Skip to content
Franck SALLET edited this page Sep 5, 2026 · 1 revision

System

General Windows system administration: uptime, disk space, installed software, drivers, services, scheduled tasks, environment variables, page file, crash dumps, pending reboot, reboot history.

20 function(s) in Public/system/.

Functions

  • Clear-DiskCleanup — Removes temporary files and system cleanup targets from local or remote machines
  • Get-ComputerUptime — Retrieves system uptime for one or more Windows computers
  • Get-CrashDump — Inventory Windows crash memory dumps with size, type and BugCheck code
  • Get-DiskCleanupInfo — Scans a Windows computer and reports what can be cleaned up without deleting anything
  • Get-DiskSpace — Retrieves disk space information from local or remote computers
  • Get-DriverInventory — Retrieves a structured inventory of signed drivers from local or remote computers
  • Get-EnvironmentVariable — Retrieves environment variables from local or remote computers
  • Get-InstalledSoftware — Retrieves installed software from local or remote Windows computers
  • Get-PageFileConfiguration — Retrieves pagefile configuration and usage from local or remote computers
  • Get-PendingReboot — Checks pending reboot status from multiple Windows sources
  • Get-RebootHistory — Reconstructs reboot and shutdown history from the Windows System event log
  • Get-ScheduledTaskDetail — Retrieves scheduled task details from local or remote computers
  • Get-ServiceAccount — Audit service logon accounts across local or remote computers
  • Get-StartupProgram — Retrieves programs configured to run at system startup or user logon
  • Get-SystemSummary — Gather comprehensive system information from Windows machines
  • Remove-UserProfile — Removes stale user profiles that have not been used within a specified number of days
  • Set-EnvironmentVariable — Sets or deletes a Machine- or User-scoped environment variable on local or remote computers
  • Set-PageFile — Configure the Windows pagefile on local or remote computers
  • Show-SystemMonitor — Displays an interactive real-time system monitor inspired by htop
  • Stop-ProcessTree — Terminate a process and its entire descendant tree, leaves first

Reference

Clear-DiskCleanup

Removes temporary files and system cleanup targets from local or remote machines.

Performs disk cleanup operations across multiple categories including temporary files, Windows Update cache, Recycle Bin, crash dumps, old logs, browser caches, Windows.old, and thumbnail caches. Supports remote execution via the private Invoke-RemoteOrLocal helper. Accepts pipeline input from Get-DiskCleanupInfo.

Syntax

Clear-DiskCleanup [-ComputerName <string[]>] [-Category <string[]>] [-OlderThanDays <int>] [-ExcludePath <string[]>] [-Force]

Examples

Clear-DiskCleanup -Category 'TempFiles' -Force

Cleans temporary files older than 30 days on the local computer.

Clear-DiskCleanup -ComputerName 'SRV01' -Category 'WindowsUpdate', 'OldLogs' -Force

Cleans WindowsUpdate cache and old log files on remote server SRV01.

Get-DiskCleanupInfo -ComputerName 'SRV01' | Where-Object SizeMB -gt 100 | Clear-DiskCleanup -Force

Pipes scan results and cleans only categories larger than 100 MB.

Clear-DiskCleanup -Category 'All' -ExcludePath 'C:\Windows\Logs\CBS' -WhatIf

Shows what would be cleaned across all categories, excluding a specific path.

Output: PSWinOps.DiskCleanupResult

Returns one result object per category per computer with FilesRemoved, FilesSkipped, SpaceRecoveredBytes, SpaceRecoveredMB, and Errors.


Get-ComputerUptime

Retrieves system uptime for one or more Windows computers.

Queries Win32_OperatingSystem via CIM to retrieve the last boot time and calculates the current uptime for each target machine. Uses direct CIM queries for the local machine and CIM remoting (-ComputerName) for remote machines.

When the -Credential parameter is specified, a temporary CimSession is created for authentication and automatically cleaned up after use.

