Updated: October 2026
Every technician's day still includes a black window. When the GUI hangs, the network drops or Windows Setup stalls, the fastest tool on the machine is a text prompt that has shipped with Windows for decades. This is a technician reference to cmd.exe: the commands for networking, processes, system info, disks, shutdown and permissions, with the switches and the ticket each one fits.
TL;DR
- cmd.exe is the Windows command interpreter. It matters because it opens in places the GUI and PowerShell do not: the Shift+F10 prompt in Windows Setup and the Command Prompt in the recovery environment.
- Only a handful of commands (dir, cd, copy, set, echo, for, if) live inside cmd.exe. The rest, such as ping, taskkill and shutdown, are programs in System32 that work the same from PowerShell.
- WMIC is gone from Windows 11 24H2 and 25H2 as of August 2026. Serial-number and uptime one-liners that used it now need Get-CimInstance or systeminfo.
- A timeout above zero on shutdown implies /f, so users lose unsaved work. Chain checks with && and || and pipe long output into findstr.
- Once the same command has to run on dozens of machines, move it to PowerShell or a script run across the fleet.
What cmd.exe Is and Where It Still Wins
cmd.exe is the Windows Command Processor. Typing cmd in the Run box starts it, and typing exit closes it. The window around it may be the classic console or Windows Terminal, which can host cmd.exe, PowerShell and WSL side by side. "Command prompt" is the name people use for the experience, and cmd.exe is the program behind it.
It handles text, not objects. Everything a command prints is a string, which is why the pipe into findstr is the main filtering tool. PowerShell passes objects with properties, which is why it wins at reporting. The PowerShell vs CMD comparison covers that split in depth.
Two facts decide when a technician reaches for cmd.exe. The first is location. Windows Setup opens a Command Prompt on Shift+F10, and the recovery environment offers one under Troubleshoot and Advanced options. Neither needs a working desktop. The second is portability. Every program in this guide is a standalone executable, so a one-liner pasted from a ticket note works from any shell, a remote console or an RMM script.
Opening cmd the Way a Technician Does
Press Win+R, type cmd and press Enter for a standard prompt. For an elevated one, type cmd in the Run box and press Ctrl+Shift+Enter, or right-click Command Prompt in Start and choose Run as administrator. The title bar then reads "Administrator: Command Prompt".
An unelevated prompt causes a long list of "access denied" tickets. This one-liner settles it, because net session only succeeds with admin rights:
codenet session >nul 2>&1 && echo Elevated || echo Not elevated
In Windows Setup or the first-run screens, press Shift+F10. Some laptops need Fn+Shift+F10. In the recovery environment, choose Command Prompt from Advanced options. Drive letters there often differ from the installed system, so find the Windows volume before running anything:
codediskpart list volume exit dir D:\Windows
Two launch switches are worth knowing. cmd /c <command> runs a command and exits, which is what scripts and scheduled tasks use. cmd /k <command> runs it and keeps the window open.
Navigation and File Commands
These are the commands behind every file hunt. cd /d changes drive and folder in one step, which plain cd does not.
codecd /d D:\Logs dir /a /o-d dir /s /b *.log tree /f C:\Users\jsmith\Desktop type app.log | findstr /i "error" findstr /s /i /c:"password" *.config where /r C:\ outlook.exe
dir /a shows hidden and system files, /o-d sorts newest first, and /s /b walks subfolders and prints bare paths. findstr takes a regular-expression subset and is the cmd.exe answer to grep.
For copying, use robocopy instead of copy or xcopy. It retries, resumes and logs.
coderobocopy C:\Users\jsmith D:\Backup\jsmith /e /r:1 /w:1 /log:C:\Temp\copy.log
/mir mirrors a folder and deletes anything in the destination that is missing from the source, so check the order of the two paths twice. Robocopy exit codes are bit flags: 0 to 7 mean the run succeeded in some form (0 nothing to copy, 1 files copied, 2 extra files in the destination), and 8 or higher means at least one failure.
Network Commands
Network tickets reward a fixed order, because each command rules out a layer. Start at the machine, move to the gateway, then the internet, then names.
codeping 127.0.0.1 ping 192.168.1.1 ping 1.1.1.1 ping example.com nslookup example.com
If the first ping fails, the TCP/IP stack on the machine is damaged. If the gateway fails, the problem is the cable, Wi-Fi or switch port. If the IP address works but the name does not, the cause is DNS, and nslookup example.com 1.1.1.1 shows whether a different resolver answers. The ipconfig commands guide covers the address side of this ladder, including what a 169.254 address means, so this guide stops short of repeating it.
