Cheatsheets / Windows (PowerShell) Cheatsheet
Windows (PowerShell) Cheatsheet
Everyday PowerShell commands for Windows - files, processes, services, networking, and package management with winget.
Commands target PowerShell 7+ (pwsh), which ships on modern Windows and is
also available on macOS/Linux. Built-in aliases (like ls for Get-ChildItem)
are noted but the full cmdlet name is shown first since aliases can be removed
or shadowed.
Navigation and files
Get-ChildItem
Lists files and folders in the current directory (aliased as ls or dir).
Set-Location C:\Projects
Changes the current directory (aliased as cd).
Get-Location
Prints the current directory’s full path (aliased as pwd).
New-Item -ItemType Directory -Path "a\b\c" -Force
Creates nested directories, without erroring if they already exist.
Copy-Item -Path src -Destination dest -Recurse
Copies a directory recursively.
Move-Item old.txt new.txt
Renames or moves a file.
Remove-Item -Path build -Recurse -Force
Deletes a directory and its contents without confirmation prompts.
Get-ChildItem -Recurse -Filter "*.log" | Where-Object LastWriteTime -gt (Get-Date).AddDays(-7)
Finds .log files modified in the last 7 days.
Get-Content file.txt -Tail 20
Prints the last 20 lines of a file.
Get-Content app.log -Wait -Tail 10
Follows a growing log file live, similar to tail -f; Ctrl+C to stop.
Set-Content -Path file.txt -Value "hello"
Overwrites a file’s contents (use Add-Content to append instead).
Search and text processing
Select-String -Path *.log -Pattern "ERROR"
Searches files for a pattern, printing matching lines with line numbers (like grep).
Get-ChildItem -Recurse | Select-String "TODO"
Recursively searches file contents for a pattern.
Sort-Object -Property Length
Sorts piped objects by a property - here, file size.
Get-Content data.csv | Select-Object -Unique
Removes duplicate lines from input.
(Get-Content file.txt).Count
Counts the number of lines in a file.
Compare-Object (Get-Content old.txt) (Get-Content new.txt)
Shows line-by-line differences between two files.
Processes and services
Get-Process
Lists running processes with CPU and memory usage.
Get-Process -Name chrome
Filters running processes by name.
Stop-Process -Name chrome -Force
Kills every process matching a name.
Stop-Process -Id 1234
Kills a specific process by PID.
Start-Process notepad.exe
Launches a program.
Get-Service
Lists all Windows services and their status.
Get-Service -Name spooler
Shows the status of a specific service.
Restart-Service -Name spooler
Restarts a Windows service (requires an elevated/admin shell).
Start-Service -Name spooler
Starts a stopped service.
System info
Get-ComputerInfo
Shows detailed OS, BIOS, and hardware information.
systeminfo
Legacy (but still available) command-line system summary - faster than Get-ComputerInfo for a quick check.
Get-Volume
Lists drive volumes with free/total space.
Get-Disk
Lists physical disks.
Get-PSDrive
Lists all PowerShell drives, including filesystem drives and the registry.
[Environment]::OSVersion
Prints the .NET-reported OS version string.
Networking
Test-Connection example.com -Count 4
Sends 4 ICMP echo requests, PowerShell’s equivalent of ping.
Test-NetConnection example.com -Port 443
Tests TCP connectivity to a specific port (useful when a firewall might be blocking it).
Get-NetIPAddress
Lists IP addresses assigned to all network adapters.
ipconfig /all
Legacy command showing detailed adapter configuration, still the fastest way to check IPs.
Resolve-DnsName example.com
Performs a DNS lookup (PowerShell’s equivalent of dig/nslookup).
Get-NetTCPConnection -State Listen
Lists listening TCP ports with owning process IDs (PowerShell’s equivalent of netstat -an).
Get-NetTCPConnection | Where-Object LocalPort -eq 8080
Finds which connection or listener is using a specific port.
See networking.md and ssh.md for a deeper cross-OS networking reference.
Package management (winget)
winget search vscode
Searches the Windows Package Manager repository.
winget install Microsoft.VisualStudioCode
Installs a package by its winget ID.
winget upgrade
Lists packages with available updates.
winget upgrade --all
Upgrades every package that has an update available.
winget list
Lists installed packages winget knows about.
winget uninstall Microsoft.VisualStudioCode
Uninstalls a package.
Users and permissions
whoami
Prints the current user, in DOMAIN\user form.
whoami /groups
Lists the security groups the current user belongs to.
Get-LocalUser
Lists local user accounts.
Get-Acl file.txt
Shows the access control list (permissions) on a file.
icacls file.txt /grant User:F
Grants full control on a file to a user via the legacy ACL tool (still the most reliable for scripting).
Environment and profile
$env:PATH
Prints the current session’s PATH environment variable.
$env:PATH += ";C:\Tools"
Appends a directory to PATH for the current session only.
Get-ExecutionPolicy
Shows whether the current session allows running local scripts.
Set-ExecutionPolicy -Scope CurrentUser RemoteSigned
Allows locally-written scripts to run while still requiring downloaded scripts to be signed.
$PROFILE
Prints the path to your PowerShell startup script (create it with New-Item -Path $PROFILE -Force if missing).
Get-Alias
Lists all cmdlet aliases available in the current session (like ls for Get-ChildItem).
Get-History
Lists commands run earlier in the current session.
Archives and remoting
Compress-Archive -Path dir -DestinationPath archive.zip
Creates a zip archive from a folder.
Expand-Archive -Path archive.zip -DestinationPath dest
Extracts a zip archive into a target directory.
Enter-PSSession -ComputerName server01
Opens an interactive remote PowerShell session (requires WinRM configured on the target).
Invoke-Command -ComputerName server01 -ScriptBlock { Get-Service }
Runs a command block on a remote machine and returns the result.