~/jackwent.co.uk
jack@jackwent:~$ cat commands.md

Commands Every IT Admin Should Know

published 7 October 20269 min read

You don’t need a hundred tools to fix most IT problems. A good handful of built-in commands will get you a very long way, on any Windows or Linux machine, without installing anything.

These are the ones I use most often after 20+ years in IT. For each one there’s what it does and when I actually reach for it, because knowing when is the bit nobody teaches you. Every code block has a copy button, so help yourself.

Windows: networking

Most “the internet is broken” tickets can be solved with this lot. Run them from Command Prompt or PowerShell.

CommandWhat it doesWhen I use it
ipconfigShows your IP address, subnet and gatewayFirst thing, every time. No gateway means no network.
ipconfig /allAdds DNS servers, MAC address and DHCP detailsChecking which DNS server a machine is really using
ipconfig /releaseGives up the current DHCP addressBefore moving a machine to a different network or VLAN
ipconfig /renewAsks DHCP for a fresh addressA 169.254.x.x address means DHCP failed, so try this
ipconfig /flushdnsClears the local DNS cacheA site moved servers and one PC still goes to the old one
pingChecks if a host answersping 1.1.1.1 then ping google.com tells you if it’s the network or DNS
tracertLists every hop on the way to a hostFinding where along the route things fall over
pathpingTraceroute plus packet loss at every hopIntermittent drops and “it’s slow sometimes” complaints
nslookupAsks DNS what a name resolves toChecking a DNS change has gone through
netstat -anLists every connection and listening portIs the service actually listening?
arp -aShows IP to MAC address mappingsSpotting two devices fighting over one IP
route printShows the routing tableVPN users who can’t reach one particular subnet
getmacLists MAC addressesDHCP reservations and network access control
hostnamePrints the computer nameMaking sure you’re on the box you think you are!

Two extras I use a lot: netstat -ano | findstr :443 shows which process ID is using port 443, and ping -t keeps pinging until you press Ctrl+C, which is perfect while you wiggle cables.

Windows: system and processes

CommandWhat it doesWhen I use it
tasklistLists running processesSeeing what’s running on a remote or headless machine
taskkillEnds a processtaskkill /im outlook.exe /f when Outlook won’t close
systeminfoOS version, install date, uptime, patchesGathering details for a ticket in one go
shutdown /r /t 0Restarts immediatelyWhen “have you tried turning it off and on again” is the fix
driverqueryLists installed driversHunting down an old or dodgy driver after a blue screen

Handy: systeminfo | find "Boot Time" tells you when the machine last restarted. Users don’t always remember correctly.

Windows: disks and repairs

CommandWhat it doesWhen I use it
chkdskChecks a disk for file system errorschkdsk C: /f after a crash or a power cut
diskpartManages disks and partitionsPrepping USB sticks and fixing broken partitions. Careful, clean wipes a whole disk.
sfc /scannowChecks and repairs Windows system filesOdd crashes, broken built-in apps, failing updates
dismRepairs the image that sfc repairs from, with dism /online /cleanup-image /restorehealthRun this first when sfc can’t fix everything

The order matters. DISM fixes the source, then sfc uses that source to fix the system:

Windows: Group Policy

CommandWhat it doesWhen I use it
gpupdate /forceReapplies Group Policy right nowYou’ve changed a policy and don’t want to wait 90 minutes
gpresult /rShows which policies applied and which groups you’re in“Why hasn’t my mapped drive appeared?”

For the full picture, gpresult /h report.html writes a proper HTML report you can open in a browser.

Linux: networking

CommandWhat it doesWhen I use it
ip aShows interfaces and IP addressesThe modern ifconfig, which isn’t installed by default any more
pingChecks if a host answersSame as Windows, but it runs until you press Ctrl+C. Add -c 4 to stop after four.
tracerouteLists every hop to a hostsudo apt install traceroute if it’s missing
ss -tulpnLists listening ports and the process behind each oneThe modern netstat. “Is nginx actually listening on 443?”
digDetailed DNS lookupsdig +short example.co.uk for just the answer

Linux: processes and resources

CommandWhat it doesWhen I use it
top / htopLive view of CPU, memory and processesSomething’s slow. htop is friendlier if it’s installed.
ps auxSnapshot of every processps aux | grep nginx to find one in particular
kill / kill -9Stops a processPlain kill asks nicely. -9 doesn’t ask. Try the polite one first.
df -hFree space on every diskFirst check whenever anything weird happens
du -shSize of a folderWorking out what’s eaten the disk
free -mMemory and swap in megabytesHeavy swap use explains a lot of slowness
uptimeHow long since the last reboot, plus loadDid it reboot overnight? Is it overloaded?

