Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Every technician's day still includes a black window. When the GUI hangs, the network drops or Windows Setup stalls, the fastest tool on the machine is a text prompt that has shipped with Windows for decades. This is a technician reference to cmd.exe: the commands for networking, processes, system info, disks, shutdown and permissions, with the switches and the ticket each one fits.

TL;DR

  • cmd.exe is the Windows command interpreter. It matters because it opens in places the GUI and PowerShell do not: the Shift+F10 prompt in Windows Setup and the Command Prompt in the recovery environment.
  • Only a handful of commands (dir, cd, copy, set, echo, for, if) live inside cmd.exe. The rest, such as ping, taskkill and shutdown, are programs in System32 that work the same from PowerShell.
  • WMIC is gone from Windows 11 24H2 and 25H2 as of August 2026. Serial-number and uptime one-liners that used it now need Get-CimInstance or systeminfo.
  • A timeout above zero on shutdown implies /f, so users lose unsaved work. Chain checks with && and || and pipe long output into findstr.
  • Once the same command has to run on dozens of machines, move it to PowerShell or a script run across the fleet.

What cmd.exe Is and Where It Still Wins

cmd.exe is the Windows Command Processor. Typing cmd in the Run box starts it, and typing exit closes it. The window around it may be the classic console or Windows Terminal, which can host cmd.exe, PowerShell and WSL side by side. "Command prompt" is the name people use for the experience, and cmd.exe is the program behind it.

It handles text, not objects. Everything a command prints is a string, which is why the pipe into findstr is the main filtering tool. PowerShell passes objects with properties, which is why it wins at reporting. The PowerShell vs CMD comparison covers that split in depth.

Two facts decide when a technician reaches for cmd.exe. The first is location. Windows Setup opens a Command Prompt on Shift+F10, and the recovery environment offers one under Troubleshoot and Advanced options. Neither needs a working desktop. The second is portability. Every program in this guide is a standalone executable, so a one-liner pasted from a ticket note works from any shell, a remote console or an RMM script.

Opening cmd the Way a Technician Does

Press Win+R, type cmd and press Enter for a standard prompt. For an elevated one, type cmd in the Run box and press Ctrl+Shift+Enter, or right-click Command Prompt in Start and choose Run as administrator. The title bar then reads "Administrator: Command Prompt".

An unelevated prompt causes a long list of "access denied" tickets. This one-liner settles it, because net session only succeeds with admin rights:

code
net session >nul 2>&1 && echo Elevated || echo Not elevated

In Windows Setup or the first-run screens, press Shift+F10. Some laptops need Fn+Shift+F10. In the recovery environment, choose Command Prompt from Advanced options. Drive letters there often differ from the installed system, so find the Windows volume before running anything:

code
diskpart
list volume
exit
dir D:\Windows

Two launch switches are worth knowing. cmd /c <command> runs a command and exits, which is what scripts and scheduled tasks use. cmd /k <command> runs it and keeps the window open.

These are the commands behind every file hunt. cd /d changes drive and folder in one step, which plain cd does not.

code
cd /d D:\Logs
dir /a /o-d
dir /s /b *.log
tree /f C:\Users\jsmith\Desktop
type app.log | findstr /i "error"
findstr /s /i /c:"password" *.config
where /r C:\ outlook.exe

dir /a shows hidden and system files, /o-d sorts newest first, and /s /b walks subfolders and prints bare paths. findstr takes a regular-expression subset and is the cmd.exe answer to grep.

For copying, use robocopy instead of copy or xcopy. It retries, resumes and logs.

code
robocopy C:\Users\jsmith D:\Backup\jsmith /e /r:1 /w:1 /log:C:\Temp\copy.log

/mir mirrors a folder and deletes anything in the destination that is missing from the source, so check the order of the two paths twice. Robocopy exit codes are bit flags: 0 to 7 mean the run succeeded in some form (0 nothing to copy, 1 files copied, 2 extra files in the destination), and 8 or higher means at least one failure.

Network Commands

Network tickets reward a fixed order, because each command rules out a layer. Start at the machine, move to the gateway, then the internet, then names.

code
ping 127.0.0.1
ping 192.168.1.1
ping 1.1.1.1
ping example.com
nslookup example.com

If the first ping fails, the TCP/IP stack on the machine is damaged. If the gateway fails, the problem is the cable, Wi-Fi or switch port. If the IP address works but the name does not, the cause is DNS, and nslookup example.com 1.1.1.1 shows whether a different resolver answers. The ipconfig commands guide covers the address side of this ladder, including what a 169.254 address means, so this guide stops short of repeating it.

