Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

CMD is still included in Windows 11 and Windows Server 2025. It has not been removed or replaced by a new 2025 command interpreter. For authorized security work, cmd.exe is useful for identifying the current security context, checking system configuration, reviewing processes, diagnosing DNS, and testing basic network reachability.

This list uses “hacking” in the legitimate security-testing sense: troubleshooting systems you own or have explicit permission to assess. These commands are mainly reconnaissance and diagnostics. They do not bypass authentication, exploit vulnerabilities, or prove that a machine or service is secure.

Open Command Prompt normally for read-only checks. Use Run as administrator only when a command or the investigation genuinely requires an elevated token. Results can differ between an ordinary and elevated CMD session.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CMD commands for authorized security diagnostics

The most useful commands are not necessarily the most dramatic ones. A good Windows investigation starts by answering five practical questions:

  1. Which account and privileges am I using?
  2. What operating system and configuration does the host have?
  3. Which processes and services are running?
  4. What network and DNS settings are active?
  5. Can the intended host be resolved and reached?

The commands below map to those questions.

1. whoami: identify the current security context

Before interpreting any result, establish who CMD is running as. Windows can return different information in a standard session and an elevated session.

whoami
whoami /user
whoami /groups
whoami /priv
whoami /all
Command What it shows
whoami The current domain and username
whoami /user The account, domain, and security identifier (SID)
whoami /groups Groups in the current access token
whoami /priv Privileges in the current token
whoami /all All supported account, group, privilege, and claim information

For a script-friendly report, use:

whoami /all /fo csv /nh

/fo supports table, list, and csv. The /nh switch removes column headings and works with table and CSV output.

Important limitation

whoami /priv displays privileges in the current access token; it does not grant administrator rights. A listed privilege also does not automatically mean that every privileged operation will succeed. Record whether the command was run in an elevated window.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. systeminfo: collect host and operating-system details

systeminfo produces a broad inventory of the operating system, hardware, security configuration, and related system information.

systeminfo
systeminfo /fo list
systeminfo /fo csv /nh

The list format is easier to read when collecting evidence manually. CSV is more convenient when importing results into another tool or combining reports from multiple authorized systems.

Microsoft also documents remote syntax:

systeminfo /s COMPUTER-NAME
systeminfo /s 192.0.2.25 /u CONTOSO analyst

Do not assume that a reachable address makes a remote query possible. Remote execution can fail because of name resolution, authentication, permissions, firewall rules, or RPC/WMI-related restrictions. The remote computer name or IP address should not contain backslashes.

Do not put real passwords in the command line

The documented syntax supports /p <password>, but entering a password there can expose it through command history, process inspection, logging, or a screenshot. It is safer to use an approved credential-handling process instead of embedding credentials in a command.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. tasklist: review running processes

Use tasklist to see which processes are running and, when useful, which services are hosted inside them.

tasklist
tasklist /v
tasklist /svc
tasklist /fo list
tasklist /fo csv /nh

Useful filters include:

tasklist /fi "STATUS eq running"
tasklist /fi "USERNAME ne NT AUTHORITYSYSTEM" /fi "STATUS eq running"
tasklist /m example.dll
Option Use
/v Shows verbose task information
/svc Shows services hosted by each process
/m module.dll Lists processes using a specified DLL module
/fi Applies a process filter; multiple filters can be supplied
/fo csv /nh Produces headerless CSV output

A process name is only a starting point. A familiar name can be abused by a malicious executable, while a legitimate process may have details unavailable without elevation. Confirm suspicious findings with the executable path, signature, parent process, service association, and endpoint telemetry.

tasklist is the current documented replacement for the older tlist tool. Use tasklist in current Windows procedures.

4. ipconfig: inspect the local network configuration

Start with the basic output:

ipconfig
ipconfig /all

The short form shows IPv4 and IPv6 addresses, subnet masks, and default gateways. The /all form adds the full TCP/IP configuration for each adapter, including information useful when investigating DHCP, DNS, VPN, and virtual-network problems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For DNS-related checks, use:

ipconfig /displaydns
ipconfig /flushdns
ipconfig /registerdns
  • /displaydns displays the local DNS resolver cache.
  • /flushdns clears that local cache.
  • /registerdns initiates DNS registration for configured DNS names.

DHCP troubleshooting commands include:

ipconfig /release
ipconfig /renew
ipconfig /release6
ipconfig /renew6

Release and renew are primarily meaningful for DHCP-configured interfaces. They do not obtain a new lease for a statically configured address. They can also temporarily interrupt connectivity, so avoid using them during a production incident without understanding the effect.

What ipconfig /flushdns does not do

It clears the local resolver cache only. It does not modify authoritative DNS records, change the configured DNS server, or clear caches on other machines. If the wrong DNS answer persists, compare results with nslookup against the configured resolver and another approved DNS server.

5. ping: test ICMP reachability

ping sends ICMP Echo Requests and waits for Echo Replies. A short test is:

ping example.microsoft.com
ping /n 10 /w 1000 192.0.2.25
ping /4 hostname
ping /6 hostname

The default wait time is 4,000 milliseconds. Use /n to choose the number of requests and /w to set the timeout in milliseconds. The /4 and /6 switches force IPv4 or IPv6 when the target is a hostname.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You can ask Windows to resolve an address to a name:

ping /a 192.0.2.25

For route-related diagnostics, Microsoft documents /r for recording an IPv4 route and /R for tracing the IPv6 round-trip path.

What ping proves—and what it does not

A successful reply shows that an ICMP exchange succeeded. It does not prove that a TCP or UDP service port is open. Conversely, “Request timed out” does not prove that the host is offline: a destination or intermediate firewall may block, filter, or rate-limit ICMP.