A full disk breaks things in strange ways, and df and du together will find the culprit in a minute:

Linux: who, what and where

CommandWhat it doesWhen I use it
uname -aKernel version and architectureChecking a kernel update took after a reboot
whoamiPrints your usernameAm I root right now?
idYour user ID and groups“Permission denied” when you think you’re in the right group
chmodChanges file permissionschmod +x script.sh to make a script runnable
chownChanges who owns a filesudo chown -R www-data: /var/www/site after copying files in as root

Please don’t fix permission errors with chmod 777. It makes the error go away by letting everyone do everything, which is a much bigger problem than the one you started with.

Linux: services and logs

CommandWhat it doesWhen I use it
systemctl statusShows if a service is running, plus its last few log linesFirst stop when a service is down
systemctl restartRestarts a serviceAfter changing its config
journalctlReads the system logsjournalctl -u nginx -f follows one service’s log live

Two more worth knowing: systemctl --failed lists every service that’s fallen over, and journalctl -b -p err shows only the errors since the last boot.

Linux: files and folders

CommandWhat it doesWhen I use it
lsLists filesls -lah shows hidden files, sizes and permissions
cdChanges foldercd - jumps back to the folder you were just in
mkdirMakes a foldermkdir -p a/b/c makes the whole path in one go
rm -rfDeletes a folder and everything in itNo undo, no recycle bin. Always run ls on the same path first.
grepSearches textgrep -ri "error" /var/log/ searches every log for errors

PowerShell versions

PowerShell can do everything Command Prompt can, and it gives you objects you can filter and sort rather than plain text. These are the swaps I use most:

Instead ofTryWhy it’s better
ping + telnetTest-NetConnection server -Port 443Tests a specific port, not just whether the host answers
nslookupResolve-DnsName example.co.ukCleaner output, and you can ask for a record type
ipconfigGet-NetIPConfigurationEverything per adapter, tidy
tasklistGet-Process | Sort-Object CPU -DescendingSortable, so the top offender is on line one
shutdown /rRestart-Computer -ComputerName pc01Works on remote machines too
systeminfoGet-ComputerInfoEvery property can be picked out on its own
Event ViewerGet-WinEvent -LogName System -MaxEvents 20Recent events without clicking through the GUI

Terminal shortcuts that save hours

These work in Bash on Linux, and most of them in PowerShell too.

  • Tab completes commands and file names. Press it twice to see every option.
  • Ctrl+R searches your command history. Start typing any part of an old command and it finds it.
  • !! repeats the last command. sudo !! reruns it with sudo when you forgot. (Linux)
  • Ctrl+C stops whatever’s running. Ctrl+L clears the screen.
  • history | grep ssh finds that command you ran last week. (Linux)
  • | clip copies a command’s output to the clipboard on Windows, like ipconfig /all | clip.
  • watch -n 5 df -h reruns a command every 5 seconds, great for keeping an eye on something. (Linux)
  • tail -f follows a log file as it’s written. Ctrl+C to stop.

My troubleshooting order

When something “doesn’t work”, I go through the same steps every time. It’s boring, and it works:

  1. Is it just this machine? Ask someone else to try, or try another device.
  2. Do I have an IP address? ipconfig or ip a. A 169.254.x.x address means DHCP failed.
  3. Can I reach the gateway? Ping the router.
  4. Can I reach the internet by IP? ping 1.1.1.1.
  5. Can I reach it by name? ping google.com. If step 4 works and this doesn’t, it’s DNS. It’s nearly always DNS.
  6. Is the service listening? Test-NetConnection server -Port 443 on Windows, ss -tulpn on the server itself.
  7. What do the logs say? journalctl, Event Viewer, or the application’s own logs.
  8. What changed? Updates, config changes, new kit. Something always changed.

A few safety rules

  • Read a command before you run it, especially one you’ve copied from the internet. Including this page!
  • Commands that delete things have no undo. rm -rf, diskpart clean and format don’t ask twice.
  • Check where you are before you hit Enter. hostname and pwd (Linux) are cheap insurance.
  • Script anything you do more than twice. I’ve got plenty of examples on my scripting page.

If there’s a command you can’t live without that isn’t here, let me know and I’ll add it.

[jackwent]