The rest of the toolkit:

code
ping -t 192.168.1.1
ping -n 20 -l 1472 -f 1.1.1.1
tracert -d 1.1.1.1
pathping -n 1.1.1.1
netstat -ano
netstat -ano | findstr :3389
route print
arp -a
netsh winsock reset
netsh int ip reset

ping -t runs until Ctrl+C, which is how you watch a flapping link while someone reseats a cable. -f with -l tests the path MTU by setting the don't-fragment bit with a payload size. tracert -d skips name lookups so the hops appear faster, and pathping adds per-hop loss statistics over a few minutes.

netstat -ano lists connections with the owning process ID. Pair it with tasklist to name the program: take the PID from the last column and run tasklist /fi "pid eq 4120". The two netsh resets repair a corrupted Winsock catalog and TCP/IP stack, and both need a restart to take effect.

Mapped drives are the other network job that lands in cmd.exe, through net use. The guide to mapping a network drive covers the GUI, CMD and GPO routes.

Process Commands: Tasklist and Taskkill

Tasklist shows what is running and taskkill ends it. Together they replace Task Manager on a machine too slow to open it, or on a remote session where you only have a prompt.

code
tasklist
tasklist /v /fi "status eq not responding"
tasklist /svc /fi "imagename eq svchost.exe"
tasklist /fi "memusage gt 500000"

/v adds window titles and status, /svc maps a process to the Windows services inside it, and /fi filters by image name, PID, status, memory and more. Memory in the filter is in kilobytes, so 500000 is roughly 500 MB.

Taskkill takes a name (/im) or a process ID (/pid).

code
taskkill /im outlook.exe
taskkill /f /im outlook.exe
taskkill /f /t /im teams.exe
taskkill /fi "status eq not responding" /f
taskkill /s PC042 /u CONTOSO\admin /im app.exe

Without /f, taskkill asks the program to close, and a hung program ignores the request. With /f, the process is ended forcefully and unsaved work in it is gone. /t ends the whole process tree, which matters for apps that spawn helpers and relaunch them. Microsoft's documentation notes that /f is ignored for remote processes, because all remote processes are forcefully ended.

"Access is denied" means the prompt is not elevated or the target is a protected system process. Do not push past the second case. Killing svchost.exe by name takes down every service hosted in it, and ending csrss.exe or wininit.exe crashes the machine.

The classic taskkill ticket is a frozen taskbar. Ending explorer.exe and starting it again fixes it without a reboot, and the guide to restarting Windows Explorer lists the steps and the failure cases.

System Info and Serial Number Commands

Systeminfo is the one-screen inventory: OS name and build, install date, boot time, hardware model, BIOS version, domain, logon server and the installed hotfixes. Filter it unless you want 70 lines.

code
systeminfo | findstr /b /c:"OS Name" /c:"OS Version" /c:"System Boot Time"
systeminfo /s PC042
hostname
whoami
whoami /groups
ver

Run hostname and whoami before anything destructive. They confirm which machine and which account the next command lands on, and the thirty seconds they cost beat a wrong-machine ticket.

Uptime has no dedicated command in cmd.exe. Two one-liners cover it:

code
systeminfo | find "System Boot Time"
net statistics workstation | find "since"

Serial numbers were the job WMIC did best, and WMIC is now gone. Microsoft's deprecated-features page lists the utility as deprecated, and its August 2026 update states that WMIC is removed and no longer available as a Feature on Demand on Windows 11, version 24H2 and above. WMI itself is unaffected. Only the command-line tool left. The replacement is a one-line PowerShell call that works from a cmd.exe prompt:

code
:: old way, fails on current Windows 11
wmic bios get serialnumber

:: replacement, run from cmd.exe
powershell -NoProfile -Command "(Get-CimInstance Win32_BIOS).SerialNumber"
powershell -NoProfile -Command "(Get-CimInstance Win32_OperatingSystem).LastBootUpTime"
powershell -NoProfile -Command "Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5"

On a white-box PC or a virtual machine, the serial field may read "To be filled by O.E.M." or a placeholder, because the manufacturer never wrote one. In that case the motherboard or hypervisor ID is the best identifier you have.

An r/sysadmin thread from August 2026 shows how the removal lands in practice. One administrator noticed WMIC missing after the Windows 11 preview updates and asked how to put it back, and replies in the thread say they have moved to gcim Win32_bios instead of fighting it.

Audit any old scripts and RMM tasks for wmic now. A script that quietly returned a serial number last year will return an error on the next build.

Disk and Repair Commands

Repair commands split into two families, and picking the wrong one wastes an hour. Suspect the disk when you see clicking, SMART warnings or file system errors. Suspect Windows files when you see crashes, failed updates or missing components.