Unlike the built-in Get-Uptime cmdlet (PowerShell 6.1+), this function supports remote computers, credentials, pipeline input, and structured output with UptimeDays for sorting/filtering.

Syntax

Get-ComputerUptime [-ComputerName <string[]>] [-Credential <PSCredential>]

Examples

Get-ComputerUptime

Returns uptime information for the local machine using a direct CIM query.

Get-ComputerUptime -ComputerName 'SRV01', 'SRV02'

Returns uptime information for two remote servers via CIM remoting.

'SRV01', 'SRV02' | Get-ComputerUptime -Credential (Get-Credential)

Queries multiple servers via pipeline with explicit credentials.

Output: PSWinOps.ComputerUptime

Uptime details including last boot time and duration.


Get-CrashDump

Inventory Windows crash memory dumps with size, type and BugCheck code.

Enumerates minidumps and the full/kernel MEMORY.DMP on one or more machines in a single pass, reporting size, creation time and configured dump type. The BugCheck code and symbol are correlated from WER System Error Reporting event 1001 by temporal proximity, so no binary dump parsing is required. Local and remote targets are dispatched through Invoke-RemoteOrLocal.

Syntax

Get-CrashDump [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-Path <string>] [-Newest <int>]

Examples

Get-CrashDump

Returns every crash dump found on the local computer.

Get-CrashDump -ComputerName 'SRV01' -Newest 5

Returns the 5 most recent crash dumps on SRV01 via WinRM.

'SRV01', 'SRV02' | Get-CrashDump -Credential $cred

Returns crash dumps for SRV01 and SRV02 via pipeline, using alternate credentials.

Output: PSWinOps.CrashDump

One object per discovered dump file, with size, creation time, configured dump type, and the correlated BugCheck code/symbol when resolvable.


Get-DiskCleanupInfo

Scans a Windows computer and reports what can be cleaned up without deleting anything.

Analyzes multiple cleanup categories on local or remote Windows computers and returns size information for each category. Categories include temporary files, Windows Update cache, Recycle Bin, crash dumps, old logs, browser caches, Windows.old, and thumbnail caches. No files are deleted.

Syntax

Get-DiskCleanupInfo [-ComputerName <string[]>] [-Category <string[]>] [-OlderThanDays <int>]

Examples

Get-DiskCleanupInfo

Scans all cleanup categories on the local computer.

Get-DiskCleanupInfo -ComputerName 'SRV01' -Category 'TempFiles', 'OldLogs'

Scans only TempFiles and OldLogs categories on remote server SRV01.

'SRV01', 'SRV02' | Get-DiskCleanupInfo -Category 'BrowserCache'

Scans browser cache on multiple remote servers via pipeline.

Output: PSWinOps.DiskCleanupInfo

Returns one object per cleanup category per computer with file count, size in bytes and megabytes, and oldest/newest file timestamps.


Get-DiskSpace

Retrieves disk space information from local or remote computers.

Queries Win32_LogicalDisk via CIM to return disk usage statistics for fixed drives (DriveType 3). Calculates percentage free and applies configurable warning and critical thresholds to set a health status per volume.

Syntax

Get-DiskSpace [-ComputerName <string[]>] [-WarningThreshold <int>] [-CriticalThreshold <int>]

Examples

Get-DiskSpace

Retrieves disk space for all fixed drives on the local computer.

Get-DiskSpace -ComputerName 'SRV01' -WarningThreshold 30 -CriticalThreshold 15

Retrieves disk space from SRV01 with custom alert thresholds.

'SRV01', 'SRV02' | Get-DiskSpace

Retrieves disk space from multiple servers via pipeline.

Output: PSWinOps.DiskSpace

Returns one object per fixed drive with size, free space, usage percentages, and a health status based on configurable thresholds.


Get-DriverInventory

Retrieves a structured inventory of signed drivers from local or remote computers.

Queries Win32_PnPSignedDriver via CIM to return an inventory of installed device drivers, including device name, class, manufacturer, version, date, signature state, and INF file. Results can be filtered by device class or restricted to unsigned drivers only, and the function supports multiple machines with per-machine error isolation.

