faster)
net user Rights core Manage local user accounts (create, modify, delete, list) net user list all local accounts
net
net user name pass /
/delete remove user
/active:yes
/passwordchg:yes
net localgroup Rights core Manage local groups and their members net localgroup list groups
net localgroup Administrator list members
Administrator user /add add to group
/delete remove from group
group /add create new group
whoami Rights core Display current user, SID, groups, and primileges /user show username and SID
/groups group members
/priv enabled privileges
/all show everything
/fo output format (table, csv, list)
/upn show UPN form
/login show logon ID
cipher Rights core Manage EFS encryption and safely wipe free disk space /e encrypt files
/d decrypt files
/s:dir resource directory
/w:dir wipe delegated data on volume
/k create new EFS key for user
/u update encrypted files with new key
Get-Acl / Set-Acl Rights modern PowerShell - read or write security descriptor of files, folders, register Get-Acl path retrieve ACL object
Set-Acl path -AclObject only ACL
-Audit also include audit ACEs
"Format-List inspection entities"
$acl.SetAccessRule() add ACE programmatically
net user /domain Rights core Query and manage thought user accounts (joined to AD) net user name /
/domain query domain controller
/add /domain create domain account (admin)
note: required AD-joined machine
gpressult Rights core Display applied Group Policy (RSoP) for user and computer /r summary report
/v verbose
/z super-verbose
/h file.html HTML report
/scope user
/user name
auditpol Rights modern View and configuration /get / category:* show current policy
/set /sub category:
/list /subcategory:* list all categories
/backup /file:audit.csv export policy
/restor /file:audit.csv import policy
/clear clear audit policy
Get-LocalUser/New-LocalUser Rights modern PowerShell - management local user accounts (modern net user replacement) Get-LocalUser list local accounts
- name
New-LocalUser -Name -Password (Read-Host -AsSecure)
Set-LocalUser modifiy account
Remove-LocalUser delete account
Enable-LocalUser/Disable-LocalUser
Add-LocalGroupMember -Group Administrator -Member name
Get-ADUser (RSAT) Rights modern PowerShell - query Active Directory user objects (requires RSAT) - Identity sam by SAMAccount
-Filter 'Enabled-eq $true'
-SearchBase 'OU=Sales,DC=...'
-Properties * return all responses
-Server dc.example target DC
Set-ADUser modifications
Unlock-ADaccount
Add-ADGroupMember (RSAT) Rights modern PowerShell - management Active Directory group membership - Identity Group
- Members user1,user2
Remove-ADGroup
Get-DGroup
-Refoursive flatten nested groups
Get-DGroup -Filter * enumerate groups
klist Rights core View and purge Kerberos ticket klist list current ticket
ticket service ticket
tgt Ticket Granting Ticket
purge delete all ticket
purge bind purge bindings
sessions list logo sessions
-li 0x3e7 computer session
ipconfig Network core Display TCP/IP configuration for all network adapters /all show full info incl. MAC, DNS, DHCP
/release [adapter] release DHCP please
/new [adapter] request new DHCP please
/flushdns clear DNA
/displaydns show
/registerdns re-register with DNA
netstat Network core Display TCP/UDP connections, placing ports, and statistics -a all communications and documentation
-n numeric addresses (from DNA)
-o show PID downing connection
-b show existing name (admin)
-r selectable
-s protocol statistics
-p tcp·udp protocol filter
ping Network core Test host reachability using ICMP echo -n N number of echo requests
