Cheatsheets / Windows (PowerShell) Cheatsheet

Windows (PowerShell) Cheatsheet

Everyday PowerShell commands for Windows - files, processes, services, networking, and package management with winget.

Last verified

Commands target PowerShell 7+ (pwsh), which ships on modern Windows and is also available on macOS/Linux. Built-in aliases (like ls for Get-ChildItem) are noted but the full cmdlet name is shown first since aliases can be removed or shadowed.

Get-ChildItem

Lists files and folders in the current directory (aliased as ls or dir).

Set-Location C:\Projects

Changes the current directory (aliased as cd).

Get-Location

Prints the current directory’s full path (aliased as pwd).

New-Item -ItemType Directory -Path "a\b\c" -Force

Creates nested directories, without erroring if they already exist.

Copy-Item -Path src -Destination dest -Recurse

Copies a directory recursively.

Move-Item old.txt new.txt

Renames or moves a file.

Remove-Item -Path build -Recurse -Force

Deletes a directory and its contents without confirmation prompts.

Get-ChildItem -Recurse -Filter "*.log" | Where-Object LastWriteTime -gt (Get-Date).AddDays(-7)

Finds .log files modified in the last 7 days.

Get-Content file.txt -Tail 20

Prints the last 20 lines of a file.

Get-Content app.log -Wait -Tail 10

Follows a growing log file live, similar to tail -f; Ctrl+C to stop.

Set-Content -Path file.txt -Value "hello"

Overwrites a file’s contents (use Add-Content to append instead).

Search and text processing

Select-String -Path *.log -Pattern "ERROR"

Searches files for a pattern, printing matching lines with line numbers (like grep).

Get-ChildItem -Recurse | Select-String "TODO"

Recursively searches file contents for a pattern.

Sort-Object -Property Length

Sorts piped objects by a property - here, file size.

Get-Content data.csv | Select-Object -Unique

Removes duplicate lines from input.

(Get-Content file.txt).Count

Counts the number of lines in a file.

Compare-Object (Get-Content old.txt) (Get-Content new.txt)

Shows line-by-line differences between two files.

Processes and services

Get-Process

Lists running processes with CPU and memory usage.

Get-Process -Name chrome

Filters running processes by name.

Stop-Process -Name chrome -Force

Kills every process matching a name.

Stop-Process -Id 1234

Kills a specific process by PID.

Start-Process notepad.exe

Launches a program.

Get-Service

Lists all Windows services and their status.

Get-Service -Name spooler

Shows the status of a specific service.

Restart-Service -Name spooler

Restarts a Windows service (requires an elevated/admin shell).

Start-Service -Name spooler

Starts a stopped service.

System info

Get-ComputerInfo

Shows detailed OS, BIOS, and hardware information.

systeminfo

Legacy (but still available) command-line system summary - faster than Get-ComputerInfo for a quick check.

Get-Volume

Lists drive volumes with free/total space.

Get-Disk

Lists physical disks.

Get-PSDrive

Lists all PowerShell drives, including filesystem drives and the registry.

[Environment]::OSVersion

Prints the .NET-reported OS version string.

Networking

Test-Connection example.com -Count 4

Sends 4 ICMP echo requests, PowerShell’s equivalent of ping.

Test-NetConnection example.com -Port 443

Tests TCP connectivity to a specific port (useful when a firewall might be blocking it).

Get-NetIPAddress

Lists IP addresses assigned to all network adapters.

ipconfig /all

Legacy command showing detailed adapter configuration, still the fastest way to check IPs.

Resolve-DnsName example.com

Performs a DNS lookup (PowerShell’s equivalent of dig/nslookup).

Get-NetTCPConnection -State Listen

Lists listening TCP ports with owning process IDs (PowerShell’s equivalent of netstat -an).

Get-NetTCPConnection | Where-Object LocalPort -eq 8080

Finds which connection or listener is using a specific port.

See networking.md and ssh.md for a deeper cross-OS networking reference.

Package management (winget)

winget search vscode

Searches the Windows Package Manager repository.

winget install Microsoft.VisualStudioCode

Installs a package by its winget ID.

winget upgrade

Lists packages with available updates.

winget upgrade --all

Upgrades every package that has an update available.

winget list

Lists installed packages winget knows about.

winget uninstall Microsoft.VisualStudioCode

Uninstalls a package.

Users and permissions

whoami

Prints the current user, in DOMAIN\user form.

whoami /groups

Lists the security groups the current user belongs to.

Get-LocalUser

Lists local user accounts.

Get-Acl file.txt

Shows the access control list (permissions) on a file.

icacls file.txt /grant User:F

Grants full control on a file to a user via the legacy ACL tool (still the most reliable for scripting).

Environment and profile

$env:PATH

Prints the current session’s PATH environment variable.

$env:PATH += ";C:\Tools"

Appends a directory to PATH for the current session only.

Get-ExecutionPolicy

Shows whether the current session allows running local scripts.

Set-ExecutionPolicy -Scope CurrentUser RemoteSigned

Allows locally-written scripts to run while still requiring downloaded scripts to be signed.

$PROFILE

Prints the path to your PowerShell startup script (create it with New-Item -Path $PROFILE -Force if missing).

Get-Alias

Lists all cmdlet aliases available in the current session (like ls for Get-ChildItem).

Get-History

Lists commands run earlier in the current session.

Archives and remoting

Compress-Archive -Path dir -DestinationPath archive.zip

Creates a zip archive from a folder.

Expand-Archive -Path archive.zip -DestinationPath dest

Extracts a zip archive into a target directory.

Enter-PSSession -ComputerName server01

Opens an interactive remote PowerShell session (requires WinRM configured on the target).

Invoke-Command -ComputerName server01 -ScriptBlock { Get-Service }

Runs a command block on a remote machine and returns the result.