-
Notifications
You must be signed in to change notification settings - Fork 0
System
General Windows system administration: uptime, disk space, installed software, drivers, services, scheduled tasks, environment variables, page file, crash dumps, pending reboot, reboot history.
20 function(s) in Public/system/.
-
Clear-DiskCleanup— Removes temporary files and system cleanup targets from local or remote machines -
Get-ComputerUptime— Retrieves system uptime for one or more Windows computers -
Get-CrashDump— Inventory Windows crash memory dumps with size, type and BugCheck code -
Get-DiskCleanupInfo— Scans a Windows computer and reports what can be cleaned up without deleting anything -
Get-DiskSpace— Retrieves disk space information from local or remote computers -
Get-DriverInventory— Retrieves a structured inventory of signed drivers from local or remote computers -
Get-EnvironmentVariable— Retrieves environment variables from local or remote computers -
Get-InstalledSoftware— Retrieves installed software from local or remote Windows computers -
Get-PageFileConfiguration— Retrieves pagefile configuration and usage from local or remote computers -
Get-PendingReboot— Checks pending reboot status from multiple Windows sources -
Get-RebootHistory— Reconstructs reboot and shutdown history from the Windows System event log -
Get-ScheduledTaskDetail— Retrieves scheduled task details from local or remote computers -
Get-ServiceAccount— Audit service logon accounts across local or remote computers -
Get-StartupProgram— Retrieves programs configured to run at system startup or user logon -
Get-SystemSummary— Gather comprehensive system information from Windows machines -
Remove-UserProfile— Removes stale user profiles that have not been used within a specified number of days -
Set-EnvironmentVariable— Sets or deletes a Machine- or User-scoped environment variable on local or remote computers -
Set-PageFile— Configure the Windows pagefile on local or remote computers -
Show-SystemMonitor— Displays an interactive real-time system monitor inspired by htop -
Stop-ProcessTree— Terminate a process and its entire descendant tree, leaves first
Removes temporary files and system cleanup targets from local or remote machines.
Performs disk cleanup operations across multiple categories including temporary files, Windows Update cache, Recycle Bin, crash dumps, old logs, browser caches, Windows.old, and thumbnail caches. Supports remote execution via the private Invoke-RemoteOrLocal helper. Accepts pipeline input from Get-DiskCleanupInfo.
Syntax
Clear-DiskCleanup [-ComputerName <string[]>] [-Category <string[]>] [-OlderThanDays <int>] [-ExcludePath <string[]>] [-Force]Examples
Clear-DiskCleanup -Category 'TempFiles' -ForceCleans temporary files older than 30 days on the local computer.
Clear-DiskCleanup -ComputerName 'SRV01' -Category 'WindowsUpdate', 'OldLogs' -ForceCleans WindowsUpdate cache and old log files on remote server SRV01.
Get-DiskCleanupInfo -ComputerName 'SRV01' | Where-Object SizeMB -gt 100 | Clear-DiskCleanup -ForcePipes scan results and cleans only categories larger than 100 MB.
Clear-DiskCleanup -Category 'All' -ExcludePath 'C:\Windows\Logs\CBS' -WhatIfShows what would be cleaned across all categories, excluding a specific path.
Output: PSWinOps.DiskCleanupResult
Returns one result object per category per computer with FilesRemoved, FilesSkipped, SpaceRecoveredBytes, SpaceRecoveredMB, and Errors.
Retrieves system uptime for one or more Windows computers.
Queries Win32_OperatingSystem via CIM to retrieve the last boot time and calculates the current uptime for each target machine. Uses direct CIM queries for the local machine and CIM remoting (-ComputerName) for remote machines.
When the -Credential parameter is specified, a temporary CimSession is created for authentication and automatically cleaned up after use.
Unlike the built-in Get-Uptime cmdlet (PowerShell 6.1+), this function supports remote computers, credentials, pipeline input, and structured output with UptimeDays for sorting/filtering.