Syntax

Get-DriverInventory [-ComputerName <string[]>] [-DeviceClass <string>] [-UnsignedOnly]

Examples

Get-DriverInventory

Retrieves the full driver inventory from the local computer.

Get-DriverInventory -ComputerName 'SRV01' -DeviceClass 'Net'

Retrieves only network-class drivers from SRV01.

'SRV01', 'SRV02' | Get-DriverInventory -UnsignedOnly

Retrieves only unsigned drivers from multiple servers via pipeline.

Output: PSWinOps.DriverInventory

Returns one object per driver with device name, class, manufacturer, version, date, signature state, and INF file name.


Get-EnvironmentVariable

Retrieves environment variables from local or remote computers.

Returns environment variables organized by scope (Machine, User, Process). Machine and User scopes read from the registry for persistent values. Process scope uses the current runtime environment. Supports wildcard filtering by variable name.

Syntax

Get-EnvironmentVariable [-ComputerName <string[]>] [-VariableName <string>] [-Scope <string>]

Examples

Get-EnvironmentVariable

Returns all environment variables from all scopes on the local computer.

Get-EnvironmentVariable -ComputerName 'SRV01' -VariableName 'PATH' -Scope Machine

Returns the Machine-scoped PATH variable from SRV01.

'SRV01', 'SRV02' | Get-EnvironmentVariable -VariableName 'TEMP*'

Retrieves all TEMP-related variables from multiple servers via pipeline.

Output: PSWinOps.EnvironmentVariable

Returns objects with ComputerName, Name, Value, Scope, and Timestamp. Results are sorted by Scope then by Name.


Get-InstalledSoftware

Retrieves installed software from local or remote Windows computers.

Queries the Windows registry Uninstall keys to enumerate installed software. Both 64-bit and 32-bit (WOW6432Node) registry hives are queried to provide a complete inventory. Supports wildcard filtering by display name.

Syntax

Get-InstalledSoftware [-ComputerName <string[]>] [-Name <string>]

Examples

Get-InstalledSoftware

Retrieves all installed software on the local computer.

Get-InstalledSoftware -ComputerName 'SRV01' -Name 'Microsoft SQL*' -Credential (Get-Credential)

Retrieves SQL Server related software from SRV01 using alternate credentials.

'SRV01', 'SRV02' | Get-InstalledSoftware -Name '7-Zip*'

Retrieves 7-Zip installations from multiple servers via pipeline.

Output: PSWinOps.InstalledSoftware

Returns objects with ComputerName, DisplayName, DisplayVersion, Publisher, InstallDate, InstallLocation, UninstallString, Architecture, EstimatedSizeMB, and Timestamp properties. Output is sorted by DisplayName.


Get-PageFileConfiguration

Retrieves pagefile configuration and usage from local or remote computers.

Queries Win32_ComputerSystem, Win32_PageFileSetting, and Win32_PageFileUsage via CIM to return detailed pagefile configuration, current usage, and system memory information. Supports pipeline input and remote execution with optional credentials.

Syntax

Get-PageFileConfiguration [-ComputerName <string[]>]

Examples

Get-PageFileConfiguration

Retrieves pagefile configuration from the local computer.

Get-PageFileConfiguration -ComputerName 'SRV01'

Retrieves pagefile configuration from a single remote server.

'SRV01', 'SRV02' | Get-PageFileConfiguration

Retrieves pagefile configuration from multiple servers via pipeline.

Output: PSWinOps.PageFileConfiguration

Returns one object per pagefile found on each target computer, including path, sizes, current usage, and auto-managed status.


Get-PendingReboot

Checks pending reboot status from multiple Windows sources.

Queries multiple system sources to determine if a Windows machine has a pending reboot. Sources include Component Based Servicing, Windows Update, pending file rename operations, pending computer rename, and SCCM client SDK.

Syntax

Get-PendingReboot [-ComputerName <string[]>]

Examples

Get-PendingReboot

Checks the local machine for any pending reboot indicators.

