Windows komandu saraksts
Windows komandu (cmd) un PowerShell cmdlet saraksts ar argumentiem un kategoriju filtru.
| Komanda | Kategorija | Līmenis | Apraksts | Galvenie argumenti |
|---|---|---|---|---|
| dir | Faili | core | List directory contents with attributes and sizes | /a show files with all attributes /s recurse into subdirectories /b bare format - filenames only /o sort order (n=name s=size d=date) /p pause after each screen /q display owner |
| cd / chdir | Faili | core | Change current working directory | cd .. move up one level cd \ go to drive root cd /d D:\path also switch drive cd (no args) print current directory |
| copy | Faili | core | Copy one or more files to another location | /y overwrite without prompt /-y prompt before overwrite /b binary copy /a ASCII copy /v verify copy after write |
| xcopy | Faili | core | Extended copy of files and directory trees | /s copy non-empty subdirs /e copy all subdirs (including empty) /i assume destination is directory /h copy hidden and system files /y overwrite without prompt /d copy only newer files /exclude skip patterns from file |
| robocopy | Faili | modern | Robust file copy - mirror, resume, multi-thread | /mir mirror tree (delete extra at dest) /e copy subdirs including empty /z restartable mode (resume on break) /mt:N multi-threaded copy (default 8) /r:N retry count on failure /w:N wait seconds between retries /log:file write log to file /xo exclude older files /eta show estimated time of arrival |
| move | Faili | core | Move or rename files and directories | /y overwrite without prompt /-y prompt on overwrite move file new rename file move *.txt D:\arc batch move |
| del / erase | Faili | core | Delete files permanently (not to Recycle Bin) | /p prompt before each delete /f force delete read-only /s recurse subdirectories /q quiet (no prompt) for wildcards /a filter by attributes (h, s, r, a) |
| mkdir / md | Faili | core | Create one or more directories | mkdir a\b\c create nested path in one call md "My Folder" quote names with spaces |
| rmdir / rd | Faili | core | Remove an empty directory or whole tree | /s remove directory and all contents /q quiet mode (no confirmation) rd dir remove empty directory only |
| mklink | Faili | core | Create symbolic links, hard links, or junctions | /d directory symbolic link /h hard link (file only) /j directory junction mklink link target default file symlink |
| attrib | Faili | core | Display or change file attributes (R H S A) | +r / -r set/clear read-only +h / -h set/clear hidden +s / -s set/clear system /s apply recursively /d also process folders |
| Get-ChildItem | Faili | modern | PowerShell - list filesystem (or registry) items with rich properties | -Path target path or wildcard -Recurse enumerate subdirectories -Filter fast filesystem-level filter -Force include hidden/system items -File / -Directory type filter -Hidden hidden items only |
| Copy-Item | Faili | modern | PowerShell - copy files, directories, or registry items | -Path / -Destination source and target -Recurse copy entire tree -Force overwrite read-only -Exclude pattern to skip -Filter fast provider filter -PassThru emit copied object |
| Remove-Item | Faili | modern | PowerShell - delete files, folders, registry keys | -Recurse delete subtree -Force delete read-only/hidden -Include / -Exclude pattern filters -Confirm prompt before deletion -WhatIf dry-run preview only |
| where | Faili | core | Locate executables in PATH (Linux 'which' equivalent) | where program find first match in PATH /r dir recurse from directory /q quiet (only exit code) /f quote returned paths /t show size and timestamp |
| assoc / ftype | Faili | core | Display or modify file extension associations and command handlers | assoc list all associations assoc .txt show association for ext assoc .txt=txtfile set association ftype list all file types ftype txtfile=notepad %1 set handler |
| Test-Path | Faili | modern | PowerShell - test if a file, folder, registry path, or variable exists | -Path target path -PathType Leaf/Container/Any -IsValid check syntax only -IsAbsolute absolute path check -OlderThan / -NewerThan time predicate |
| type | Teksts | core | Display the contents of a text file on the console | type file.txt print file type a.txt b.txt concatenate type *.log prints filenames + contents |
| more | Teksts | core | Display output one screen at a time (pager) | /c clear screen before each page /s squeeze multiple blank lines +N start at line N SPACE next page ENTER next line |
| findstr | Teksts | core | Search for text patterns in files (regex capable) | /i case-insensitive match /r treat strings as regular expressions /s recurse subdirectories /n prefix output with line numbers /v print lines that do NOT match /c:"phrase" literal multi-word search /g:file read patterns from file |
| find | Teksts | core | Search for a literal text string in files | /i case-insensitive /v invert (lines not containing string) /c count matching lines /n show line numbers |
| fc | Teksts | core | Compare two files and show differences | /a abbreviated text output /b binary compare /n show line numbers (text) /u Unicode compare /w ignore whitespace |