Syntax
Get-ComputerUptime [-ComputerName <string[]>] [-Credential <PSCredential>]Examples
Get-ComputerUptimeReturns uptime information for the local machine using a direct CIM query.
Get-ComputerUptime -ComputerName 'SRV01', 'SRV02'Returns uptime information for two remote servers via CIM remoting.
'SRV01', 'SRV02' | Get-ComputerUptime -Credential (Get-Credential)Queries multiple servers via pipeline with explicit credentials.
Output: PSWinOps.ComputerUptime
Uptime details including last boot time and duration.
Inventory Windows crash memory dumps with size, type and BugCheck code.
Enumerates minidumps and the full/kernel MEMORY.DMP on one or more machines in a single pass, reporting size, creation time and configured dump type. The BugCheck code and symbol are correlated from WER System Error Reporting event 1001 by temporal proximity, so no binary dump parsing is required. Local and remote targets are dispatched through Invoke-RemoteOrLocal.
Syntax
Get-CrashDump [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-Path <string>] [-Newest <int>]Examples
Get-CrashDumpReturns every crash dump found on the local computer.
Get-CrashDump -ComputerName 'SRV01' -Newest 5Returns the 5 most recent crash dumps on SRV01 via WinRM.
'SRV01', 'SRV02' | Get-CrashDump -Credential $credReturns crash dumps for SRV01 and SRV02 via pipeline, using alternate credentials.
Output: PSWinOps.CrashDump
One object per discovered dump file, with size, creation time, configured dump type, and the correlated BugCheck code/symbol when resolvable.
Scans a Windows computer and reports what can be cleaned up without deleting anything.
Analyzes multiple cleanup categories on local or remote Windows computers and returns size information for each category. Categories include temporary files, Windows Update cache, Recycle Bin, crash dumps, old logs, browser caches, Windows.old, and thumbnail caches. No files are deleted.
Syntax
Get-DiskCleanupInfo [-ComputerName <string[]>] [-Category <string[]>] [-OlderThanDays <int>]Examples
Get-DiskCleanupInfoScans all cleanup categories on the local computer.
Get-DiskCleanupInfo -ComputerName 'SRV01' -Category 'TempFiles', 'OldLogs'Scans only TempFiles and OldLogs categories on remote server SRV01.
'SRV01', 'SRV02' | Get-DiskCleanupInfo -Category 'BrowserCache'Scans browser cache on multiple remote servers via pipeline.
Output: PSWinOps.DiskCleanupInfo
Returns one object per cleanup category per computer with file count, size in bytes and megabytes, and oldest/newest file timestamps.
Retrieves disk space information from local or remote computers.
Queries Win32_LogicalDisk via CIM to return disk usage statistics for fixed drives (DriveType 3). Calculates percentage free and applies configurable warning and critical thresholds to set a health status per volume.
Syntax
Get-DiskSpace [-ComputerName <string[]>] [-WarningThreshold <int>] [-CriticalThreshold <int>]Examples
Get-DiskSpaceRetrieves disk space for all fixed drives on the local computer.
Get-DiskSpace -ComputerName 'SRV01' -WarningThreshold 30 -CriticalThreshold 15Retrieves disk space from SRV01 with custom alert thresholds.
'SRV01', 'SRV02' | Get-DiskSpaceRetrieves disk space from multiple servers via pipeline.
Output: PSWinOps.DiskSpace
Returns one object per fixed drive with size, free space, usage percentages, and a health status based on configurable thresholds.
Retrieves a structured inventory of signed drivers from local or remote computers.
Queries Win32_PnPSignedDriver via CIM to return an inventory of installed device drivers, including device name, class, manufacturer, version, date, signature state, and INF file. Results can be filtered by device class or restricted to unsigned drivers only, and the function supports multiple machines with per-machine error isolation.