Get-PendingReboot -ComputerName 'SERVER01'

Checks a single remote machine for pending reboot status.

'SERVER01', 'SERVER02' | Get-PendingReboot -Credential (Get-Credential)

Checks multiple remote machines via pipeline input with alternate credentials.

Output: PSWinOps.PendingReboot

Pending reboot status from multiple detection sources.


Get-RebootHistory

Reconstructs reboot and shutdown history from the Windows System event log.

Correlates Windows System event log entries (1074, 1076, 6005, 6006, 6008 and Kernel-Power 41) to rebuild each reboot or shutdown for one or more computers. Each event is classified as Planned, Unexpected, Crash, PowerLoss or Unknown, with its cause, initiator and comment, and the downtime duration between a clean stop and the following boot. Local and remote targets are dispatched through Invoke-RemoteOrLocal.

Syntax

Get-RebootHistory [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-MaxEvents <int>] [-After <datetime>] [-Before <datetime>]

Examples

Get-RebootHistory

Returns the 50 most recent reboot and shutdown records for the local machine.

Get-RebootHistory -ComputerName 'SRV01' -MaxEvents 20

Returns the 20 most recent reboot records for SRV01 via WinRM.

'SRV01', 'SRV02' | Get-RebootHistory -After (Get-Date).AddDays(-30)

Returns all reboots in the last 30 days for SRV01 and SRV02 via pipeline.

Output: PSWinOps.RebootHistory

One object per boot event, enriched with shutdown type, cause, initiator, comment and downtime duration.


Get-ScheduledTaskDetail

Retrieves scheduled task details from local or remote computers.

Queries the ScheduledTasks CIM namespace to enumerate scheduled tasks and their last/next run details. Returns typed PSWinOps.ScheduledTaskDetail objects with human-readable HRESULT translation. Microsoft built-in tasks are excluded by default to reduce noise.

Syntax

Get-ScheduledTaskDetail [-ComputerName <string[]>] [-TaskPath <string>] [-TaskName <string>] [-IncludeMicrosoftTasks]

Examples

Get-ScheduledTaskDetail

Retrieves all non-Microsoft scheduled tasks from the local computer.

Get-ScheduledTaskDetail -ComputerName 'SRV01' -TaskName 'Backup*' -Credential (Get-Credential)

Retrieves scheduled tasks matching 'Backup*' on SRV01 with explicit credentials.

'SRV01', 'SRV02' | Get-ScheduledTaskDetail -TaskPath '\Maintenance\*' -IncludeMicrosoftTasks

Queries multiple servers via pipeline for tasks in the Maintenance folder.

Output: PSWinOps.ScheduledTaskDetail

Returns one object per scheduled task with ComputerName, TaskName, TaskPath, State, LastRunTime, LastTaskResult, LastResultMessage, NextRunTime, Author, Description, and Timestamp.


Get-ServiceAccount

Audit service logon accounts across local or remote computers.

Projects Win32_Service into a security-oriented view of service logon accounts, reporting which account (Log On As / StartName) runs each service, its start mode, delayed auto-start flag, current state, and full binary path. Supports wildcard filtering by account and exclusion of built-in system accounts for multi-machine service-account auditing.

Syntax

Get-ServiceAccount [-ComputerName <string[]>] [-Account <string>] [-NonSystemOnly]

Examples

Get-ServiceAccount

Retrieves the logon account for every service on the local computer.

Get-ServiceAccount -ComputerName 'SRV01' -Account 'CONTOSO\svc-*' -Credential (Get-Credential)

Retrieves services on SRV01 whose logon account matches 'CONTOSO\svc-*' using alternate credentials.

'SRV01', 'SRV02' | Get-ServiceAccount -NonSystemOnly

Retrieves custom (non built-in) service accounts from multiple servers via pipeline.

Output: PSWinOps.ServiceAccount

Returns one object per matching service, with ComputerName, ServiceName, DisplayName, StartName, StartMode, DelayedAutoStart, State, PathName, and Timestamp.