| comp | Teksts | core | Byte-by-byte file comparison | /a display differences as characters /l show line numbers of differences /n=N compare first N lines only /c case-insensitive |
| sort | Teksts | core | Sort lines from input or files alphabetically | /r reverse sort order /+N start sort at column N /m N use N megabytes of memory /o file write output to file |
| Select-String | Teksts | modern | PowerShell - regex search across files (grep equivalent) | -Pattern regex to match -Path / -LiteralPath files to search -CaseSensitive exact case -Context A,B N lines before/after -NotMatch invert (non-matching lines) -List one match per file only -AllMatches all matches per line |
| Get-Content | Teksts | modern | PowerShell - read file content (cat/tail/head equivalent) | -TotalCount N first N lines (head) -Tail N last N lines -Wait follow file (tail -f) -Encoding UTF8, ASCII, Unicode -Raw read as single string -Stream read alternate data streams |
| Set-Content | Teksts | modern | PowerShell - write or replace file content with given string | -Path target file -Value content to write -Encoding UTF8, ASCII, UTF8BOM -Force overwrite read-only -NoNewline do not append CRLF |
| ConvertFrom-Json / ConvertTo-Json | Teksts | modern | PowerShell - parse JSON into objects and back to text | ConvertFrom-Json string → object -Depth N nesting depth (default 2) ConvertTo-Json object → string -Compress no whitespace -AsHashtable parse into hashtable |
| doskey | Teksts | core | Recall and edit command history; define command macros (cmd.exe) | /history print command history /listsize=N history buffer size name=command define macro alias /macros list all macros /macrofile=file load macros from file |
| clip | Teksts | core | Pipe stdout into the Windows clipboard | echo hello | clip copy text to clipboard dir | clip capture command output type file | clip copy file contents |
| tasklist | Procesi | core | Display all running processes with PID and memory | /v verbose (user, status) /svc show services in each process /fi apply filter (e.g. "imagename eq chrome.exe") /fo output format (table, csv, list) /m show DLLs loaded by process |
| taskkill | Procesi | core | Terminate a running process by PID or name | /pid N terminate by process ID /im name.exe terminate by image name /f force terminate (no graceful close) /t also terminate child processes /fi apply filter (e.g. "status eq not responding") |
| start | Procesi | core | Start a separate window to run a program or command | /b start without new window /wait wait for program to exit /min / /max start minimized/maximized /d path starting directory /affinity N CPU affinity mask start "" notepad empty title required |
| Get-Process | Procesi | modern | PowerShell - retrieve process objects with rich properties | -Name filter by name pattern -Id N filter by PID -IncludeUserName show owner (admin) -Module show loaded modules -FileVersionInfo show exe version | Sort-Object CPU -Desc top by CPU |
| Stop-Process | Procesi | modern | PowerShell - terminate one or more processes | -Id N terminate by PID -Name name terminate by name -Force skip confirmation -PassThru emit terminated object -Confirm prompt before kill |
| Start-Process | Procesi | modern | PowerShell - launch program with detailed control | -FilePath executable to run -ArgumentList command-line arguments -Verb RunAs elevated (UAC prompt) -WindowStyle Hidden/Minimized/Maximized -Wait block until exit -RedirectStandardOutput capture stdout |
| Wait-Process | Procesi | modern | PowerShell - block until one or more processes exit | -Name wait for processes by name -Id N wait for PID -Timeout N give up after N seconds -ErrorAction SilentlyContinue ignore missing |
| Get-Service | Procesi | modern | PowerShell - list and inspect Windows services | -Name filter by service short name -DisplayName filter by display name -Status Running, Stopped, Paused -Include / -Exclude pattern filter -RequiredServices show dependencies |
| Procmon (Sysinternals) | Procesi | modern | Real-time file, registry, network, and process activity monitor | /AcceptEula skip EULA prompt /Quiet start tracing immediately /BackingFile log to file /LoadConfig load filter set /Terminate stop running instance |
| shutdown | Procesi | core | Shut down, restart, or log off the local or remote computer | /s shut down /r restart /l log off /g shutdown + restart apps /t N delay in seconds /m \\host target remote host /c "msg" comment shown to users /f force close apps /a abort pending shutdown |
| logoff | Procesi | core | End a user session (local or terminal services) | sessionid log off specific session /server:name target server /v verbose note: combine with quser to find session ID |
| Restart-Computer | Procesi | modern | PowerShell - reboot one or more computers (local or remote) | -ComputerName host1,host2 -Force force shutdown despite locked sessions -Credential alternate credentials -Wait -For PowerShell wait until WinRM up -Delay N retry interval -Protocol DCOM/WSMan |
| Stop-Computer | Procesi | modern | PowerShell - power off one or more computers | -ComputerName host -Force force shutdown -Credential alternate credentials -WsmanAuthentication Default/Basic/Kerberos |