For Windows files, run DISM first and sfc second. DISM repairs the component store, and sfc then repairs system files from that store.

code
DISM /Online /Cleanup-Image /RestoreHealth
sfc /scannow

Both need an elevated prompt, and sfc logs its findings to C:\Windows\Logs\CBS\CBS.log. When DISM fails with a source error, the DISM RestoreHealth guide walks through the causes and the fixes.

For the disk, chkdsk checks the file system.

code
chkdsk C:
chkdsk C: /f
chkdsk C: /r

Plain chkdsk C: is read-only and reports. /f fixes file system errors. /r also reads every sector to find bad ones and implies /f. On the system drive, Windows offers to schedule the check for the next restart, so tell the user before you say yes. A full /r pass reads the whole drive, which matters on a failing hard disk and takes hours while telling you little on an SSD. For an SSD, start with the SSD health check instead.

Diskpart is the sharpest tool in the box. It lists, selects and rewrites disks, and one wrong select is unrecoverable.

code
diskpart
list disk
select disk 1
detail disk
list volume

Stop at detail disk until the disk number, size and model match the one in the ticket. clean removes the partition table of the selected disk, and clean all zeroes every sector. If the repair order above leaves Windows unbootable, the guide to repairing Windows 11 covers the in-place options that keep user data.

Shutdown, Restart and Session Commands

Shutdown does more than power off. It restarts, logs off, hibernates, reboots into firmware and targets remote machines.

code
shutdown /r /t 0
shutdown /s /t 60 /c "Patching tonight, please save your work"
shutdown /a
shutdown /r /o /t 0
shutdown /r /fw /t 0
shutdown /r /m \\PC042 /t 300 /c "Security update" /d p:4:1

/a aborts a pending shutdown, and it has to run in a new window during the countdown. /r /o restarts into the advanced boot options menu, which is the route to Safe Mode when the machine will not offer it any other way. The Safe Mode on Windows 11 guide lists the other routes. /fw boots into the UEFI firmware screen on supported hardware. /d p:4:1 tags the restart as a planned security update in the event log.

One detail catches technicians out. Microsoft documents the /t default as 30 seconds, valid from 0 to 315360000, and states that if the timeout is greater than zero, /f is implied. A countdown with a friendly message still force-closes applications when it ends. Use /c to warn the user and give them enough time to save.

An r/sysadmin poster in April 2026 reported that shutdown /r /t 0 showed a one-minute warning on their machine while /t 1 restarted in a second. The thread is a reminder to test a restart command on one machine before you push it to a group.

Before you restart a shared machine or a terminal server, see who is on it. query user lists sessions and logoff ends one by ID.

code
query user /server:PC042
logoff 3 /server:PC042

Accounts, Elevation and Policy Commands

The net family covers local accounts and groups without opening a management console.

code
net user
net user jsmith /domain
net localgroup administrators
net localgroup administrators CONTOSO\jsmith /add
net user jsmith /active:no

Checking net localgroup administrators on a customer machine is a two-second audit. Unexpected members are worth a ticket of their own.

Runas starts a program under another account, which is how a technician opens a tool as the domain admin while the desktop stays signed in as the user.

code
runas /user:CONTOSO\admin cmd
runas /netonly /user:CONTOSO\admin "mmc dsa.msc"

/netonly uses the credentials only for network access, which is the right pattern for managing a domain from a machine that is not joined to it. Avoid /savecred. It stores the password in the credential manager, where any process running as that user can use it.

Group Policy refresh and troubleshooting sit here too. gpupdate /force reapplies policy, and gpresult /r shows which policies reached the user and the computer.

code
gpupdate /force
gpresult /r
gpresult /h C:\Temp\gp.html

When a setting will not apply, the HTML report from /h shows the winning policy and the ones that lost. The Group Policy guide explains the editor and the refresh behavior.

Chaining and Redirecting Output

Four operators turn single commands into checks.

code
ping -n 1 192.168.1.1 && echo Gateway up
ping -n 1 192.168.1.1 || echo Gateway down
ipconfig /flushdns & ipconfig /registerdns
tasklist | findstr /i "teams"

&& runs the second command only if the first succeeds. || runs it only if the first fails. A single & runs both whatever happens, and | feeds the output of the first into the second. Redirection saves a result for the ticket: > overwrites a file, >> appends and 2>&1 sends errors to the same place.

code
systeminfo > C:\Temp\PC042-systeminfo.txt
net localgroup administrators >> C:\Temp\PC042-audit.txt 2>&1

Every command also leaves an exit code in %errorlevel%, where 0 means success. echo %errorlevel% straight after a command tells you whether it worked when the output is ambiguous, and it is how scripts decide what to do next.