Get-StartupProgram

Retrieves programs configured to run at system startup or user logon.

Enumerates startup entries from multiple sources: registry Run and RunOnce keys (both Machine and User scope, including WOW6432Node for 32-bit entries on 64-bit systems) and the common Startup folder. Provides a consolidated view of all auto-start programs across all launch points.

Syntax

Get-StartupProgram [-ComputerName <string[]>]

Examples

Get-StartupProgram

Lists all startup programs on the local computer.

Get-StartupProgram -ComputerName 'SRV01'

Lists startup programs from a remote server.

'SRV01', 'SRV02' | Get-StartupProgram

Lists startup programs from multiple servers via pipeline.

Output: PSWinOps.StartupProgram

Returns objects with program name, command line, location source, scope (Machine or User), and timestamp.


Get-SystemSummary

Gather comprehensive system information from Windows machines.

Queries six WMI/CIM classes to build a detailed system summary for local or remote Windows machines. Supports pipeline input, explicit credentials for remote hosts, and returns a structured PSCustomObject per machine. CIM session management and cleanup are handled automatically.

Syntax

Get-SystemSummary [-ComputerName <string[]>] [-Credential <PSCredential>]

Examples

Get-SystemSummary
Returns a full system summary for the local machine.
Get-SystemSummary -ComputerName 'SRV01', 'SRV02' -Credential (Get-Credential)
Returns system summaries for two remote servers using explicit credentials.
'WEB01', 'WEB02' | Get-SystemSummary -Verbose
Queries two machines via pipeline input with verbose logging.

Output: PSWinOps.SystemSummary

System information summary including OS, CPU, RAM, and uptime.


Remove-UserProfile

Removes stale user profiles that have not been used within a specified number of days.

Enumerates Win32_UserProfile instances via CIM and removes those whose LastUseTime exceeds the configured threshold. System and service profiles are always excluded. Supports -WhatIf and -Confirm for safe operation. Profile folder size is calculated before deletion unless -SkipSizeCalculation is specified. Returns a result object for each profile processed.

Syntax

Remove-UserProfile [-ComputerName <string[]>] [-OlderThanDays <int>] [-ExcludeUser <string[]>] [-SkipSizeCalculation] [-Credential <PSCredential>] [-Force]

Examples

Remove-UserProfile -WhatIf

Shows which profiles older than 90 days would be removed on the local machine.

Remove-UserProfile -ComputerName 'SRV01' -OlderThanDays 180 -Confirm:$false

Removes profiles unused for 180+ days on SRV01 without confirmation prompts.

'SRV01', 'SRV02' | Remove-UserProfile -ExcludeUser 'admin', 'svc_*' -WhatIf

Shows which profiles would be removed on two servers, excluding admin and any account starting with svc_.

Output: PSWinOps.UserProfileRemoval

Returns objects with ComputerName, UserName, LocalPath, SID, Source, LastUseTime, ProfileSizeMB, DaysInactive, Status, ErrorMessage, and Timestamp. The Source property indicates how the profile was detected: - Registry+Disk : entry in Win32_UserProfile AND folder on disk (normal) - RegistryOnly : entry in Win32_UserProfile but folder missing (ghost) - DiskOnly : folder under C:\Users with no Win32_UserProfile entry (orphan)


Set-EnvironmentVariable

Sets or deletes a Machine- or User-scoped environment variable on local or remote computers.

Sets a Machine- or User-scoped environment variable using [Environment]::SetEnvironmentVariable, the symmetric writer for Get-EnvironmentVariable. Supports -WhatIf/-Confirm (ConfirmImpact Medium). An empty Value deletes the variable. User scope targets the executing account profile when run remotely (the WinRM logon identity), not the console user; already-running processes will not see the change until restarted regardless of scope.

Syntax

Set-EnvironmentVariable -Name <string> -Value <string> [-Scope <string>] [-ComputerName <string[]>]

Examples

Set-EnvironmentVariable -Name 'FOO' -Value 'bar' -Scope Machine

Sets the Machine-scoped 'FOO' variable to 'bar' on the local computer.