| Invoke-Command | Procesi | modern | PowerShell remoting - run commands on one or many remote hosts | -ComputerName host1,host2 -ScriptBlock { } -FilePath script.ps1 run local script remotely -Credential alternate credentials -AsJob run as background job -ThrottleLimit N max concurrent |
| Enter-PSSession | Procesi | modern | PowerShell remoting - open interactive remote session | -ComputerName host -Credential alternate credentials -Authentication Kerberos/CredSSP -ConfigurationName name -UseSSL WinRM over HTTPS Exit-PSSession leave session |
| sc | Sistēma | core | Control and query the Windows Service Control Manager | query list services and status queryex include PID and flags start / stop control service config change start type or path create name binPath= create new service delete remove service |
| systeminfo | Sistēma | core | Display detailed configuration of the local system | /s host query remote computer /u user authenticate as user /fo output format (table, csv, list) /nh suppress headers (csv/table) |
| ver | Sistēma | core | Display the Windows version string | ver prints OS version |
| hostname | Sistēma | core | Print the computer NetBIOS hostname | hostname prints current hostname |
| set | Sistēma | core | Display, set, or remove environment variables | set VAR=value set in current session set VAR= remove from session set list all variables set /p VAR=Prompt: read from user input set /a VAR=2*3 arithmetic evaluation |
| setx | Sistēma | core | Persistently set environment variables (user or machine) | setx VAR value set for current user /m set system-wide (admin) /s host set on remote computer /k regkey read from registry note: new value not visible in current shell |
| wmic | Sistēma | core | Windows Management Instrumentation command-line (legacy) | os get caption,version cpu get name,numberofcores logicaldisk get size,freespace,caption process where name='chrome.exe' get processid computersystem get manufacturer,model note: WMIC is deprecated and not installed by default since Windows 11 24H2 - use Get-CimInstance |
| Get-CimInstance | Sistēma | modern | PowerShell - query WMI/CIM objects (WMIC replacement) | -ClassName WMI class (Win32_*) -Filter WQL filter clause -Property return only listed properties -ComputerName query remote system -Namespace alternate CIM namespace |
| Get-ComputerInfo | Sistēma | modern | PowerShell - retrieve consolidated system information object | -Property * show all properties Os* filter to OS-related properties Bios* BIOS/firmware info Cs* computer system info |
| Set-Service | Sistēma | modern | PowerShell - configure a Windows service | -Name service to modify -Status Running/Stopped -StartupType Automatic/Manual/Disabled -Description set service description -DisplayName set display name |
| schtasks | Sistēma | core | Schedule, run, query, or delete tasks (Task Scheduler CLI) | /create define new scheduled task /run trigger immediately /end stop running task /query list all tasks /delete remove task /sc schedule type (DAILY, ONLOGON, ONSTART) /tn task name /tr command to run |
| git | Sistēma | modern | Distributed version control - track and collaborate on code | status show working tree state log --oneline --graph compact history diff HEAD changes since last commit stash push/pop shelve and restore changes rebase -i interactive squash/reorder bisect start/good/bad find bug commit blame show line-by-line authorship |
| winget | Sistēma | modern | Windows Package Manager - install, upgrade, remove apps | search name find package install id install package upgrade --all update all packages list show installed packages uninstall id remove package source add add repository export / import reproduce setup |
| choco | Sistēma | modern | Chocolatey - community Windows package manager | install pkg -y install silently upgrade all -y update all packages list --local-only installed packages uninstall pkg -y remove package pin add -n=pkg freeze version feature enable -n enable feature |
| gpupdate | Sistēma | core | Refresh Group Policy settings on the local computer | /force reapply all settings /target:user|computer scope /wait:N seconds to wait /logoff log off if needed by policies /boot reboot if needed by policies /sync synchronous foreground refresh |
| reg | Sistēma | core | Read, write, import, export, and compare Windows Registry entries | query KEY /s recursive list query KEY /v VALUE add KEY /v name /t REG_SZ /d val delete KEY /v name /f export KEY file.reg import file.reg save KEY file.hiv raw hive load HKLM\Tmp file.hiv |
| regedit | Sistēma | core | Registry Editor - GUI for browsing and modifying the registry | regedit open GUI regedit /s file.reg silently apply .reg /e file.reg HKLM\path export branch note: prefer 'reg' for scripting |
| msiexec | Sistēma | core | Install, uninstall, or repair MSI/MSP packages | /i pkg.msi install /x pkg.msi uninstall /qn silent (no UI) /qb basic UI /norestart do not auto-reboot /l*v log.txt verbose logging ALLUSERS=1 machine-wide TRANSFORMS= apply .mst |
| sfc | Sistēma | core | System File Checker - scan and repair protected OS files | /scannow scan and repair all system files /verifyonly scan without repair /scanfile=path check single file /offbootdir / /offwindir offline image scan note: run from elevated shell |