A for loop runs one command against a list. This one checks which machines in a text file answer:

code
for /f %i in (pcs.txt) do @ping -n 1 -w 500 %i >nul && (echo %i up) || (echo %i DOWN)

Typed at a prompt, the variable is %i. Inside a batch file it becomes %%i. That difference is a frequent reason a loop that works at the prompt fails in a script. Turning these one-liners into saved, reusable scripts is the job of our .bat file guide.

CMD Commands Cheat Sheet

New technicians learn faster from a walkthrough than from a reference. This one covers twenty commands, and the table after it holds the switches that matter.

TaskCommandNote
Elevation testnet session >nul 2>&1 && echo ElevatedFails without admin rights
Change drive and foldercd /d D:\Logs/d switches the drive too
Find filesdir /s /b *.logBare paths, all subfolders
Search inside filesfindstr /s /i /c:"text" *.configCase-insensitive
Copy foldersrobocopy src dst /e /r:1 /w:1Exit 0 to 7 is success
Network ladderping gateway, then ping 1.1.1.1, then nslookupEach rung rules out a layer
Who owns a portnetstat -ano | findstr :3389Then tasklist /fi "pid eq N"
Reset the stacknetsh winsock resetNeeds a restart
List processestasklist /v /fi "status eq not responding"/svc shows services
End a processtaskkill /f /t /im app.exe/t ends child processes
System inventorysysteminfoFilter with findstr
Serial numberpowershell -NoProfile -Command "(Get-CimInstance Win32_BIOS).SerialNumber"WMIC removed
Uptimesysteminfo | find "System Boot Time"No dedicated command
Repair Windows filesDISM /Online /Cleanup-Image /RestoreHealth then sfc /scannowElevated prompt
Check a diskchkdsk C: /fSchedules at restart on C:
Restart nowshutdown /r /t 0/t above 0 implies /f
Cancel a shutdownshutdown /aNew window, during countdown
Local adminsnet localgroup administratorsA quick audit
Run as another userrunas /netonly /user:DOMAIN\admin "cmd"Avoid /savecred
Refresh policygpupdate /forcegpresult /r shows results

Every command takes /? for its own switch list, and help prints the built-in commands. When a switch is hard to remember, taskkill /? is faster than a search.

When CMD Is the Wrong Tool

cmd.exe stops being the right tool when the output needs structure or the job needs scale. Asking for the five largest folders, comparing two lists or exporting results to CSV takes a screenful of findstr in cmd.exe and one line in PowerShell. The PowerShell commands guide is the sister reference to this one, sorted by ticket.

Scale is the other limit. Typing a command into 40 machines one at a time costs a morning, and a loop over a text file still needs credentials, reachability and error handling that a one-liner does not carry. A check you trust on one machine belongs in a script that runs across the fleet and collects the output. OpenFrame does this for a client's devices: it runs the script and returns the results in one place.

Before you run anything on a customer machine, work through this list.

  1. Run hostname and whoami, and confirm both match the ticket.
  2. Check elevation with the net session test, so a command does not fail halfway.
  3. Read the switches with /? for anything you have not run this month, especially /f, /mir and clean.
  4. Test a change on one machine before a group, including restart commands.
  5. Save the output with > and attach it to the ticket.

The commands themselves rarely change. The habits around them, such as confirming the target, reading the switches and keeping the output, are what separate a clean ticket from a long one.

Aliaska Varieva

Aliaska Varieva

Head of Platform

Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
cmd.exe is the Windows command interpreter. It reads commands typed at the Command Prompt or stored in a .bat file, runs them and prints the result as text. Built-in commands such as dir and cd live inside it, and most others, such as ping and taskkill, are separate programs in System32.
Press Win+R, type cmd and press Ctrl+Shift+Enter, or right-click Command Prompt in the Start menu and choose Run as administrator. The title bar reads Administrator: Command Prompt. Running net session confirms it, because the command only succeeds with admin rights.
Press Shift+F10 on any Windows Setup screen. Some laptops need Fn+Shift+F10. In the recovery environment, choose Troubleshoot, then Advanced options, then Command Prompt. Drive letters there can differ from the installed system, so check with diskpart and list volume first.
Microsoft removed WMIC from Windows 11 24H2 and later, and as of August 2026 it is no longer available as a Feature on Demand. From cmd.exe, run powershell -NoProfile -Command "(Get-CimInstance Win32_BIOS).SerialNumber". WMI itself is unaffected.
Run tasklist to find the image name or PID, then taskkill /im name.exe or taskkill /pid 1234. Add /f to force the process to end and /t to end its child processes. An access denied error means the prompt is not elevated or the process is protected.
Microsoft documents /t as the time-out in seconds, from 0 to 315360000, with a default of 30. A time-out above zero implies /f, which closes applications without warning. One r/sysadmin poster reported a one-minute warning on /t 0 in April 2026, so test a restart command on one machine first.