Set-EnvironmentVariable -Name 'FOO' -Value 'bar' -ComputerName 'SRV01' -Credential (Get-Credential)

Sets the Machine-scoped 'FOO' variable to 'bar' on SRV01 using explicit credentials.

'SRV01', 'SRV02' | Set-EnvironmentVariable -Name 'FOO' -Value ''

Deletes the 'FOO' variable on both SRV01 and SRV02 via pipeline (empty Value = delete).

Output: PSWinOps.EnvironmentVariable

Returns one object per computer with the read-back Name/Value/Scope after the operation. Value is an empty string when the variable was deleted.


Set-PageFile

Configure the Windows pagefile on local or remote computers.

Configures the Windows pagefile by disabling automatic management and setting explicit initial and maximum sizes. Supports auto-calculation based on installed RAM, manual size specification, restoring automatic management, and ensuring the pagefile is large enough for a complete memory dump. All changes require a restart to take effect.

Syntax

Set-PageFile [-ComputerName <string[]>] [-DriveLetter <string>] -InitialSizeMB <int> -MaximumSizeMB <int> -AutoCalculate [-EnsureCompleteDump] -RestoreAutoManaged

Examples

Set-PageFile -AutoCalculate

Configures the pagefile on the local computer with sizes calculated from installed RAM.

Set-PageFile -ComputerName 'SRV01' -InitialSizeMB 8192 -MaximumSizeMB 16384

Sets the pagefile on SRV01 to a fixed 8 GB initial / 16 GB maximum size.

'SRV01', 'SRV02' | Set-PageFile -AutoCalculate -EnsureCompleteDump

Calculates pagefile sizes for each server via pipeline and ensures the size is sufficient for a complete memory dump.

Set-PageFile -RestoreAutoManaged -ComputerName 'SRV01'

Restores automatic pagefile management on SRV01.

Output: PSWinOps.PageFileConfiguration

Returns an object per computer with pagefile configuration details and status.


Show-SystemMonitor

Displays an interactive real-time system monitor inspired by htop.

Renders a full-screen terminal UI showing per-core CPU usage bars, memory and page file utilization, and a sortable process list refreshed at a configurable interval. Designed for use over SSH, remoting sessions, or any terminal where Task Manager is not available. Press Q to quit, or use C/M/P/N keys to change the sort column interactively.

Syntax

Show-SystemMonitor [-RefreshInterval <int>] [-ProcessCount <int>] [-NoColor]

Examples

Show-SystemMonitor

Launches the monitor with default settings (2-second refresh, top 25 processes).

Show-SystemMonitor -RefreshInterval 5 -ProcessCount 40

Refreshes every 5 seconds and shows the top 40 processes.

Show-SystemMonitor -NoColor

Launches without color for terminals that do not support ANSI escape sequences.


Stop-ProcessTree

Terminate a process and its entire descendant tree, leaves first.

Builds the descendant tree of one or more root processes from Win32_Process ParentProcessId and terminates every node, killing leaves before the root. Select roots by -Id or -Name (mutually exclusive), target local or remote machines, and preview with -WhatIf. Termination is irreversible (ConfirmImpact High).

Syntax

Stop-ProcessTree [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] -Id <int[]> -Name <string[]>

Examples

Stop-ProcessTree -Id 1234

Terminates process 1234 and all of its descendants on the local computer.

Stop-ProcessTree -Name 'chrome' -ComputerName 'SRV01'

Terminates every 'chrome' process tree found on SRV01.

'SRV01', 'SRV02' | Stop-ProcessTree -Name 'notepad' -WhatIf

Previews termination of every 'notepad' process tree on SRV01 and SRV02 without actually terminating anything.

Output: PSWinOps.ProcessKillResult

Returns one object per process examined (root, descendant, or unresolved root), including whether it was killed and any error encountered.


PSWinOps Wiki

Home

Domains

Clone this wiki locally