-l N payload size
-t ping continuous
-i N set IP TTL
-w ms timeout
-4 / -6 force IPv4 or IPv6
tracert Network core Track the network path packages take to a host -d do not resolve hostnames
-h N max hops
-w ms timeout per probe
-4 / -6 force IPv4 or IPv6
trackert host default track
pathping Network core Combine trackout with per-hop package loss statistics -n of
-h N max hops
-q N quests per hop
-w ms timeout
-p ms wait between pings
-4 / -6 force protocol
nslookup Network core Interactive and non-interactive DNA lookup nslookup host basic lookup
nslookup host server
set type=MX change queue type
set type=
-debug show full response
route Network core Display and modify the IP setting table print show
add destin mask gw add static route
delete destin remove route
change dest modifiy route
-p make route persistent
-4 / -6 IPv4 or IPv6 table
arp Network core Display and modify the ARP cache (IP↔MAC Mappings) -a show ARP table
-d ip delete entry
-s ip mac add static entry
-N iface filter by interface
netsh Network core Configuration network interfaces, firewall, WLAN, and more interface ip show config view IP settings
wlan show profiles list brings Wi-Fi
wlan show profile
advfirewall set all profiles state on
int tcp show global TCP tuning
winsock set set set Winsock catalog
Test-NetConnection Network modern PowerShell - port reachability, traceroute, ping diagnostics -Computer host target
-Port N test specific TCP port
-TraceRoute show route hops
- CommonTCPPort HTTP/HTTPS/RDP
-InformationLevel Detailed full output
tnc host -p 443 shorthand
Get-NetIPAddress Network modern PowerShell - retrieve IP address configuration objects -InterfaceAlias name filter by adapter
-AddressFamily IPv4 / IPv6
-PrefixOrigin Dhcp/Manual
-SkipAsSource filter source preference
√ Format-Table tabular view
ssh (OpenSSH) Network modern Secure Shell client - remote login, exec, port forwarding -i identity (private key) file
-p N remote port
-L local port forwarding
-R remote port forwarding
-J jump
-N do not execute remote command
-v verbose debug output
Resolve-Dns Network modern PowerShell - query DNA records with full record-type support -Type A/AAAA/MX/TXT/ANY
-Server ip use specific residual
-DnsOnly clip Hosts file
-NoHostFile note static hosts
-LlmnrFallback also try LLMNR
nbtstat Network core Display NetBIOS over TCP/IP statistics and name cache -a host remote
-A ip remote name table by IP
-n local name
-c NetBIOS name cache
-r resolved names
-R purge and reload from LMHOSTS
-S sessions table
nltest Network core Test and configuration NETLOGON, domain trusts, and DC discovery /dsgetdc:DOMAIN locale DC for domain
/sc query:DOMAIN query secure channel
/sc reset:DOMAIN reset secure channel
/domain trust list trust relations
/dclist:DOMAIN list DCs in domain
/parentdomain show preliminary thought
netsh advfirewall Network core Configure Windows Defender Firewall - roules, profiles, login set all profiles
firewall add rule name=R protocol=TCP dir=in localport=8080 action=allow
firewall
firewall delete rule name=R
monitor show contacts
set loging filename file.log
set output policy
New-NetFirewallRule Network modern PowerShell - create Windows Firewall rules -Display name
-Direction Inbound/Outbound
-Action Alllow/Block
- Protocol TCP/UDP/ICMPv4
-LocalPort N
- RemoteAddress ip/subnet
-Profile Domain/Private/Public
Get-NetFirewallRule/Remove-NetFirewallRule
curl Transmission core Transfer data over HTTP, HTTPS, FTP, and many other protons -o write output to file
-X HTTP method (GET POST PUT...)