| dism | Sistēma | core | Deployment Image Servicing and Management - online and image servicing | /Online target running OS /Image:path target offline WIM /Cleanup-Image /RestoreHealth repair /Get-Features list features /Enable-Feature /FeatureName:name /Get-Packages list installed updates /Add-Driver /Driver:path /Export-Image export WIM |
| bcdedit | Sistēma | core | Boot Configuration Data store editor - boot loader configuration | /enum list boot entries /default {GUID} set default OS /timeout N set menu timeout /set {GUID} description "name" /copy {GUID} /d "copy" /export file back up BCD /import file restore BCD note: requires admin |
| driverquery | Sistēma | core | List installed device drivers and their properties | /v verbose /si signed driver info /fo output format (table, list, csv) /nh suppress headers /s host /u user remote query |
| pnputil | Sistēma | core | Manage driver packages in the driver store | /enum-drivers list staged drivers /add-driver inf add and install /delete-driver oem##.inf /uninstall /scan-devices rescan for new devices /disable-device / /enable-device /restart-device |
| powercfg | Sistēma | core | Query and configure power plans, sleep, hibernation, battery | /list list power schemes /setactive GUID switch scheme /h on|off hibernate toggle /lastwake show last wake source /devicequery wake_armed who can wake /batteryreport HTML battery report /energy power efficiency audit /requests active power requests |
| net share / net use | Sistēma | core | Manage SMB shares and mapped network drives | net share list local shares net share name=C:\path create share /grant:user,read|change|full net use Z: \\srv\share map drive net use Z: /delete remove mapping /user:DOM\u pass alternate creds /persistent:yes|no persist |
| net start / net stop | Sistēma | core | Start or stop a Windows service by name | net start list running services net start name start service net stop name stop service note: use sc for advanced control |
| Restart-Service / Start-Service / Stop-Service | Sistēma | modern | PowerShell - lifecycle control for Windows services | -Name service short name -Force override dependencies -PassThru emit resulting object -Confirm prompt before action -WhatIf dry-run preview |
| Get-HotFix | Sistēma | modern | PowerShell - list installed Windows updates (KB articles) | -Id KB###### -ComputerName host remote -Description Hotfix/Update/Security | Sort-Object InstalledOn by date |
| Get-ItemProperty | Sistēma | modern | PowerShell - read property values (e.g. registry values) | -Path HKLM:\Software\name -Name value Set-ItemProperty write value New-ItemProperty create value Remove-ItemProperty delete value |
| Get-WindowsFeature / Install-WindowsFeature | Sistēma | modern | PowerShell - Server Manager - manage roles and features (Windows Server) | Get-WindowsFeature list all features -Name Web-Server filter Install-WindowsFeature -Name name -IncludeManagementTools -IncludeAllSubFeature -Restart reboot if needed Uninstall-WindowsFeature remove |
| icacls | Tiesības | core | Display, modify, and back up NTFS access control lists (ACLs) | /grant user:perm grant permission (F, M, RX, R, W) /deny user:perm explicit deny /remove user remove all ACEs for user /t recurse into subdirectories /c continue on errors /inheritance:e/d/r enable/disable/reset /save file back up ACLs /restore file restore ACLs |
| takeown | Tiesības | core | Take ownership of a file or folder (typically as admin) | /f file target file or directory /r recursive /d Y/N default answer for prompt /a give ownership to Administrators group /skipsl skip symlinks |
| runas | Tiesības | core | Run a program under a different user account | /user:DOMAIN\user specify user /profile load user profile /savecred save credentials in Vault /netonly remote-only credentials /noprofile no profile (faster) |
| net user | Tiesības | core | Manage local user accounts (create, modify, delete, list) | net user list all local accounts net user name show details net user name pass /add create user /delete remove user /active:yes|no enable/disable /passwordchg:yes|no allow password change |
| net localgroup | Tiesības | core | Manage local groups and their members | net localgroup list groups net localgroup Administrators list members Administrators user /add add to group /delete remove from group group /add create new group |
| whoami | Tiesības | core | Display current user, SID, groups, and privileges | /user show username and SID /groups group memberships /priv enabled privileges /all show everything /fo output format (table, csv, list) /upn show UPN form /login show logon ID |
| cipher | Tiesības | core | Manage EFS encryption and securely wipe free disk space | /e encrypt files /d decrypt files /s:dir recurse directory /w:dir wipe deleted data on volume /k create new EFS key for user /u update encrypted files with new key |
| Get-Acl / Set-Acl | Tiesības | modern | PowerShell - read or write security descriptor of files, folders, registry | Get-Acl path retrieve ACL object Set-Acl path -AclObject apply ACL -Audit also include audit ACEs | Format-List inspect entries $acl.SetAccessRule() add ACE programmatically |