Syntax
Get-DriverInventory [-ComputerName <string[]>] [-DeviceClass <string>] [-UnsignedOnly]Examples
Get-DriverInventoryRetrieves the full driver inventory from the local computer.
Get-DriverInventory -ComputerName 'SRV01' -DeviceClass 'Net'Retrieves only network-class drivers from SRV01.
'SRV01', 'SRV02' | Get-DriverInventory -UnsignedOnlyRetrieves only unsigned drivers from multiple servers via pipeline.
Output: PSWinOps.DriverInventory
Returns one object per driver with device name, class, manufacturer, version, date, signature state, and INF file name.
Retrieves environment variables from local or remote computers.
Returns environment variables organized by scope (Machine, User, Process). Machine and User scopes read from the registry for persistent values. Process scope uses the current runtime environment. Supports wildcard filtering by variable name.
Syntax
Get-EnvironmentVariable [-ComputerName <string[]>] [-VariableName <string>] [-Scope <string>]Examples
Get-EnvironmentVariableReturns all environment variables from all scopes on the local computer.
Get-EnvironmentVariable -ComputerName 'SRV01' -VariableName 'PATH' -Scope MachineReturns the Machine-scoped PATH variable from SRV01.
'SRV01', 'SRV02' | Get-EnvironmentVariable -VariableName 'TEMP*'Retrieves all TEMP-related variables from multiple servers via pipeline.
Output: PSWinOps.EnvironmentVariable
Returns objects with ComputerName, Name, Value, Scope, and Timestamp. Results are sorted by Scope then by Name.
Retrieves installed software from local or remote Windows computers.
Queries the Windows registry Uninstall keys to enumerate installed software. Both 64-bit and 32-bit (WOW6432Node) registry hives are queried to provide a complete inventory. Supports wildcard filtering by display name.
Syntax
Get-InstalledSoftware [-ComputerName <string[]>] [-Name <string>]Examples
Get-InstalledSoftwareRetrieves all installed software on the local computer.
Get-InstalledSoftware -ComputerName 'SRV01' -Name 'Microsoft SQL*' -Credential (Get-Credential)Retrieves SQL Server related software from SRV01 using alternate credentials.
'SRV01', 'SRV02' | Get-InstalledSoftware -Name '7-Zip*'Retrieves 7-Zip installations from multiple servers via pipeline.
Output: PSWinOps.InstalledSoftware
Returns objects with ComputerName, DisplayName, DisplayVersion, Publisher, InstallDate, InstallLocation, UninstallString, Architecture, EstimatedSizeMB, and Timestamp properties. Output is sorted by DisplayName.
Retrieves pagefile configuration and usage from local or remote computers.
Queries Win32_ComputerSystem, Win32_PageFileSetting, and Win32_PageFileUsage via CIM to return detailed pagefile configuration, current usage, and system memory information. Supports pipeline input and remote execution with optional credentials.
Syntax
Get-PageFileConfiguration [-ComputerName <string[]>]Examples
Get-PageFileConfigurationRetrieves pagefile configuration from the local computer.
Get-PageFileConfiguration -ComputerName 'SRV01'Retrieves pagefile configuration from a single remote server.
'SRV01', 'SRV02' | Get-PageFileConfigurationRetrieves pagefile configuration from multiple servers via pipeline.
Output: PSWinOps.PageFileConfiguration
Returns one object per pagefile found on each target computer, including path, sizes, current usage, and auto-managed status.
Checks pending reboot status from multiple Windows sources.
Queries multiple system sources to determine if a Windows machine has a pending reboot. Sources include Component Based Servicing, Windows Update, pending file rename operations, pending computer rename, and SCCM client SDK.
Syntax
Get-PendingReboot [-ComputerName <string[]>]Examples
Get-PendingRebootChecks the local machine for any pending reboot indicators.
Get-PendingReboot -ComputerName 'SERVER01'Checks a single remote machine for pending reboot status.