-H add request header
-d POST body data
-L follow redirects
-k skip TLS verification
--retry N rtry on transient file
-u user:pass basic auth
--form multipart/form-data
-s silent (from progress)
Invoke-WebRequest Transmission modern PowerShell - HTTP client return parsed response object - Uri target URL
- Matthew GET/POST/PUT/DELET
- Headers {mm/ yyyy}
- Body request body
-OutFile save response to file
- UseBasicParsing from IE engine
-SkipCertificateCheck denore TLS error
-Credential pass PSCredential
Invoke-RestMethod Transmission modern PowerShell - HTTP client for REST APIs (parses JSON/XML) - Uri endpoint
- Matthew HTTP verb
- Headers request heads
- Body body (auto-series JSON if hashtable)
-ContentType set content-type
- Authentication Bearer -Token modern auth
"ConvertTo-Json perspective result
bitsadmin Transmission core Background Intelligent Transfer Service - resumable downloads (legacy) /transfer name url file download URL to file
/list show active jobs
/cancel jobid abort job
/info jobid /verbose job state
note:
Start-BitsTransfer Transmission modern PowerShell - resumable background HTTP/HTTPS/SMB transfer -Source url source URL
- Destination path target file
- Asynchronous non-blocking job
-Priority Foreground/High/Normal/Low
- Authentication Basic/NTLM/Negoitate
- RetryInterval N seconds between retries
scp (OpenSSH) Transmission core Securely copy files between hosts over SSH -r resource copy of directories
-P N specified remote port
-i identity (private key) file
-p prevent timesteps and fashion
-v verbose debug output
sftp (OpenSSH) Transmission core Interactive secure file transfer over SSH -P N specify port
-i identity file
get / put download / upload file
ls / lls list remote / local files
mget / mput match transfer
perfmon Monitoring core Performance Monitor - real-time and recorded counterparties (GUI/CLI) perfmon open Performance Monitor
perfmon /res open Resource Monitor
perfmon /rel open Relief Monitor
perfmon /report generation System Diagnostic report
typeperf Monitoring core Sample performance counters and write to stdout or CSV "\Processor( Total)\% Processor Time"
-sc N sample count
-si N sample interval (seconds)
-f csv/tsv/bin output format
-o file write to file
-cf file read counter list from file
-q list all counters
Get-Counter Monitoring modern PowerShell - single performance counters with rich objects - Counter "\path' counter path
-SampleInterval N seconds between samples
-MaxSamples N number
- Continuous sample until Ctrl+C
-Computer remote host
-ListSet * enumerate counter sets
Get-EventLog Monitoring modern PowerShell - read classic Windows event window (legacy API) -Log Application/System/Security
-Newest N most recent N entities
-EntryType Error/Warning/Information
-Source name filter by source
- After / -Belore time range
note: supersed by Get-WinEvent
Get-WinEvent Monitoring modern PowerShell - read modern (ETW) Windows event windows with XPath/XML filters -Log Microsoft-Windows* / Security
-FilterHashtable @{LogName='Security'; Id=4625}
-MaxEvents N cap output
-Oldest oldest first
-FilterXPath X
-ListLog * enumerate window
wevtutil Monitoring core Windows Event Log command-line utility el
qe Security /c:10 /rd:tree /f:text query
cl Security Clear log
gli Security log info
epl Security file.evtx export log
sl Log
resmon Monitoring core Resource Monitor - GUI for CPU, memory, disk, network in real time resmon launch GUI
note: Drill down per-process I/O and network connections
Get-NetTCPConnection Monitoring modern PowerShell - list active TCP connections (modern netstat) -State Listen/Established
-LocalPort N filter by local port
- RemoteAddress ip filter by remote IP
-OwningProcess PID filter by process
Id
Sysmon (Sysinternals) Monitoring modern System Monitor - rich endpoint telemetry into Event Log -i config.xml install with config
-c config.xml update running config
-u force uninstall
-h sha256,imphash set hash algorithms
-n log network connections
note: events appeared in Microsoft-Windows-Sysmon/Oporal
quser / query user Monitoring core Display interactive and RDP user sessions on local or remote host quser list sessions on local
quser /server:host remote host
note:
qwinsta / rwinsta Monitoring core Query and reset terminal services (RDP) sessions qwinsta list sessions
qwinsta /server:host
