Skip to content

Latest commit

 

History

History
390 lines (256 loc) · 4.66 KB

File metadata and controls

390 lines (256 loc) · 4.66 KB

PowerShell Commands

Samer Sultan
https://www.sultansolutions.com

@SultanSolutions


Network Troubleshooting

Check if Hostname + Port is Reachable

Test-NetConnection [FQDN/IP Address] -Port [Port]

Example:

Test-NetConnection google.com -Port 443

Show only whether the TCP connection succeeded:

Test-NetConnection google.com -Port 443 |
Select-Object ComputerName, RemoteAddress, RemotePort, TcpTestSucceeded

Test Basic Connectivity

Test-Connection [Hostname/IP]

Example:

Test-Connection google.com

Single ping:

Test-Connection google.com -Count 1

Resolve DNS Name

Resolve-DnsName [Hostname]

Example:

Resolve-DnsName google.com

Query a specific DNS server:

Resolve-DnsName google.com -Server 8.8.8.8

Display IP Configuration

Get-NetIPConfiguration

More detailed information:

Get-NetIPConfiguration -Detailed

Traditional output:

ipconfig /all

Show DNS Servers

Get-DnsClientServerAddress

IPv4 only:

Get-DnsClientServerAddress -AddressFamily IPv4

Clear DNS Cache

Clear-DnsClientCache

Equivalent command:

ipconfig /flushdns

Show Network Adapters

Get-NetAdapter

Only connected adapters:

Get-NetAdapter |
Where-Object Status -eq "Up"

Restart Network Adapter

Restart-NetAdapter -Name "Ethernet"

For Wi-Fi:

Restart-NetAdapter -Name "Wi-Fi"

Show Routing Table

Get-NetRoute

IPv4 routes only:

Get-NetRoute -AddressFamily IPv4

Default route:

Get-NetRoute -DestinationPrefix "0.0.0.0/0"

Show Active TCP Connections

Get-NetTCPConnection

Established connections only:

Get-NetTCPConnection -State Established

Find connections using a specific port:

Get-NetTCPConnection -LocalPort 443

Find Which Process is Using a Port

Get-NetTCPConnection -LocalPort [Port] |
Select-Object LocalAddress, LocalPort, State, OwningProcess

Then find the process:

Get-Process -Id [PID]

Example:

Get-Process -Id (Get-NetTCPConnection -LocalPort 443).OwningProcess

Trace Network Path

Test-NetConnection google.com -TraceRoute

Traditional command:

tracert google.com

Display ARP / Neighbor Table

Get-NetNeighbor

IPv4 only:

Get-NetNeighbor -AddressFamily IPv4

Check Windows Firewall Profiles

Get-NetFirewallProfile

Show whether each firewall profile is enabled:

Get-NetFirewallProfile |
Select-Object Name, Enabled

Search Windows Firewall Rules

Get-NetFirewallRule |
Where-Object DisplayName -Like "*RDP*"

Show enabled rules:

Get-NetFirewallRule |
Where-Object Enabled -eq "True"

Check Listening Ports

Get-NetTCPConnection -State Listen

Sort by port:

Get-NetTCPConnection -State Listen |
Sort-Object LocalPort |
Select-Object LocalAddress, LocalPort, OwningProcess

Check Computer Hostname

hostname

PowerShell-native method:

$env:COMPUTERNAME

Check Current Logged-In User

whoami

PowerShell:

[System.Security.Principal.WindowsIdentity]::GetCurrent().Name

Check Domain Membership

Get-CimInstance Win32_ComputerSystem |
Select-Object Name, Domain, PartOfDomain

Check Domain Controller Being Used

nltest /dsgetdc:$env:USERDNSDOMAIN

Check the logon server:

$env:LOGONSERVER

Check Network Profile

Get-NetConnectionProfile

Displays whether the connection is:

  • DomainAuthenticated
  • Private
  • Public

Display Public IP Address

Invoke-RestMethod https://api.ipify.org

Display Local IPv4 Addresses

Get-NetIPAddress -AddressFamily IPv4 |
Where-Object IPAddress -NotLike "169.254*" |
Select-Object InterfaceAlias, IPAddress, PrefixLength

Test Multiple Ports

80,443,3389 | ForEach-Object {
    Test-NetConnection server01 -Port $_ |
    Select-Object ComputerName, RemotePort, TcpTestSucceeded
}

Continuous Connectivity Test

Test-Connection google.com -Continuous

Stop with:

Ctrl + C