PowerShell Troubleshooting Commands

A copy-and-paste reference of ~50 PowerShell and az CLI commands for day-to-day Tier 1-3 troubleshooting. Each card shows the command, what it does, and the expected output - so you know success when you see it. Free for every learner heading toward Sysadmin, Identity, Cloud, or SecOps.

Test SMB port to a domain controller

Resolves DNS, ICMP-pings, and TCP-tests port 445 on the DC. A single go-to for 'is the corp file share up?'.

Test-NetConnection -ComputerName dc01.contoso.com -Port 445

Expected output

ComputerName     : dc01.contoso.com
RemoteAddress    : 10.0.0.10
RemotePort       : 445
InterfaceAlias   : Ethernet
SourceAddress    : 192.168.1.50
PingSucceeded    : True
PingReplyDetails (RTT) : 6 ms
TcpTestSucceeded : True

Show IP, DNS, gateway for an interface

Returns the IPv4 address, default gateway, and DNS servers for the named NIC.

Get-NetIPConfiguration -InterfaceAlias Ethernet

Expected output

InterfaceAlias       : Ethernet
IPv4Address          : 192.168.1.50
IPv4DefaultGateway   : 192.168.1.1
DNSServer            : 10.0.0.53, 10.0.0.54
NetProfile           : contoso.com

List all active (Up) network adapters

Lists interface name, status, link speed, and MAC for live NICs only - skips disconnected ones.

Get-NetAdapter | Where-Object Status -eq 'Up'

Expected output

Name              InterfaceDescription          LinkSpeed
----              --------------------          ---------
Ethernet          Intel(R) I219-LM              1 Gbps
Wi-Fi             Intel(R) Wi-Fi 6 AX200        866 Mbps
VPN01             Contoso VPN Adapter           100 Mbps

Resolve a name against a specific DNS server

Forces the lookup against the named resolver; bypasses the workstation suffix and NRPT.

Resolve-DnsName -Name contoso.com -Server 10.0.0.53

Expected output

Name              Type  TTL   Section   NameHost
----              ----  ---   -------   --------
contoso.com       A     3600  Answer    10.0.0.5
contoso.com       NS    3600  Authority ns1.contoso.com
contoso.com       SOA   3600  Authority ns1.contoso.com

Inspect the default route (where am I sending 0.0.0.0/0?)

Returns the active NextHop gateway and the route metric. Lower metric = preferred.

Get-NetRoute -DestinationPrefix 0.0.0.0/0 | Select-Object DestinationPrefix, NextHop, RouteMetric

Expected output

DestinationPrefix NextHop      RouteMetric ifMetric
----------------- -------      ----------  --------
0.0.0.0/0         192.168.1.1         25       25
0.0.0.0/0         10.0.50.1           50      100

Flush the workstation DNS cache

Clears the local resolver cache; forces subsequent lookups back to the resolver.

ipconfig /flushdns

Expected output

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

Detailed ICMP and routing test to 8.8.8.8

Useful before opening an external-DNS ticket - shows source interface, RTT, result.

Test-NetConnection -ComputerName 8.8.8.8 -InformationLevel Detailed

Expected output

ComputerName     : 8.8.8.8
RemoteAddress    : 8.8.8.8
InterfaceAlias   : Ethernet
SourceAddress    : 192.168.1.50
PingSucceeded    : True
PingReplyDetails (RTT) : 12 ms

List established TCP connections (excluding loopback)

Spot-check outbound connections. Useful when investigating suspected malware beacons.

Get-NetTCPConnection -State Established | Where-Object RemoteAddress -ne '127.0.0.1' | Select-Object LocalAddress, LocalPort, RemoteAddress, RemotePort

Expected output

LocalAddress  LocalPort  RemoteAddress  RemotePort
------------  --------   -------------  ----------
192.168.1.50  49172      10.0.0.10      445
192.168.1.50  49180      142.250.0.5    443
192.168.1.50  49200      20.190.132.4  443