'SERVER01', 'SERVER02' | Get-PendingReboot -Credential (Get-Credential)Checks multiple remote machines via pipeline input with alternate credentials.
Output: PSWinOps.PendingReboot
Pending reboot status from multiple detection sources.
Reconstructs reboot and shutdown history from the Windows System event log.
Correlates Windows System event log entries (1074, 1076, 6005, 6006, 6008 and Kernel-Power 41) to rebuild each reboot or shutdown for one or more computers. Each event is classified as Planned, Unexpected, Crash, PowerLoss or Unknown, with its cause, initiator and comment, and the downtime duration between a clean stop and the following boot. Local and remote targets are dispatched through Invoke-RemoteOrLocal.
Syntax
Get-RebootHistory [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-MaxEvents <int>] [-After <datetime>] [-Before <datetime>]Examples
Get-RebootHistoryReturns the 50 most recent reboot and shutdown records for the local machine.
Get-RebootHistory -ComputerName 'SRV01' -MaxEvents 20Returns the 20 most recent reboot records for SRV01 via WinRM.
'SRV01', 'SRV02' | Get-RebootHistory -After (Get-Date).AddDays(-30)Returns all reboots in the last 30 days for SRV01 and SRV02 via pipeline.
Output: PSWinOps.RebootHistory
One object per boot event, enriched with shutdown type, cause, initiator, comment and downtime duration.
Retrieves scheduled task details from local or remote computers.
Queries the ScheduledTasks CIM namespace to enumerate scheduled tasks and their last/next run details. Returns typed PSWinOps.ScheduledTaskDetail objects with human-readable HRESULT translation. Microsoft built-in tasks are excluded by default to reduce noise.
Syntax
Get-ScheduledTaskDetail [-ComputerName <string[]>] [-TaskPath <string>] [-TaskName <string>] [-IncludeMicrosoftTasks]Examples
Get-ScheduledTaskDetailRetrieves all non-Microsoft scheduled tasks from the local computer.
Get-ScheduledTaskDetail -ComputerName 'SRV01' -TaskName 'Backup*' -Credential (Get-Credential)Retrieves scheduled tasks matching 'Backup*' on SRV01 with explicit credentials.
'SRV01', 'SRV02' | Get-ScheduledTaskDetail -TaskPath '\Maintenance\*' -IncludeMicrosoftTasksQueries multiple servers via pipeline for tasks in the Maintenance folder.
Output: PSWinOps.ScheduledTaskDetail
Returns one object per scheduled task with ComputerName, TaskName, TaskPath, State, LastRunTime, LastTaskResult, LastResultMessage, NextRunTime, Author, Description, and Timestamp.
Audit service logon accounts across local or remote computers.
Projects Win32_Service into a security-oriented view of service logon accounts, reporting which account (Log On As / StartName) runs each service, its start mode, delayed auto-start flag, current state, and full binary path. Supports wildcard filtering by account and exclusion of built-in system accounts for multi-machine service-account auditing.
Syntax
Get-ServiceAccount [-ComputerName <string[]>] [-Account <string>] [-NonSystemOnly]Examples
Get-ServiceAccountRetrieves the logon account for every service on the local computer.
Get-ServiceAccount -ComputerName 'SRV01' -Account 'CONTOSO\svc-*' -Credential (Get-Credential)Retrieves services on SRV01 whose logon account matches 'CONTOSO\svc-*' using alternate credentials.
'SRV01', 'SRV02' | Get-ServiceAccount -NonSystemOnlyRetrieves custom (non built-in) service accounts from multiple servers via pipeline.
Output: PSWinOps.ServiceAccount
Returns one object per matching service, with ComputerName, ServiceName, DisplayName, StartName, StartMode, DelayedAutoStart, State, PathName, and Timestamp.
Retrieves programs configured to run at system startup or user logon.