rwinsta sessionid set session
rwinsta /server:host id
note: equivalent to 'query session'
diskpart Discs core Manage disc, partitions, and volumes (scriptable disc utility) list disk / partition / volume
select disk N
clean wipe partition table
create partition primary
format fs=ntfs quick
assign letter=X
extend / shrink desired = N
note:
chkdsk Discs core Check disk for filesystem machines and bad sections /f fix filesystem error
/r also locale bad sectors
/x force dismount before scan
/scan online scan (NTFS)
/spotfix targeted fix on next boot
/b re-evaluate bad clusters (with /r)
fsutil Discs core Filesystem utility for advanced MMFS, USN, links, and quotes fsinfo drives list drives
volume diskfree C: free/total bytes
behind the set tunnel
usn USN journal management
hardlink create create hard link
file createnew name N creation N-byte file
format Discs core Format a disk volume with a filesystem /fs:NTFS-FAT32-exFAT filesystem type
/q quick format
/v:
/a:
/l large FRS (NTFS)
/p:
mountvol Discs core Mount or unmount a volume at a drive letter or MMFS bear mountvol list mounted volumes
mountvol X: \\? \Volume{GUID}\mount
mountvol X: /d unmount drive
/r remove orphaned points
/n / /e disabled/enable auto-mount
Get-Disk Discs modern PowerShell - retrieve physical disk objects and health -Number N filter by disk number
-Friendly name
Initialize-Disk -PartitionStyle GPT
√ Set-Disk - IsOffline $false
HealthStatus disk health summary
Get-Volume Discs modern PowerShell - retrieve volumes with size, filesystem, health -DriveLetter C
-FileSystem MMFs/ReFS/FAT32
-FileSystemLabel name
- OfflineScanAndFix
√ Optimize-Volume - Defrag
New-Partition / Format-Volume Discs modern Power New-Partition - DiskNumber N - UseMaximumSize
-DriveLetter X assign letter
- AssignDriveLetter auto-assign
Format-Volume -FileSystem MMFS
-NewFileSystemLabel label
- Confirm:
defrag Discs core Analyze and Defragment Volumes Defragment drive
/a analysis only
/o optimal (defrag + slab consolidated)
/l retrim SSD
/x free-space consolidation
/v verbose output
convert Discs core Convert FAT/FAT32 volume to MMFs in-place C: /fs:ntfs basic conversion
/v verbose
/cvtarea:file reserve MFT space
/nosecurity no security descriptors
/x force dismount first
note: one-way; cannot convert to FAT
vssadmin Discs core Manage Volume Shadow Copies and storage providers list shadows show all snapshots
list shadowstorage storage location
create shadow / for=C:
delete shadows / for=C: /oldest
resize shadowstorage /on=C: /maxsize=10GB
list writers list VSS writers
Get-PhysicalDisk Discs modern PowerShell - retrieve physical disc objects (Storage Spacesera) -Friendly name
-MediaType SSD/HDD/SCM
-HealthStatus Healthy/Warning
√ Get-StoragePool Associated Pool
Reset-PhysicalDisk brand back online
tar Archives core Built-in BSD tar - create/extract archives (.tar, .tar.gz, .zip) -c create archive
-x extract archive
-f file archive filename
-z gzip filter
-v verbose listing
-t list content without extracting
--strip-compponents N strip pat level
note: built into Windows 10 1803+
compact Archives core View and change MMFS file compression /c compress files
/u uncompress files
/s course subdirectories
/a display hidden/system files
(i)
/exe:LZX√XPRESS algorithm choice
expand Archives core Expand pressed CAB/MSU/cabinet archives -r rename expanded files
-i ignore directory structure
-f:* files to expand (childcards)
-d display content only
source most basic expansion
Compress-Archive Archives modern PowerShell - create or append to .zip archives -Path files/dir to include
- DestinationPath file.zip
-Update add/update entities
- Force over
-CompressionLevel Fastest/Optimal
Expand-Archive Archives modern PowerShell - extract .zip archive contents -Path file.zip
- DestinationPath dir
- Force over
-PassThru emit extracted items
7z (7-Zip CLI) Archives modern 7-Zip - high-ratio compression with 7z, zip, tar, gz support a archive. 7z files added to archive
x archive. 7z extract protecting paths
e archive. 7z extract flat
l archive. 7z list content
t archive. 7z test integrity
-p set password
-mx=9 max compression
-mhe=on encrypt heads
nmap Intrusion test security Network Scanner - host discovery, port scan, service detection -sV detect service versions
-sC run default NSE scripts
-O enable OS fingerprinting