| net user /domain | Tiesības | core | Query and manage domain user accounts (joined to AD) | net user name /domain show user info /domain query domain controller /add /domain create domain account (admin) note: requires AD-joined machine |
| gpresult | Tiesības | core | Display applied Group Policy (RSoP) for user and computer | /r summary report /v verbose /z super-verbose /h file.html HTML report /scope user|computer limit scope /user name another user's policy |
| auditpol | Tiesības | modern | View and configure Windows audit policy categories | /get /category:* show current policy /set /subcategory:"Logon" /success:enable /list /subcategory:* list all subcategories /backup /file:audit.csv export policy /restore /file:audit.csv import policy /clear clear audit policy |
| Get-LocalUser / New-LocalUser | Tiesības | modern | PowerShell - manage local user accounts (modern net user replacement) | Get-LocalUser list local accounts -Name name filter New-LocalUser -Name -Password (Read-Host -AsSecure) Set-LocalUser modify account Remove-LocalUser delete account Enable-LocalUser / Disable-LocalUser Add-LocalGroupMember -Group Administrators -Member name |
| Get-ADUser (RSAT) | Tiesības | modern | PowerShell - query Active Directory user objects (requires RSAT) | -Identity sam by SAMAccountName -Filter 'Enabled -eq $true' -SearchBase 'OU=Sales,DC=…' -Properties * return all attributes -Server dc.example target DC Set-ADUser modify attributes Unlock-ADAccount unlock locked account |
| Add-ADGroupMember (RSAT) | Tiesības | modern | PowerShell - manage Active Directory group membership | -Identity GroupName -Members user1,user2 Remove-ADGroupMember remove member Get-ADGroupMember list members -Recursive flatten nested groups Get-ADGroup -Filter * enumerate groups |
| klist | Tiesības | core | View and purge Kerberos tickets (TGT and service tickets) | klist list current tickets tickets service tickets tgt Ticket Granting Ticket purge delete all tickets purge_bind purge bindings cache sessions list logon sessions -li 0x3e7 computer session |
| ipconfig | Tīkls | core | Display TCP/IP configuration for all network adapters | /all show full info incl. MAC, DNS, DHCP /release [adapter] release DHCP lease /renew [adapter] request new DHCP lease /flushdns clear DNS resolver cache /displaydns show cached DNS entries /registerdns re-register with DNS |
| netstat | Tīkls | core | Display TCP/UDP connections, listening ports, and statistics | -a all connections and listening -n numeric addresses (no DNS) -o show PID owning connection -b show executable name (admin) -r routing table -s protocol statistics -p tcp|udp protocol filter |
| ping | Tīkls | core | Test host reachability using ICMP echo | -n N number of echo requests -l N payload size in bytes -t ping continuously -i N set IP TTL -w ms timeout per reply -4 / -6 force IPv4 or IPv6 |
| tracert | Tīkls | core | Trace the network path packets take to a host | -d do not resolve hostnames -h N max hops -w ms timeout per probe -4 / -6 force IPv4 or IPv6 tracert host default trace |
| pathping | Tīkls | core | Combine traceroute with per-hop packet loss statistics | -n no name resolution -h N max hops -q N queries per hop -w ms timeout per reply -p ms wait between pings -4 / -6 force protocol |
| nslookup | Tīkls | core | Interactive and non-interactive DNS lookup | nslookup host basic lookup nslookup host server use specific resolver set type=MX change query type set type=ANY request any record -debug show full response |
| route | Tīkls | core | Display and modify the IP routing table | print show routing table add dest mask gw add static route delete dest remove route change dest modify route -p make route persistent -4 / -6 IPv4 or IPv6 table |
| arp | Tīkls | core | Display and modify the ARP cache (IP↔MAC mappings) | -a show ARP table -d ip delete entry -s ip mac add static entry -N iface filter by interface |
| netsh | Tīkls | core | Configure network interfaces, firewall, WLAN, and more | interface ip show config view IP settings wlan show profiles list saved Wi-Fi wlan show profile name key=clear reveal password advfirewall set allprofiles state on int tcp show global TCP tuning winsock reset reset Winsock catalog |
| Test-NetConnection | Tīkls | modern | PowerShell - port reachability, traceroute, ping diagnostics | -ComputerName host target -Port N test specific TCP port -TraceRoute show route hops -CommonTCPPort HTTP/HTTPS/RDP -InformationLevel Detailed full output tnc host -p 443 shorthand |
| Get-NetIPAddress | Tīkls | modern | PowerShell - retrieve IP address configuration objects | -InterfaceAlias name filter by adapter -AddressFamily IPv4 / IPv6 -PrefixOrigin Dhcp/Manual -SkipAsSource filter source preference | Format-Table tabular view |
| ssh (OpenSSH) | Tīkls | modern | Secure Shell client - remote login, exec, port forwarding | -i identity (private key) file -p N remote port -L local port forwarding -R remote port forwarding -J jump through bastion host -N do not execute remote command -v verbose debug output |
| Resolve-DnsName | Tīkls | modern | PowerShell - query DNS records with full record-type support | -Type A/AAAA/MX/TXT/ANY -Server ip use specific resolver -DnsOnly skip Hosts file -NoHostsFile ignore static hosts -LlmnrFallback also try LLMNR |