The rest of the toolkit:
codeping -t 192.168.1.1 ping -n 20 -l 1472 -f 1.1.1.1 tracert -d 1.1.1.1 pathping -n 1.1.1.1 netstat -ano netstat -ano | findstr :3389 route print arp -a netsh winsock reset netsh int ip reset
ping -t runs until Ctrl+C, which is how you watch a flapping link while someone reseats a cable. -f with -l tests the path MTU by setting the don't-fragment bit with a payload size. tracert -d skips name lookups so the hops appear faster, and pathping adds per-hop loss statistics over a few minutes.
netstat -ano lists connections with the owning process ID. Pair it with tasklist to name the program: take the PID from the last column and run tasklist /fi "pid eq 4120". The two netsh resets repair a corrupted Winsock catalog and TCP/IP stack, and both need a restart to take effect.
Mapped drives are the other network job that lands in cmd.exe, through net use. The guide to mapping a network drive covers the GUI, CMD and GPO routes.
Process Commands: Tasklist and Taskkill
Tasklist shows what is running and taskkill ends it. Together they replace Task Manager on a machine too slow to open it, or on a remote session where you only have a prompt.
codetasklist tasklist /v /fi "status eq not responding" tasklist /svc /fi "imagename eq svchost.exe" tasklist /fi "memusage gt 500000"
/v adds window titles and status, /svc maps a process to the Windows services inside it, and /fi filters by image name, PID, status, memory and more. Memory in the filter is in kilobytes, so 500000 is roughly 500 MB.
Taskkill takes a name (/im) or a process ID (/pid).
codetaskkill /im outlook.exe taskkill /f /im outlook.exe taskkill /f /t /im teams.exe taskkill /fi "status eq not responding" /f taskkill /s PC042 /u CONTOSO\admin /im app.exe
Without /f, taskkill asks the program to close, and a hung program ignores the request. With /f, the process is ended forcefully and unsaved work in it is gone. /t ends the whole process tree, which matters for apps that spawn helpers and relaunch them. Microsoft's documentation notes that /f is ignored for remote processes, because all remote processes are forcefully ended.
"Access is denied" means the prompt is not elevated or the target is a protected system process. Do not push past the second case. Killing svchost.exe by name takes down every service hosted in it, and ending csrss.exe or wininit.exe crashes the machine.
The classic taskkill ticket is a frozen taskbar. Ending explorer.exe and starting it again fixes it without a reboot, and the guide to restarting Windows Explorer lists the steps and the failure cases.
System Info and Serial Number Commands
Systeminfo is the one-screen inventory: OS name and build, install date, boot time, hardware model, BIOS version, domain, logon server and the installed hotfixes. Filter it unless you want 70 lines.
codesysteminfo | findstr /b /c:"OS Name" /c:"OS Version" /c:"System Boot Time" systeminfo /s PC042 hostname whoami whoami /groups ver
Run hostname and whoami before anything destructive. They confirm which machine and which account the next command lands on, and the thirty seconds they cost beat a wrong-machine ticket.
Uptime has no dedicated command in cmd.exe. Two one-liners cover it:
codesysteminfo | find "System Boot Time" net statistics workstation | find "since"
Serial numbers were the job WMIC did best, and WMIC is now gone. Microsoft's deprecated-features page lists the utility as deprecated, and its August 2026 update states that WMIC is removed and no longer available as a Feature on Demand on Windows 11, version 24H2 and above. WMI itself is unaffected. Only the command-line tool left. The replacement is a one-line PowerShell call that works from a cmd.exe prompt:
code:: old way, fails on current Windows 11 wmic bios get serialnumber :: replacement, run from cmd.exe powershell -NoProfile -Command "(Get-CimInstance Win32_BIOS).SerialNumber" powershell -NoProfile -Command "(Get-CimInstance Win32_OperatingSystem).LastBootUpTime" powershell -NoProfile -Command "Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5"
On a white-box PC or a virtual machine, the serial field may read "To be filled by O.E.M." or a placeholder, because the manufacturer never wrote one. In that case the motherboard or hypervisor ID is the best identifier you have.