-p specific port range (e.g. 1-65535)
-A aggressive: OS+version+scripts+traceroute
--script run specific NSE script
-oN / -oX output to file
-Pn slip host discovery (size up)
-sS SYN stealth scan (admin)
certutil Intrusion test security Certificate Services tool - inspection certs, hash files, base64 encode -hashfile file SHA256 hash a file
-encode in out base64 encode
-decode in out base64 decode
-store -enterprise Root list Root certs
-verify -urlfech cert.cer
-dump inspection certificate
note: also used by actors as LOLBin
openssl Intrusion test security TLS/SSL toolkit - certificates, keys, entry, and testing s client -connect host:443 test TLS
x509 -in cert.pem -text inspect cert
genrsa -out key.pem 4096 generate RSA key
req -new generation CSR
enc -aes-256-cbc encrypt/decrypt
verify -CAfile validate chain
speak benchmark ciphers
ssh-keygen Intrusion test security Generation, management, and convert SSH authentication keys -t ed25519 modern key type (recommended)
-b 4096 bit length (for RWA)
-C 'comment' add identifying comment
-f file output file path
-p change or remove
-l print
gpg Intrusion test security GNU Privacy Guard for Windows - encrypt, sign, verify --gen-key generic key pair
-e -r recipient encrypt file
--decrypt decrypt .gpg file
-s create detailed signature
--verify verify signature file
--armo ASCII-armored output
--export / --import key management
PsExec (Sysinternals) Intrusion test security Executive processes on remote systems with full I/O resolution \\host -u user -p pass cmd
-s run as SYSTEM
-i interactive (show GUI)
-d do not wait for process
-c copy local exe to remote
-h elevated token
note:
mimikatz Intrusion test security Windows critical extraction toolkit (RED TEAM / LAB ONLY) privacy::debug aquire SeDebug
sekirlsa::logonpasswords dump LSASS creds
lsadump:
kerberos::
note: blocked by Defender; LAB USE ONLY
legal:
hashcat Intrusion test security GPU-qualified password hash cracking tool -m hash type (1000=NTLM, 13100=Kerberos TGS)
-a image mode (0=dict, 3=bruteforce)
-w workload profile (12.2006,4)
-r rules applicable rules file
--show show already cracked hashes
--status live progress update
john (JtR) Intrusion test security CPU-based password hash cracker with auto-detection --wordlist dictionary file path
--rolls apply mangling rules
--format=ntlm specific hash type
--show display cracked passwords
--fork N parallel processes
note: Cygwin or native Win64 built
Defender (Set-MpPreference) Intrusion test security PowerShell - configure Microsoft Defender Antivirus Get-Mp
Set-MpPreference -DisableRealtimeMonitoring
Add-MpPreference -ExclusionPath path
Start-MpScan -ScanType QuickScan/FullScan
Update-Mp
Get-MpThreat
docker Containers modern Build, ship, and run application containers (Docker Desktop) run -d run container detached
run --rm auto-remove on exit
exec -it open shell in running container
window -f follow container log stream
inspect detailed JSON metadata
ps -a list all containers
building -t building image with tag
network ls / inspection management networks
volume ls/inspect manage volumes
system usage
kubectl Containers modern CLI to manage Cubanetes clusters and jobs get pot/svc/nodes list resources
describe pod
applicable -f manifest.yaml employment/update
exec -it pod -- powershell shell into pod
window -f pod follow log stream
top node / top pod resource use
rollout status/undo employment control
port-ward forward local port to pod
config use-text
podman Containers modern Rootless daemonless OCI engine - Windows port via WSL run --rm auto-remove after exit
--user 1000 run as non-root UID
--pod attach to pod group
-v single mount host volume
generale kube export as Kubernetes Yaml
play kube run from Cubanettes YAML
helm Containers modern Cubanettes package manager for tempered chart employments install release
upgrade --install upsert employment
rollback release
list show all requested releases
value
repo add / update management chart repos
template tender manifests locally
wsl Containers modern Windows Subsystem for Linux - run Linux distros and containers --list --verbose show distros and state
--install -d Ubuntu install distro
--set-default name
--set-version name 2 Switch to WSL2
--shutdown stop all distros
--export / --import backup/restore
note: required for Docker Desktop on Windows