A useful comparison is:

ping 192.0.2.25
ping server.example.com

If the IP address responds but the hostname does not resolve or reaches a different address, investigate DNS, the Hosts file, VPN settings, or name-resolution behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. nslookup: investigate DNS answers

Use nslookup when you need to separate DNS problems from general connectivity problems.

nslookup example.com
nslookup example.com 1.1.1.1
nslookup -type=A example.com
nslookup -type=AAAA example.com

The first form uses the default DNS server. The second explicitly queries the DNS server at 1.1.1.1. The record-specific forms request IPv4 A records or IPv6 AAAA records.

For more detailed testing:

nslookup -debug -type=A+AAAA -nosearch -recurse example.com 1.1.1.1

Running nslookup without arguments starts interactive mode:

nslookup
set all
server 1.1.1.1
set type=HINFO
example.com
exit

Results can differ between DNS servers because of split DNS, VPN configuration, search lists, recursion policy, caching, and access restrictions. A successful lookup proves that a DNS server returned an answer; it does not prove that the resulting host is reachable or that a service accepts connections.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not treat nslookup as a domain dump tool

The command supports an ls subcommand, but that does not mean every DNS server allows zone transfers or full-domain listing. Record types must be requested, and the server decides what it will return. nslookup is a diagnostic query tool, not a general vulnerability scanner.

7. cmd: control how a command runs

The cmd command starts a new command-interpreter instance. It is especially useful when a script needs a clean, predictable child CMD process.

cmd /c whoami
cmd /k ipconfig /all
cmd /d /c systeminfo
Switch Behavior
/c Runs the supplied command and exits
/k Runs the supplied command and keeps CMD open
/d Disables configured CMD AutoRun commands
/q Turns command echoing off
/v:on Enables delayed environment-variable expansion
/e:off Disables command extensions

The /d switch matters in repeatable diagnostics because, without it, configured AutoRun commands may execute whenever a new CMD instance starts. The /s switch changes quote-stripping rules when used with /c or /k, so quoted paths should be tested carefully.

CMD is not PowerShell. PowerShell cmdlets, object pipelines, and PowerShell quoting do not automatically work in a CMD window. Microsoft recommends PowerShell for more advanced scripting and automation, while CMD remains useful for these compact built-in checks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A practical, low-impact investigation sequence

For an authorized workstation or server review, run the following sequence and save the output through your organization’s approved evidence process:

  1. cmd /d /c whoami /all — record the account, groups, claims, and token privileges without CMD AutoRun commands.
  2. systeminfo /fo list — record the operating-system and host baseline.
  3. ipconfig /all — identify active, virtual, VPN, DHCP, gateway, and DNS configuration.
  4. nslookup hostname — check how the configured DNS server resolves the target.
  5. ping /n 4 hostname — test basic ICMP reachability, while remembering that ICMP may be filtered.
  6. tasklist /svc — associate running processes with hosted services.

Repeat remote commands only where remote administration is explicitly authorized. A failed remote query is not automatically evidence of a compromised or offline host; it may reflect authentication, firewall, RPC, or permission policy.

Common mistakes in CMD-based security checks

Incorrect assumption More accurate interpretation
Ping checks whether a port is open. Ping tests ICMP echo reachability, not TCP or UDP service ports.
A failed ping means the computer is offline. ICMP may be blocked, filtered, or rate-limited.
ipconfig /flushdns fixes DNS everywhere. It clears only the local resolver cache.
whoami /priv grants administrator privileges. It only reports privileges in the current token.
A process name proves an executable is legitimate. Verify its path, signature, parent, service relationship, and telemetry.
systeminfo /s works against any reachable IP. Remote access also requires suitable authentication, permissions, firewall policy, and infrastructure.
CMD was removed from Windows 11. Microsoft continues to document CMD for Windows 11 and Windows Server 2025.

FAQ

Is CMD still available in Windows 11 in 2025?

Yes. Microsoft’s current documentation lists CMD and these command references for Windows 11, Windows 10, Windows Server 2025, and several earlier Windows Server versions. Microsoft recommends PowerShell for more advanced automation, but CMD remains available.

Which CMD command shows my current Windows privileges?

Use whoami /priv. It reports privileges in the current access token. It does not grant administrator rights, and an elevated CMD session can produce different results from a normal session.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can ping tell me whether a port is open?

No. ping uses ICMP Echo Requests and Replies. A successful ping does not prove that a TCP or UDP service port is accepting connections, and a failed ping may simply mean ICMP is filtered.

Does ipconfig /flushdns clear DNS for the whole network?

No. It clears the local Windows DNS resolver cache. It does not change authoritative DNS records, remote caches, or the DNS configuration on other devices.

Why does systeminfo /s fail against a reachable computer?

Remote queries depend on more than reachability. Authentication, permissions, firewall rules, name or address resolution, and RPC/WMI-related access restrictions can all cause failure.

Can nslookup list every DNS record for a domain?

Not automatically. You must request record types, and the DNS server controls what it returns. The documented ls function does not guarantee that zone transfers or full-domain listing are permitted.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Should I use tlist or tasklist on current Windows systems?

Use tasklist. Microsoft documents it as replacing the older tlist tool.

The Bottom Line

The strongest CMD workflow for authorized Windows security diagnostics is simple: establish the token with whoami, inventory the host with systeminfo, inspect processes with tasklist, examine interfaces and DNS settings with ipconfig, then separate name resolution from ICMP reachability with nslookup and ping. Treat every result in context—especially remote failures, blocked ICMP, cached DNS answers, and process names that have not been verified.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.