You don’t need a hundred tools to fix most IT problems. A good handful of built-in commands will get you a very long way, on any Windows or Linux machine, without installing anything.
These are the ones I use most often after 20+ years in IT. For each one there’s what it does and when I actually reach for it, because knowing when is the bit nobody teaches you. Every code block has a copy button, so help yourself.
Windows: networking
Most “the internet is broken” tickets can be solved with this lot. Run them from Command Prompt or PowerShell.
| Command | What it does | When I use it |
|---|---|---|
ipconfig | Shows your IP address, subnet and gateway | First thing, every time. No gateway means no network. |
ipconfig /all | Adds DNS servers, MAC address and DHCP details | Checking which DNS server a machine is really using |
ipconfig /release | Gives up the current DHCP address | Before moving a machine to a different network or VLAN |
ipconfig /renew | Asks DHCP for a fresh address | A 169.254.x.x address means DHCP failed, so try this |
ipconfig /flushdns | Clears the local DNS cache | A site moved servers and one PC still goes to the old one |
ping | Checks if a host answers | ping 1.1.1.1 then ping google.com tells you if it’s the network or DNS |
tracert | Lists every hop on the way to a host | Finding where along the route things fall over |
pathping | Traceroute plus packet loss at every hop | Intermittent drops and “it’s slow sometimes” complaints |
nslookup | Asks DNS what a name resolves to | Checking a DNS change has gone through |
netstat -an | Lists every connection and listening port | Is the service actually listening? |
arp -a | Shows IP to MAC address mappings | Spotting two devices fighting over one IP |
route print | Shows the routing table | VPN users who can’t reach one particular subnet |
getmac | Lists MAC addresses | DHCP reservations and network access control |
hostname | Prints the computer name | Making sure you’re on the box you think you are! |
Two extras I use a lot: netstat -ano | findstr :443 shows which process ID is using port 443, and ping -t keeps pinging until you press Ctrl+C, which is perfect while you wiggle cables.
Windows: system and processes
| Command | What it does | When I use it |
|---|---|---|
tasklist | Lists running processes | Seeing what’s running on a remote or headless machine |
taskkill | Ends a process | taskkill /im outlook.exe /f when Outlook won’t close |
systeminfo | OS version, install date, uptime, patches | Gathering details for a ticket in one go |
shutdown /r /t 0 | Restarts immediately | When “have you tried turning it off and on again” is the fix |
driverquery | Lists installed drivers | Hunting down an old or dodgy driver after a blue screen |
Handy: systeminfo | find "Boot Time" tells you when the machine last restarted. Users don’t always remember correctly.
Windows: disks and repairs
| Command | What it does | When I use it |
|---|---|---|
chkdsk | Checks a disk for file system errors | chkdsk C: /f after a crash or a power cut |
diskpart | Manages disks and partitions | Prepping USB sticks and fixing broken partitions. Careful, clean wipes a whole disk. |
sfc /scannow | Checks and repairs Windows system files | Odd crashes, broken built-in apps, failing updates |
dism | Repairs the image that sfc repairs from, with dism /online /cleanup-image /restorehealth | Run this first when sfc can’t fix everything |
The order matters. DISM fixes the source, then sfc uses that source to fix the system:
Windows: Group Policy
| Command | What it does | When I use it |
|---|---|---|
gpupdate /force | Reapplies Group Policy right now | You’ve changed a policy and don’t want to wait 90 minutes |
gpresult /r | Shows which policies applied and which groups you’re in | “Why hasn’t my mapped drive appeared?” |
For the full picture, gpresult /h report.html writes a proper HTML report you can open in a browser.
Linux: networking
| Command | What it does | When I use it |
|---|---|---|
ip a | Shows interfaces and IP addresses | The modern ifconfig, which isn’t installed by default any more |
ping | Checks if a host answers | Same as Windows, but it runs until you press Ctrl+C. Add -c 4 to stop after four. |
traceroute | Lists every hop to a host | sudo apt install traceroute if it’s missing |
ss -tulpn | Lists listening ports and the process behind each one | The modern netstat. “Is nginx actually listening on 443?” |
dig | Detailed DNS lookups | dig +short example.co.uk for just the answer |
Linux: processes and resources
| Command | What it does | When I use it |
|---|---|---|
top / htop | Live view of CPU, memory and processes | Something’s slow. htop is friendlier if it’s installed. |
ps aux | Snapshot of every process | ps aux | grep nginx to find one in particular |
kill / kill -9 | Stops a process | Plain kill asks nicely. -9 doesn’t ask. Try the polite one first. |
df -h | Free space on every disk | First check whenever anything weird happens |
du -sh | Size of a folder | Working out what’s eaten the disk |
free -m | Memory and swap in megabytes | Heavy swap use explains a lot of slowness |
uptime | How long since the last reboot, plus load | Did it reboot overnight? Is it overloaded? |
A full disk breaks things in strange ways, and df and du together will find the culprit in a minute:
Linux: who, what and where
| Command | What it does | When I use it |
|---|---|---|
uname -a | Kernel version and architecture | Checking a kernel update took after a reboot |
whoami | Prints your username | Am I root right now? |
id | Your user ID and groups | “Permission denied” when you think you’re in the right group |
chmod | Changes file permissions | chmod +x script.sh to make a script runnable |
chown | Changes who owns a file | sudo chown -R www-data: /var/www/site after copying files in as root |
Please don’t fix permission errors with chmod 777. It makes the error go away by letting everyone do everything, which is a much bigger problem than the one you started with.
