Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
CMD is still included in Windows 11 and Windows Server 2025. It has not been removed or replaced by a new 2025 command interpreter. For authorized security work, cmd.exe is useful for identifying the current security context, checking system configuration, reviewing processes, diagnosing DNS, and testing basic network reachability.
This list uses “hacking” in the legitimate security-testing sense: troubleshooting systems you own or have explicit permission to assess. These commands are mainly reconnaissance and diagnostics. They do not bypass authentication, exploit vulnerabilities, or prove that a machine or service is secure.
Open Command Prompt normally for read-only checks. Use Run as administrator only when a command or the investigation genuinely requires an elevated token. Results can differ between an ordinary and elevated CMD session.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsCMD commands for authorized security diagnostics
The most useful commands are not necessarily the most dramatic ones. A good Windows investigation starts by answering five practical questions:
#1 Best Overall
- Which account and privileges am I using?
- What operating system and configuration does the host have?
- Which processes and services are running?
- What network and DNS settings are active?
- Can the intended host be resolved and reached?
The commands below map to those questions.
1. whoami: identify the current security context
Before interpreting any result, establish who CMD is running as. Windows can return different information in a standard session and an elevated session.
whoami
whoami /user
whoami /groups
whoami /priv
whoami /all
| Command | What it shows |
|---|---|
whoami |
The current domain and username |
whoami /user |
The account, domain, and security identifier (SID) |
whoami /groups |
Groups in the current access token |
whoami /priv |
Privileges in the current token |
whoami /all |
All supported account, group, privilege, and claim information |
For a script-friendly report, use:
whoami /all /fo csv /nh
/fo supports table, list, and csv. The /nh switch removes column headings and works with table and CSV output.
Important limitation
whoami /priv displays privileges in the current access token; it does not grant administrator rights. A listed privilege also does not automatically mean that every privileged operation will succeed. Record whether the command was run in an elevated window.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute2. systeminfo: collect host and operating-system details
systeminfo produces a broad inventory of the operating system, hardware, security configuration, and related system information.
systeminfo
systeminfo /fo list
systeminfo /fo csv /nh
The list format is easier to read when collecting evidence manually. CSV is more convenient when importing results into another tool or combining reports from multiple authorized systems.
Microsoft also documents remote syntax:
systeminfo /s COMPUTER-NAME
systeminfo /s 192.0.2.25 /u CONTOSO analyst
Do not assume that a reachable address makes a remote query possible. Remote execution can fail because of name resolution, authentication, permissions, firewall rules, or RPC/WMI-related restrictions. The remote computer name or IP address should not contain backslashes.
Do not put real passwords in the command line
The documented syntax supports /p <password>, but entering a password there can expose it through command history, process inspection, logging, or a screenshot. It is safer to use an approved credential-handling process instead of embedding credentials in a command.
3. tasklist: review running processes
Use tasklist to see which processes are running and, when useful, which services are hosted inside them.
tasklist
tasklist /v
tasklist /svc
tasklist /fo list
tasklist /fo csv /nh
Useful filters include:
tasklist /fi "STATUS eq running"
tasklist /fi "USERNAME ne NT AUTHORITYSYSTEM" /fi "STATUS eq running"
tasklist /m example.dll
| Option | Use |
|---|---|
/v |
Shows verbose task information |
/svc |
Shows services hosted by each process |
/m module.dll |
Lists processes using a specified DLL module |
/fi |
Applies a process filter; multiple filters can be supplied |
/fo csv /nh |
Produces headerless CSV output |
A process name is only a starting point. A familiar name can be abused by a malicious executable, while a legitimate process may have details unavailable without elevation. Confirm suspicious findings with the executable path, signature, parent process, service association, and endpoint telemetry.
tasklist is the current documented replacement for the older tlist tool. Use tasklist in current Windows procedures.
