Posts

Capture Network Packet trace in Windows 2016

#Initial command : netsh trace start persistent=yes capture=yes IPv4.Address=X.X.X.X tracefile=c:\temp\nettrace-boot.etl  #Stop command: netsh trace stop Open the ETL file in Microsoft Message Analyzer Ref : https://techcommunity.microsoft.com/t5/iis-support-blog/capture-a-network-trace-without-installing-anything-amp-capture/ba-p/376503

Get startup folder of current user and all users - Windows 2012, 2016,2019

Run -> shell:startup - for current user Run -> shell:common startup - for all users

WSUS configurations

wsus client configuration Registry: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windows\WindowsUpdate\ Windows update log path (obselete): c:\windows\windowsupdate.log Powershell : Get-WindowsUpdateLog Installing updates: Using Powershell: Install-Module PSWindowsUpdate #- to install the Windows update module Get-WindowsUpdate #- to check for updates Install-WindowsUpdate #- to install the available updates Older version windows (Without PowerShell module): wuauclt /detectnow - to check for updates wuauclt /updatenow - to start installing the detected updates wuauclt /detectnow /updatenow - to check, download and install updates wuauclt /reportnow # TBC wuauclt /detectnow /updatenow /reportnow # TBC For Windows 10 computers, rather than use WUAUCLT.EXE you need to use UsoClient.exe. This exe is located in System32 and you can use the following strings. StartScan - Used To Start Scan StartDownload - Used to Start Download of Patches StartInstall - Used to Install Downloaded...

View PowerShell commands executed history

Look at below files at the below location to view the PowerShell commands executed history: ConsoleHost_history.txt Visual Studio Code Host_history.txt C:\Users\<UserName>\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine

Changing the name of 'My Computer' icon on the Desktop

Update below registry value to reflect the 'My Computer' icon name in the Desktop: HKEY_USERS\S-1-5-21-1343024091-764733703-725345543-71394\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D} key: (Default) Value: Computer name Split for easy lookup: HKEY_USERS\ S-1-5-21-1343024091-764733703-725345543-71394\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ CLSID\ {20D04FE0-3AEA-1069-A2D8-08002B30309D} PowerShell one-liner: set-itemproperty - path 'registry::HKEY_USERS\S-1-5-21-1343024091-764733703-725345543-71394\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}' - name '(Default)' - value $ ( $env:computername )

Find Windows Product Keys

 Ways to find Windows Product Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform , find value of BackupProductKeyDefault (Not working) Find Product Key Using CMD: wmic path softwarelicensingservice get OA3xOriginalProductKey (Not working) powershell: "(Get-WmiObject -query ‘select * from SoftwareLicensingService’).OA3xOriginalProductKey" (Not working) Registry: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DigitalProductId

Get wifi password (connected wifi connection) from command line

Image
 Execute below command, and look for value in the output: "key content" under "security settings" netsh.exe wlan show profiles name=’Profile Name’ key=clear Sample output: Ref:  Get Wireless Network SSID and Password with PowerShell - Scripting Blog (microsoft.com)