An r/sysadmin thread from August 2026 shows how the removal lands in practice. One administrator noticed WMIC missing after the Windows 11 preview updates and asked how to put it back, and replies in the thread say they have moved to gcim Win32_bios instead of fighting it.
Audit any old scripts and RMM tasks for wmic now. A script that quietly returned a serial number last year will return an error on the next build.
Disk and Repair Commands
Repair commands split into two families, and picking the wrong one wastes an hour. Suspect the disk when you see clicking, SMART warnings or file system errors. Suspect Windows files when you see crashes, failed updates or missing components.
For Windows files, run DISM first and sfc second. DISM repairs the component store, and sfc then repairs system files from that store.
codeDISM /Online /Cleanup-Image /RestoreHealth sfc /scannow
Both need an elevated prompt, and sfc logs its findings to C:\Windows\Logs\CBS\CBS.log. When DISM fails with a source error, the DISM RestoreHealth guide walks through the causes and the fixes.
For the disk, chkdsk checks the file system.
codechkdsk C: chkdsk C: /f chkdsk C: /r
Plain chkdsk C: is read-only and reports. /f fixes file system errors. /r also reads every sector to find bad ones and implies /f. On the system drive, Windows offers to schedule the check for the next restart, so tell the user before you say yes. A full /r pass reads the whole drive, which matters on a failing hard disk and takes hours while telling you little on an SSD. For an SSD, start with the SSD health check instead.
Diskpart is the sharpest tool in the box. It lists, selects and rewrites disks, and one wrong select is unrecoverable.
codediskpart list disk select disk 1 detail disk list volume
Stop at detail disk until the disk number, size and model match the one in the ticket. clean removes the partition table of the selected disk, and clean all zeroes every sector. If the repair order above leaves Windows unbootable, the guide to repairing Windows 11 covers the in-place options that keep user data.
Shutdown, Restart and Session Commands
Shutdown does more than power off. It restarts, logs off, hibernates, reboots into firmware and targets remote machines.
codeshutdown /r /t 0 shutdown /s /t 60 /c "Patching tonight, please save your work" shutdown /a shutdown /r /o /t 0 shutdown /r /fw /t 0 shutdown /r /m \\PC042 /t 300 /c "Security update" /d p:4:1
/a aborts a pending shutdown, and it has to run in a new window during the countdown. /r /o restarts into the advanced boot options menu, which is the route to Safe Mode when the machine will not offer it any other way. The Safe Mode on Windows 11 guide lists the other routes. /fw boots into the UEFI firmware screen on supported hardware. /d p:4:1 tags the restart as a planned security update in the event log.
One detail catches technicians out. Microsoft documents the /t default as 30 seconds, valid from 0 to 315360000, and states that if the timeout is greater than zero, /f is implied. A countdown with a friendly message still force-closes applications when it ends. Use /c to warn the user and give them enough time to save.
An r/sysadmin poster in April 2026 reported that shutdown /r /t 0 showed a one-minute warning on their machine while /t 1 restarted in a second. The thread is a reminder to test a restart command on one machine before you push it to a group.
Before you restart a shared machine or a terminal server, see who is on it. query user lists sessions and logoff ends one by ID.
codequery user /server:PC042 logoff 3 /server:PC042
Accounts, Elevation and Policy Commands
The net family covers local accounts and groups without opening a management console.
codenet user net user jsmith /domain net localgroup administrators net localgroup administrators CONTOSO\jsmith /add net user jsmith /active:no
Checking net localgroup administrators on a customer machine is a two-second audit. Unexpected members are worth a ticket of their own.
Runas starts a program under another account, which is how a technician opens a tool as the domain admin while the desktop stays signed in as the user.
coderunas /user:CONTOSO\admin cmd runas /netonly /user:CONTOSO\admin "mmc dsa.msc"
/netonly uses the credentials only for network access, which is the right pattern for managing a domain from a machine that is not joined to it. Avoid /savecred. It stores the password in the credential manager, where any process running as that user can use it.
Group Policy refresh and troubleshooting sit here too. gpupdate /force reapplies policy, and gpresult /r shows which policies reached the user and the computer.
codegpupdate /force gpresult /r gpresult /h C:\Temp\gp.html
When a setting will not apply, the HTML report from /h shows the winning policy and the ones that lost. The Group Policy guide explains the editor and the refresh behavior.