Linux: services and logs
| Command | What it does | When I use it |
|---|---|---|
systemctl status | Shows if a service is running, plus its last few log lines | First stop when a service is down |
systemctl restart | Restarts a service | After changing its config |
journalctl | Reads the system logs | journalctl -u nginx -f follows one service’s log live |
Two more worth knowing: systemctl --failed lists every service that’s fallen over, and journalctl -b -p err shows only the errors since the last boot.
Linux: files and folders
| Command | What it does | When I use it |
|---|---|---|
ls | Lists files | ls -lah shows hidden files, sizes and permissions |
cd | Changes folder | cd - jumps back to the folder you were just in |
mkdir | Makes a folder | mkdir -p a/b/c makes the whole path in one go |
rm -rf | Deletes a folder and everything in it | No undo, no recycle bin. Always run ls on the same path first. |
grep | Searches text | grep -ri "error" /var/log/ searches every log for errors |
PowerShell versions
PowerShell can do everything Command Prompt can, and it gives you objects you can filter and sort rather than plain text. These are the swaps I use most:
| Instead of | Try | Why it’s better |
|---|---|---|
ping + telnet | Test-NetConnection server -Port 443 | Tests a specific port, not just whether the host answers |
nslookup | Resolve-DnsName example.co.uk | Cleaner output, and you can ask for a record type |
ipconfig | Get-NetIPConfiguration | Everything per adapter, tidy |
tasklist | Get-Process | Sort-Object CPU -Descending | Sortable, so the top offender is on line one |
shutdown /r | Restart-Computer -ComputerName pc01 | Works on remote machines too |
systeminfo | Get-ComputerInfo | Every property can be picked out on its own |
| Event Viewer | Get-WinEvent -LogName System -MaxEvents 20 | Recent events without clicking through the GUI |
Terminal shortcuts that save hours
These work in Bash on Linux, and most of them in PowerShell too.
- Tab completes commands and file names. Press it twice to see every option.
- Ctrl+R searches your command history. Start typing any part of an old command and it finds it.
!!repeats the last command.sudo !!reruns it with sudo when you forgot. (Linux)- Ctrl+C stops whatever’s running. Ctrl+L clears the screen.
history | grep sshfinds that command you ran last week. (Linux)| clipcopies a command’s output to the clipboard on Windows, likeipconfig /all | clip.watch -n 5 df -hreruns a command every 5 seconds, great for keeping an eye on something. (Linux)tail -ffollows a log file as it’s written. Ctrl+C to stop.
My troubleshooting order
When something “doesn’t work”, I go through the same steps every time. It’s boring, and it works:
- Is it just this machine? Ask someone else to try, or try another device.
- Do I have an IP address?
ipconfigorip a. A169.254.x.xaddress means DHCP failed. - Can I reach the gateway? Ping the router.
- Can I reach the internet by IP?
ping 1.1.1.1. - Can I reach it by name?
ping google.com. If step 4 works and this doesn’t, it’s DNS. It’s nearly always DNS. - Is the service listening?
Test-NetConnection server -Port 443on Windows,ss -tulpnon the server itself. - What do the logs say?
journalctl, Event Viewer, or the application’s own logs. - What changed? Updates, config changes, new kit. Something always changed.
A few safety rules
- Read a command before you run it, especially one you’ve copied from the internet. Including this page!
- Commands that delete things have no undo.
rm -rf,diskpart cleanandformatdon’t ask twice. - Check where you are before you hit Enter.
hostnameandpwd(Linux) are cheap insurance. - Script anything you do more than twice. I’ve got plenty of examples on my scripting page.
If there’s a command you can’t live without that isn’t here, let me know and I’ll add it.