4. ipconfig: inspect the local network configuration
Start with the basic output:
ipconfig
ipconfig /all
The short form shows IPv4 and IPv6 addresses, subnet masks, and default gateways. The /all form adds the full TCP/IP configuration for each adapter, including information useful when investigating DHCP, DNS, VPN, and virtual-network problems.
Recommended Free Tools
For DNS-related checks, use:
ipconfig /displaydns
ipconfig /flushdns
ipconfig /registerdns
/displaydnsdisplays the local DNS resolver cache./flushdnsclears that local cache./registerdnsinitiates DNS registration for configured DNS names.
DHCP troubleshooting commands include:
ipconfig /release
ipconfig /renew
ipconfig /release6
ipconfig /renew6
Release and renew are primarily meaningful for DHCP-configured interfaces. They do not obtain a new lease for a statically configured address. They can also temporarily interrupt connectivity, so avoid using them during a production incident without understanding the effect.
What ipconfig /flushdns does not do
It clears the local resolver cache only. It does not modify authoritative DNS records, change the configured DNS server, or clear caches on other machines. If the wrong DNS answer persists, compare results with nslookup against the configured resolver and another approved DNS server.
5. ping: test ICMP reachability
ping sends ICMP Echo Requests and waits for Echo Replies. A short test is:
Rank #3
ping example.microsoft.com
ping /n 10 /w 1000 192.0.2.25
ping /4 hostname
ping /6 hostname
The default wait time is 4,000 milliseconds. Use /n to choose the number of requests and /w to set the timeout in milliseconds. The /4 and /6 switches force IPv4 or IPv6 when the target is a hostname.
Free tools Windows power users keep installed
One-click scans. No signup required.
You can ask Windows to resolve an address to a name:
ping /a 192.0.2.25
For route-related diagnostics, Microsoft documents /r for recording an IPv4 route and /R for tracing the IPv6 round-trip path.
What ping proves—and what it does not
A successful reply shows that an ICMP exchange succeeded. It does not prove that a TCP or UDP service port is open. Conversely, “Request timed out” does not prove that the host is offline: a destination or intermediate firewall may block, filter, or rate-limit ICMP.
A useful comparison is:
ping 192.0.2.25
ping server.example.com
If the IP address responds but the hostname does not resolve or reaches a different address, investigate DNS, the Hosts file, VPN settings, or name-resolution behavior.
6. nslookup: investigate DNS answers
Use nslookup when you need to separate DNS problems from general connectivity problems.
nslookup example.com
nslookup example.com 1.1.1.1
nslookup -type=A example.com
nslookup -type=AAAA example.com
The first form uses the default DNS server. The second explicitly queries the DNS server at 1.1.1.1. The record-specific forms request IPv4 A records or IPv6 AAAA records.
For more detailed testing:
nslookup -debug -type=A+AAAA -nosearch -recurse example.com 1.1.1.1
Running nslookup without arguments starts interactive mode:
nslookup
set all
server 1.1.1.1
set type=HINFO
example.com
exit
Results can differ between DNS servers because of split DNS, VPN configuration, search lists, recursion policy, caching, and access restrictions. A successful lookup proves that a DNS server returned an answer; it does not prove that the resulting host is reachable or that a service accepts connections.
Do not treat nslookup as a domain dump tool
The command supports an ls subcommand, but that does not mean every DNS server allows zone transfers or full-domain listing. Record types must be requested, and the server decides what it will return. nslookup is a diagnostic query tool, not a general vulnerability scanner.
7. cmd: control how a command runs
The cmd command starts a new command-interpreter instance. It is especially useful when a script needs a clean, predictable child CMD process.
cmd /c whoami
cmd /k ipconfig /all
cmd /d /c systeminfo
| Switch | Behavior |
|---|---|
/c |
Runs the supplied command and exits |
/k |
Runs the supplied command and keeps CMD open |
/d |
Disables configured CMD AutoRun commands |
/q |
Turns command echoing off |
/v:on |
Enables delayed environment-variable expansion |
/e:off |
Disables command extensions |
The /d switch matters in repeatable diagnostics because, without it, configured AutoRun commands may execute whenever a new CMD instance starts. The /s switch changes quote-stripping rules when used with /c or /k, so quoted paths should be tested carefully.