Chaining and Redirecting Output
Four operators turn single commands into checks.
codeping -n 1 192.168.1.1 && echo Gateway up ping -n 1 192.168.1.1 || echo Gateway down ipconfig /flushdns & ipconfig /registerdns tasklist | findstr /i "teams"
&& runs the second command only if the first succeeds. || runs it only if the first fails. A single & runs both whatever happens, and | feeds the output of the first into the second. Redirection saves a result for the ticket: > overwrites a file, >> appends and 2>&1 sends errors to the same place.
codesysteminfo > C:\Temp\PC042-systeminfo.txt net localgroup administrators >> C:\Temp\PC042-audit.txt 2>&1
Every command also leaves an exit code in %errorlevel%, where 0 means success. echo %errorlevel% straight after a command tells you whether it worked when the output is ambiguous, and it is how scripts decide what to do next.
A for loop runs one command against a list. This one checks which machines in a text file answer:
codefor /f %i in (pcs.txt) do @ping -n 1 -w 500 %i >nul && (echo %i up) || (echo %i DOWN)
Typed at a prompt, the variable is %i. Inside a batch file it becomes %%i. That difference is a frequent reason a loop that works at the prompt fails in a script. Turning these one-liners into saved, reusable scripts is the job of our .bat file guide.
CMD Commands Cheat Sheet
New technicians learn faster from a walkthrough than from a reference. This one covers twenty commands, and the table after it holds the switches that matter.
| Task | Command | Note |
|---|---|---|
| Elevation test | net session >nul 2>&1 && echo Elevated | Fails without admin rights |
| Change drive and folder | cd /d D:\Logs | /d switches the drive too |
| Find files | dir /s /b *.log | Bare paths, all subfolders |
| Search inside files | findstr /s /i /c:"text" *.config | Case-insensitive |
| Copy folders | robocopy src dst /e /r:1 /w:1 | Exit 0 to 7 is success |
| Network ladder | ping gateway, then ping 1.1.1.1, then nslookup | Each rung rules out a layer |
| Who owns a port | netstat -ano | findstr :3389 | Then tasklist /fi "pid eq N" |
| Reset the stack | netsh winsock reset | Needs a restart |
| List processes | tasklist /v /fi "status eq not responding" | /svc shows services |
| End a process | taskkill /f /t /im app.exe | /t ends child processes |
| System inventory | systeminfo | Filter with findstr |
| Serial number | powershell -NoProfile -Command "(Get-CimInstance Win32_BIOS).SerialNumber" | WMIC removed |
| Uptime | systeminfo | find "System Boot Time" | No dedicated command |
| Repair Windows files | DISM /Online /Cleanup-Image /RestoreHealth then sfc /scannow | Elevated prompt |
| Check a disk | chkdsk C: /f | Schedules at restart on C: |
| Restart now | shutdown /r /t 0 | /t above 0 implies /f |
| Cancel a shutdown | shutdown /a | New window, during countdown |
| Local admins | net localgroup administrators | A quick audit |
| Run as another user | runas /netonly /user:DOMAIN\admin "cmd" | Avoid /savecred |
| Refresh policy | gpupdate /force | gpresult /r shows results |
Every command takes /? for its own switch list, and help prints the built-in commands. When a switch is hard to remember, taskkill /? is faster than a search.
When CMD Is the Wrong Tool
cmd.exe stops being the right tool when the output needs structure or the job needs scale. Asking for the five largest folders, comparing two lists or exporting results to CSV takes a screenful of findstr in cmd.exe and one line in PowerShell. The PowerShell commands guide is the sister reference to this one, sorted by ticket.
Scale is the other limit. Typing a command into 40 machines one at a time costs a morning, and a loop over a text file still needs credentials, reachability and error handling that a one-liner does not carry. A check you trust on one machine belongs in a script that runs across the fleet and collects the output. OpenFrame does this for a client's devices: it runs the script and returns the results in one place.
Before you run anything on a customer machine, work through this list.
- Run
hostnameandwhoami, and confirm both match the ticket. - Check elevation with the
net sessiontest, so a command does not fail halfway. - Read the switches with
/?for anything you have not run this month, especially/f,/mirandclean. - Test a change on one machine before a group, including restart commands.
- Save the output with
>and attach it to the ticket.
The commands themselves rarely change. The habits around them, such as confirming the target, reading the switches and keeping the output, are what separate a clean ticket from a long one.

Aliaska Varieva
Head of Platform
Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.