Enumerates startup entries from multiple sources: registry Run and RunOnce keys (both Machine and User scope, including WOW6432Node for 32-bit entries on 64-bit systems) and the common Startup folder. Provides a consolidated view of all auto-start programs across all launch points.
Syntax
Get-StartupProgram [-ComputerName <string[]>]Examples
Get-StartupProgramLists all startup programs on the local computer.
Get-StartupProgram -ComputerName 'SRV01'Lists startup programs from a remote server.
'SRV01', 'SRV02' | Get-StartupProgramLists startup programs from multiple servers via pipeline.
Output: PSWinOps.StartupProgram
Returns objects with program name, command line, location source, scope (Machine or User), and timestamp.
Gather comprehensive system information from Windows machines.
Queries six WMI/CIM classes to build a detailed system summary for local or remote Windows machines. Supports pipeline input, explicit credentials for remote hosts, and returns a structured PSCustomObject per machine. CIM session management and cleanup are handled automatically.
Syntax
Get-SystemSummary [-ComputerName <string[]>] [-Credential <PSCredential>]Examples
Get-SystemSummary
Returns a full system summary for the local machine.Get-SystemSummary -ComputerName 'SRV01', 'SRV02' -Credential (Get-Credential)
Returns system summaries for two remote servers using explicit credentials.'WEB01', 'WEB02' | Get-SystemSummary -Verbose
Queries two machines via pipeline input with verbose logging.Output: PSWinOps.SystemSummary
System information summary including OS, CPU, RAM, and uptime.
Removes stale user profiles that have not been used within a specified number of days.
Enumerates Win32_UserProfile instances via CIM and removes those whose LastUseTime exceeds the configured threshold. System and service profiles are always excluded. Supports -WhatIf and -Confirm for safe operation. Profile folder size is calculated before deletion unless -SkipSizeCalculation is specified. Returns a result object for each profile processed.
Syntax
Remove-UserProfile [-ComputerName <string[]>] [-OlderThanDays <int>] [-ExcludeUser <string[]>] [-SkipSizeCalculation] [-Credential <PSCredential>] [-Force]Examples
Remove-UserProfile -WhatIfShows which profiles older than 90 days would be removed on the local machine.
Remove-UserProfile -ComputerName 'SRV01' -OlderThanDays 180 -Confirm:$falseRemoves profiles unused for 180+ days on SRV01 without confirmation prompts.
'SRV01', 'SRV02' | Remove-UserProfile -ExcludeUser 'admin', 'svc_*' -WhatIfShows which profiles would be removed on two servers, excluding admin and any account starting with svc_.
Output: PSWinOps.UserProfileRemoval
Returns objects with ComputerName, UserName, LocalPath, SID, Source, LastUseTime, ProfileSizeMB, DaysInactive, Status, ErrorMessage, and Timestamp. The Source property indicates how the profile was detected: - Registry+Disk : entry in Win32_UserProfile AND folder on disk (normal) - RegistryOnly : entry in Win32_UserProfile but folder missing (ghost) - DiskOnly : folder under C:\Users with no Win32_UserProfile entry (orphan)
Sets or deletes a Machine- or User-scoped environment variable on local or remote computers.
Sets a Machine- or User-scoped environment variable using [Environment]::SetEnvironmentVariable, the symmetric writer for Get-EnvironmentVariable. Supports -WhatIf/-Confirm (ConfirmImpact Medium). An empty Value deletes the variable. User scope targets the executing account profile when run remotely (the WinRM logon identity), not the console user; already-running processes will not see the change until restarted regardless of scope.
Syntax
Set-EnvironmentVariable -Name <string> -Value <string> [-Scope <string>] [-ComputerName <string[]>]Examples
Set-EnvironmentVariable -Name 'FOO' -Value 'bar' -Scope MachineSets the Machine-scoped 'FOO' variable to 'bar' on the local computer.
Set-EnvironmentVariable -Name 'FOO' -Value 'bar' -ComputerName 'SRV01' -Credential (Get-Credential)Sets the Machine-scoped 'FOO' variable to 'bar' on SRV01 using explicit credentials.