| nbtstat | Tīkls | core | Display NetBIOS over TCP/IP statistics and name cache | -a host remote name table by name -A ip remote name table by IP -n local name table -c NetBIOS name cache -r resolved names -R purge and reload from LMHOSTS -S sessions table |
| nltest | Tīkls | core | Test and configure NETLOGON, domain trusts, and DC discovery | /dsgetdc:DOMAIN locate DC for domain /sc_query:DOMAIN query secure channel /sc_reset:DOMAIN reset secure channel /domain_trusts list trust relationships /dclist:DOMAIN list DCs in domain /parentdomain show parent domain |
| netsh advfirewall | Tīkls | core | Configure Windows Defender Firewall - rules, profiles, logging | set allprofiles state on firewall add rule name=R protocol=TCP dir=in localport=8080 action=allow firewall show rule name=all firewall delete rule name=R monitor show consec active connections set logging filename file.log reset restore default policy |
| New-NetFirewallRule | Tīkls | modern | PowerShell - create Windows Firewall rules (netsh advfirewall replacement) | -DisplayName name -Direction Inbound/Outbound -Action Allow/Block -Protocol TCP/UDP/ICMPv4 -LocalPort N -RemoteAddress ip/subnet -Profile Domain/Private/Public Get-NetFirewallRule / Remove-NetFirewallRule |
| curl | Pārsūtīšana | core | Transfer data over HTTP, HTTPS, FTP, and many other protocols | -o write output to file -X HTTP method (GET POST PUT…) -H add request header -d POST body data -L follow redirects -k skip TLS verification --retry N retry on transient failure -u user:pass basic auth --form multipart/form-data -s silent (no progress) |
| Invoke-WebRequest | Pārsūtīšana | modern | PowerShell - HTTP client returning parsed response object | -Uri target URL -Method GET/POST/PUT/DELETE -Headers @{} request headers -Body request body -OutFile save response to file -UseBasicParsing no IE engine -SkipCertificateCheck ignore TLS errors -Credential pass PSCredential |
| Invoke-RestMethod | Pārsūtīšana | modern | PowerShell - HTTP client for REST APIs (parses JSON/XML) | -Uri endpoint -Method HTTP verb -Headers request headers -Body body (auto-serializes JSON if hashtable) -ContentType set content-type -Authentication Bearer -Token modern auth | ConvertTo-Json inspect result |
| bitsadmin | Pārsūtīšana | core | Background Intelligent Transfer Service - resumable downloads (legacy) | /transfer name url file download URL to file /list show active jobs /cancel jobid abort job /info jobid /verbose job state note: deprecated in favor of Start-BitsTransfer |
| Start-BitsTransfer | Pārsūtīšana | modern | PowerShell - resumable background HTTP/HTTPS/SMB transfer | -Source url source URL -Destination path target file -Asynchronous non-blocking job -Priority Foreground/High/Normal/Low -Authentication Basic/NTLM/Negotiate -RetryInterval N seconds between retries |
| scp (OpenSSH) | Pārsūtīšana | core | Securely copy files between hosts over SSH | -r recursive copy of directories -P N specify remote port -i identity (private key) file -p preserve timestamps and modes -v verbose debug output |
| sftp (OpenSSH) | Pārsūtīšana | core | Interactive secure file transfer over SSH | -P N specify port -i identity file get / put download / upload file ls / lls list remote / local files mget / mput batch transfer |
| perfmon | Monitorings | core | Performance Monitor - real-time and recorded counters (GUI/CLI) | perfmon open Performance Monitor perfmon /res open Resource Monitor perfmon /rel open Reliability Monitor perfmon /report generate System Diagnostic report |
| typeperf | Monitorings | core | Sample performance counters and write to stdout or CSV | "\Processor(_Total)\% Processor Time" -sc N sample count -si N sample interval (seconds) -f csv/tsv/bin output format -o file write to file -cf file read counter list from file -q list all counters |
| Get-Counter | Monitorings | modern | PowerShell - sample performance counters with rich objects | -Counter "\path" counter path -SampleInterval N seconds between samples -MaxSamples N number of samples -Continuous sample until Ctrl+C -ComputerName remote host -ListSet * enumerate counter sets |
| Get-EventLog | Monitorings | modern | PowerShell - read classic Windows event logs (legacy API) | -LogName Application/System/Security -Newest N most recent N entries -EntryType Error/Warning/Information -Source name filter by source -After / -Before time range note: superseded by Get-WinEvent |
| Get-WinEvent | Monitorings | modern | PowerShell - read modern (ETW) Windows event logs with XPath/XML filters | -LogName Microsoft-Windows-* / Security -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents N cap output -Oldest oldest first -FilterXPath XPath query -ListLog * enumerate logs |
| wevtutil | Monitorings | core | Windows Event Log command-line utility | el enumerate log names qe Security /c:10 /rd:true /f:text query cl Security clear log gli Security log info epl Security file.evtx export log sl LogName /e:true|false enable/disable |
| resmon | Monitorings | core | Resource Monitor - GUI for CPU, memory, disk, network in real time | resmon launch GUI note: drill down per-process I/O and network connections |