CMD is not PowerShell. PowerShell cmdlets, object pipelines, and PowerShell quoting do not automatically work in a CMD window. Microsoft recommends PowerShell for more advanced scripting and automation, while CMD remains useful for these compact built-in checks.
A practical, low-impact investigation sequence
For an authorized workstation or server review, run the following sequence and save the output through your organization’s approved evidence process:
Best Value
cmd /d /c whoami /all— record the account, groups, claims, and token privileges without CMD AutoRun commands.systeminfo /fo list— record the operating-system and host baseline.ipconfig /all— identify active, virtual, VPN, DHCP, gateway, and DNS configuration.nslookup hostname— check how the configured DNS server resolves the target.ping /n 4 hostname— test basic ICMP reachability, while remembering that ICMP may be filtered.tasklist /svc— associate running processes with hosted services.
Repeat remote commands only where remote administration is explicitly authorized. A failed remote query is not automatically evidence of a compromised or offline host; it may reflect authentication, firewall, RPC, or permission policy.
Common mistakes in CMD-based security checks
| Incorrect assumption | More accurate interpretation |
|---|---|
| Ping checks whether a port is open. | Ping tests ICMP echo reachability, not TCP or UDP service ports. |
| A failed ping means the computer is offline. | ICMP may be blocked, filtered, or rate-limited. |
ipconfig /flushdns fixes DNS everywhere. |
It clears only the local resolver cache. |
whoami /priv grants administrator privileges. |
It only reports privileges in the current token. |
| A process name proves an executable is legitimate. | Verify its path, signature, parent, service relationship, and telemetry. |
systeminfo /s works against any reachable IP. |
Remote access also requires suitable authentication, permissions, firewall policy, and infrastructure. |
| CMD was removed from Windows 11. | Microsoft continues to document CMD for Windows 11 and Windows Server 2025. |
FAQ
Is CMD still available in Windows 11 in 2025?
Yes. Microsoft’s current documentation lists CMD and these command references for Windows 11, Windows 10, Windows Server 2025, and several earlier Windows Server versions. Microsoft recommends PowerShell for more advanced automation, but CMD remains available.
Which CMD command shows my current Windows privileges?
Use whoami /priv. It reports privileges in the current access token. It does not grant administrator rights, and an elevated CMD session can produce different results from a normal session.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Can ping tell me whether a port is open?
No. ping uses ICMP Echo Requests and Replies. A successful ping does not prove that a TCP or UDP service port is accepting connections, and a failed ping may simply mean ICMP is filtered.
Does ipconfig /flushdns clear DNS for the whole network?
No. It clears the local Windows DNS resolver cache. It does not change authoritative DNS records, remote caches, or the DNS configuration on other devices.
Why does systeminfo /s fail against a reachable computer?
Remote queries depend on more than reachability. Authentication, permissions, firewall rules, name or address resolution, and RPC/WMI-related access restrictions can all cause failure.
Can nslookup list every DNS record for a domain?
Not automatically. You must request record types, and the DNS server controls what it returns. The documented ls function does not guarantee that zone transfers or full-domain listing are permitted.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Should I use tlist or tasklist on current Windows systems?
Use tasklist. Microsoft documents it as replacing the older tlist tool.
The Bottom Line
The strongest CMD workflow for authorized Windows security diagnostics is simple: establish the token with whoami, inventory the host with systeminfo, inspect processes with tasklist, examine interfaces and DNS settings with ipconfig, then separate name resolution from ICMP reachability with nslookup and ping. Treat every result in context—especially remote failures, blocked ICMP, cached DNS answers, and process names that have not been verified.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

