
PowerShell Troubleshooting Commands
A copy-and-paste reference of ~50 PowerShell and az CLI commands for day-to-day Tier 1-3 troubleshooting. Each card shows the command, what it does, and the expected output - so you know success when you see it. Free for every learner heading toward Sysadmin, Identity, Cloud, or SecOps.
Test SMB port to a domain controller
Resolves DNS, ICMP-pings, and TCP-tests port 445 on the DC. A single go-to for 'is the corp file share up?'.
Test-NetConnection -ComputerName dc01.contoso.com -Port 445Expected output
ComputerName : dc01.contoso.com RemoteAddress : 10.0.0.10 RemotePort : 445 InterfaceAlias : Ethernet SourceAddress : 192.168.1.50 PingSucceeded : True PingReplyDetails (RTT) : 6 ms TcpTestSucceeded : True
Show IP, DNS, gateway for an interface
Returns the IPv4 address, default gateway, and DNS servers for the named NIC.
Get-NetIPConfiguration -InterfaceAlias EthernetExpected output
InterfaceAlias : Ethernet IPv4Address : 192.168.1.50 IPv4DefaultGateway : 192.168.1.1 DNSServer : 10.0.0.53, 10.0.0.54 NetProfile : contoso.com
List all active (Up) network adapters
Lists interface name, status, link speed, and MAC for live NICs only - skips disconnected ones.
Get-NetAdapter | Where-Object Status -eq 'Up'Expected output
Name InterfaceDescription LinkSpeed ---- -------------------- --------- Ethernet Intel(R) I219-LM 1 Gbps Wi-Fi Intel(R) Wi-Fi 6 AX200 866 Mbps VPN01 Contoso VPN Adapter 100 Mbps
Resolve a name against a specific DNS server
Forces the lookup against the named resolver; bypasses the workstation suffix and NRPT.
Resolve-DnsName -Name contoso.com -Server 10.0.0.53Expected output
Name Type TTL Section NameHost ---- ---- --- ------- -------- contoso.com A 3600 Answer 10.0.0.5 contoso.com NS 3600 Authority ns1.contoso.com contoso.com SOA 3600 Authority ns1.contoso.com
Inspect the default route (where am I sending 0.0.0.0/0?)
Returns the active NextHop gateway and the route metric. Lower metric = preferred.
Get-NetRoute -DestinationPrefix 0.0.0.0/0 | Select-Object DestinationPrefix, NextHop, RouteMetricExpected output
DestinationPrefix NextHop RouteMetric ifMetric ----------------- ------- ---------- -------- 0.0.0.0/0 192.168.1.1 25 25 0.0.0.0/0 10.0.50.1 50 100
Flush the workstation DNS cache
Clears the local resolver cache; forces subsequent lookups back to the resolver.
ipconfig /flushdnsExpected output
Windows IP Configuration Successfully flushed the DNS Resolver Cache.
Detailed ICMP and routing test to 8.8.8.8
Useful before opening an external-DNS ticket - shows source interface, RTT, result.
Test-NetConnection -ComputerName 8.8.8.8 -InformationLevel DetailedExpected output
ComputerName : 8.8.8.8 RemoteAddress : 8.8.8.8 InterfaceAlias : Ethernet SourceAddress : 192.168.1.50 PingSucceeded : True PingReplyDetails (RTT) : 12 ms
List established TCP connections (excluding loopback)
Spot-check outbound connections. Useful when investigating suspected malware beacons.
Get-NetTCPConnection -State Established | Where-Object RemoteAddress -ne '127.0.0.1' | Select-Object LocalAddress, LocalPort, RemoteAddress, RemotePortExpected output
LocalAddress LocalPort RemoteAddress RemotePort ------------ -------- ------------- ---------- 192.168.1.50 49172 10.0.0.10 445 192.168.1.50 49180 142.250.0.5 443 192.168.1.50 49200 20.190.132.4 443