| Get-NetTCPConnection | Monitorings | modern | PowerShell - list active TCP connections (modern netstat) | -State Listen/Established -LocalPort N filter by local port -RemoteAddress ip filter by remote IP -OwningProcess PID filter by process | Join with Get-Process Id |
| Sysmon (Sysinternals) | Monitorings | modern | System Monitor - rich endpoint telemetry into Event Log | -i config.xml install with config -c config.xml update running config -u force uninstall -h sha256,imphash set hash algorithms -n log network connections note: events appear in Microsoft-Windows-Sysmon/Operational |
| quser / query user | Monitorings | core | Display interactive and RDP user sessions on local or remote host | quser list sessions on local quser /server:host remote host note: shows session ID, state, idle time, logon time |
| qwinsta / rwinsta | Monitorings | core | Query and reset terminal services (RDP) sessions | qwinsta list sessions qwinsta /server:host rwinsta sessionid reset session rwinsta /server:host id note: equivalent to 'query session' / 'reset session' |
| diskpart | Diski | core | Manage disks, partitions, and volumes (scriptable disk utility) | list disk / partition / volume select disk N clean wipe partition table create partition primary format fs=ntfs quick assign letter=X extend / shrink desired=N note: requires admin shell |
| chkdsk | Diski | core | Check disk for filesystem errors and bad sectors | /f fix filesystem errors /r also locate bad sectors /x force dismount before scan /scan online scan (NTFS) /spotfix targeted fix on next boot /b re-evaluate bad clusters (with /r) |
| fsutil | Diski | core | Filesystem utility for advanced NTFS, USN, links, and quotas | fsinfo drives list drives volume diskfree C: free/total bytes behavior set tune NTFS behavior usn USN journal management hardlink create create hard link file createnew name N create N-byte file |
| format | Diski | core | Format a disk volume with a filesystem | /fs:NTFS|FAT32|exFAT filesystem type /q quick format /v:label set volume label /a:size allocation unit size /l large FRS (NTFS) /p:N pass count for zero-fill |
| mountvol | Diski | core | Mount or unmount a volume at a drive letter or NTFS folder | mountvol list mounted volumes mountvol X: \\?\Volume{GUID}\ mount mountvol X: /d unmount drive /r remove orphaned points /n / /e disable/enable auto-mount |
| Get-Disk | Diski | modern | PowerShell - retrieve physical disk objects and health | -Number N filter by disk number -FriendlyName name | Initialize-Disk -PartitionStyle GPT | Set-Disk -IsOffline $false HealthStatus disk health summary |
| Get-Volume | Diski | modern | PowerShell - retrieve volumes with size, filesystem, health | -DriveLetter C -FileSystem NTFS/ReFS/FAT32 -FileSystemLabel name | Repair-Volume -OfflineScanAndFix | Optimize-Volume -Defrag |
| New-Partition / Format-Volume | Diski | modern | PowerShell - create partitions and format volumes | New-Partition -DiskNumber N -UseMaximumSize -DriveLetter X assign letter -AssignDriveLetter auto-assign Format-Volume -FileSystem NTFS -NewFileSystemLabel label -Confirm:$false no prompt |
| defrag | Diski | core | Analyze and defragment volumes | C: defragment drive /a analyze only /o optimize (defrag + slab consolidate) /l retrim SSD /x free-space consolidation /v verbose output |
| convert | Diski | core | Convert FAT/FAT32 volume to NTFS in-place | C: /fs:ntfs basic conversion /v verbose /cvtarea:file reserve MFT space /nosecurity no security descriptors /x force dismount first note: one-way; cannot revert to FAT |
| vssadmin | Diski | core | Manage Volume Shadow Copies and storage providers | list shadows show all snapshots list shadowstorage storage allocation create shadow /for=C: delete shadows /for=C: /oldest resize shadowstorage /on=C: /maxsize=10GB list writers list VSS writers |
| Get-PhysicalDisk | Diski | modern | PowerShell - retrieve physical disk objects (Storage Spaces era) | -FriendlyName name -MediaType SSD/HDD/SCM -HealthStatus Healthy/Warning | Get-StoragePool associated pool Reset-PhysicalDisk bring back online |
| tar | core | Built-in BSD tar - create/extract archives (.tar, .tar.gz, .zip) | -c create archive -x extract archive -f file archive filename -z gzip filter -v verbose listing -t list contents without extracting --strip-components N strip path levels note: built into Windows 10 1803+ |
|
| compact | core | View and change NTFS file compression | /c compress files /u uncompress files /s recurse subdirectories /a display hidden/system files /i ignore errors /exe:LZX|XPRESS algorithm choice |
|
| expand | core | Expand compressed CAB/MSU/cabinet archives | -r rename expanded files -i ignore directory structure -f:* files to expand (wildcards) -d display contents only source dest basic expansion |
|
| Compress-Archive | modern | PowerShell - create or append to .zip archives | -Path files/dirs to include -DestinationPath file.zip -Update add/update entries -Force overwrite existing zip -CompressionLevel Fastest/Optimal/NoCompression |
|
| Expand-Archive | modern | PowerShell - extract .zip archive contents | -Path file.zip -DestinationPath dir -Force overwrite existing files -PassThru emit extracted items |
|