'SRV01', 'SRV02' | Set-EnvironmentVariable -Name 'FOO' -Value ''Deletes the 'FOO' variable on both SRV01 and SRV02 via pipeline (empty Value = delete).
Output: PSWinOps.EnvironmentVariable
Returns one object per computer with the read-back Name/Value/Scope after the operation. Value is an empty string when the variable was deleted.
Configure the Windows pagefile on local or remote computers.
Configures the Windows pagefile by disabling automatic management and setting explicit initial and maximum sizes. Supports auto-calculation based on installed RAM, manual size specification, restoring automatic management, and ensuring the pagefile is large enough for a complete memory dump. All changes require a restart to take effect.
Syntax
Set-PageFile [-ComputerName <string[]>] [-DriveLetter <string>] -InitialSizeMB <int> -MaximumSizeMB <int> -AutoCalculate [-EnsureCompleteDump] -RestoreAutoManagedExamples
Set-PageFile -AutoCalculateConfigures the pagefile on the local computer with sizes calculated from installed RAM.
Set-PageFile -ComputerName 'SRV01' -InitialSizeMB 8192 -MaximumSizeMB 16384Sets the pagefile on SRV01 to a fixed 8 GB initial / 16 GB maximum size.
'SRV01', 'SRV02' | Set-PageFile -AutoCalculate -EnsureCompleteDumpCalculates pagefile sizes for each server via pipeline and ensures the size is sufficient for a complete memory dump.
Set-PageFile -RestoreAutoManaged -ComputerName 'SRV01'Restores automatic pagefile management on SRV01.
Output: PSWinOps.PageFileConfiguration
Returns an object per computer with pagefile configuration details and status.
Displays an interactive real-time system monitor inspired by htop.
Renders a full-screen terminal UI showing per-core CPU usage bars, memory and page file utilization, and a sortable process list refreshed at a configurable interval. Designed for use over SSH, remoting sessions, or any terminal where Task Manager is not available. Press Q to quit, or use C/M/P/N keys to change the sort column interactively.
Syntax
Show-SystemMonitor [-RefreshInterval <int>] [-ProcessCount <int>] [-NoColor]Examples
Show-SystemMonitorLaunches the monitor with default settings (2-second refresh, top 25 processes).
Show-SystemMonitor -RefreshInterval 5 -ProcessCount 40Refreshes every 5 seconds and shows the top 40 processes.
Show-SystemMonitor -NoColorLaunches without color for terminals that do not support ANSI escape sequences.
Terminate a process and its entire descendant tree, leaves first.
Builds the descendant tree of one or more root processes from Win32_Process ParentProcessId and terminates every node, killing leaves before the root. Select roots by -Id or -Name (mutually exclusive), target local or remote machines, and preview with -WhatIf. Termination is irreversible (ConfirmImpact High).
Syntax
Stop-ProcessTree [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] -Id <int[]> -Name <string[]>Examples
Stop-ProcessTree -Id 1234Terminates process 1234 and all of its descendants on the local computer.
Stop-ProcessTree -Name 'chrome' -ComputerName 'SRV01'Terminates every 'chrome' process tree found on SRV01.
'SRV01', 'SRV02' | Stop-ProcessTree -Name 'notepad' -WhatIfPreviews termination of every 'notepad' process tree on SRV01 and SRV02 without actually terminating anything.
Output: PSWinOps.ProcessKillResult
Returns one object per process examined (root, descendant, or unresolved root), including whether it was killed and any error encountered.
Domains
- Active Directory (22)
- Certificate (1)
- Event Log (9)
- Health Check (16)
- IIS (9)
- Network (26)
- NTP (5)
- Proxy (4)
- RDP (6)
- Security (1)
- System (20)
- Utils (4)
- VSS (Shadow Copy) (6)
- Windows Update (10)