| 7z (7-Zip CLI) | modern | 7-Zip - high-ratio compression with 7z, zip, tar, gz support | a archive.7z files add to archive x archive.7z extract preserving paths e archive.7z extract flat l archive.7z list contents t archive.7z test integrity -p set password -mx=9 max compression -mhe=on encrypt headers |
|
| nmap | Ielaušanās tests | security | Network scanner - host discovery, port scan, service detection | -sV detect service versions -sC run default NSE scripts -O enable OS fingerprinting -p specify port range (e.g. 1-65535) -A aggressive: OS+version+scripts+traceroute --script run specific NSE script -oN / -oX output to file -Pn skip host discovery (assume up) -sS SYN stealth scan (admin) |
| certutil | Ielaušanās tests | security | Certificate Services tool - inspect certs, hash files, base64 encode | -hashfile file SHA256 hash a file -encode in out base64 encode -decode in out base64 decode -store -enterprise Root list Root certs -verify -urlfetch cert.cer -dump inspect certificate note: also used by attackers as LOLBin |
| openssl | Ielaušanās tests | security | TLS/SSL toolkit - certificates, keys, encryption, and testing | s_client -connect host:443 test TLS x509 -in cert.pem -text inspect cert genrsa -out key.pem 4096 generate RSA key req -new generate CSR enc -aes-256-cbc encrypt/decrypt verify -CAfile validate chain speed benchmark ciphers |
| ssh-keygen | Ielaušanās tests | security | Generate, manage, and convert SSH authentication keys | -t ed25519 modern key type (recommended) -b 4096 bit length (for RSA) -C 'comment' add identifying comment -f file output file path -p change or remove passphrase -l print key fingerprint |
| gpg | Ielaušanās tests | security | GNU Privacy Guard for Windows - encrypt, sign, verify | --gen-key generate key pair -e -r recipient encrypt file --decrypt decrypt .gpg file -s create detached signature --verify verify signature file --armor ASCII-armored output --export / --import key management |
| PsExec (Sysinternals) | Ielaušanās tests | security | Execute processes on remote systems with full I/O redirection | \\host -u user -p pass cmd -s run as SYSTEM -i interactive (show GUI) -d do not wait for process -c copy local exe to remote -h elevated token note: often used in attack chains - monitor |
| mimikatz | Ielaušanās tests | security | Windows credential extraction toolkit (RED TEAM / LAB ONLY) | privilege::debug acquire SeDebug sekurlsa::logonpasswords dump LSASS creds lsadump::sam dump local SAM kerberos::list list tickets note: blocked by Defender; LAB USE ONLY legal: use only on systems you own/authorize |
| hashcat | Ielaušanās tests | security | GPU-accelerated password hash cracking tool | -m hash type (1000=NTLM, 13100=Kerberos TGS) -a attack mode (0=dict, 3=bruteforce) -w workload profile (1–4) -r rules apply rules file --show show already cracked hashes --status live progress update |
| john (JtR) | Ielaušanās tests | security | CPU-based password hash cracker with auto-detection | --wordlist dictionary file path --rules apply mangling rules --format=ntlm specify hash type --show display cracked passwords --fork N parallel processes note: Cygwin or native Win64 build |
| Defender (Set-MpPreference) | Ielaušanās tests | security | PowerShell - configure Microsoft Defender Antivirus | Get-MpPreference show current settings Set-MpPreference -DisableRealtimeMonitoring Add-MpPreference -ExclusionPath path Start-MpScan -ScanType QuickScan/FullScan Update-MpSignature update definitions Get-MpThreatDetection recent detections |
| docker | Konteineri | modern | Build, ship, and run application containers (Docker Desktop) | run -d run container detached run --rm auto-remove on exit exec -it open shell in running container logs -f follow container log stream inspect detailed JSON metadata ps -a list all containers build -t build image with tag network ls / inspect manage networks volume ls / inspect manage volumes system prune remove unused resources |
| kubectl | Konteineri | modern | CLI to manage Kubernetes clusters and workloads | get pods/svc/nodes list resources describe pod name detailed event log apply -f manifest.yaml deploy/update exec -it pod -- powershell shell into pod logs -f pod follow log stream top node / top pod resource usage rollout status/undo deployment control port-forward forward local port to pod config use-context switch cluster |
| podman | Konteineri | modern | Rootless daemonless OCI engine - Windows port via WSL | run --rm auto-remove after exit --user 1000 run as non-root UID --pod attach to pod group -v bind mount host volume generate kube export as Kubernetes YAML play kube run from Kubernetes YAML |
| helm | Konteineri | modern | Kubernetes package manager for templated chart deployments | install release chart deploy chart upgrade --install upsert deploy rollback release N revert to revision list show all deployed releases values chart show default values repo add / update manage chart repos template render manifests locally |
| wsl | Konteineri | modern | Windows Subsystem for Linux - run Linux distros and containers | --list --verbose show distros and state --install -d Ubuntu install distro --set-default name --set-version name 2 switch to WSL2 --shutdown stop all distros --export / --import backup/restore note: required for Docker Desktop on Windows |