CMD
Windows Command Prompt: Classic Windows command-line interpreter. Essential for batch scripting and system administration.
HELP#
command /? # Help for command help # List built-in commands where command # Find command location
NAVIGATION#
cd # Current directory cd \ # Go to root cd .. # Parent directory cd path\to\folder # Change directory cd /d D:\path # Change drive and directory pushd path # Save current dir, change to path popd # Return to saved directory
DIRECTORY LISTING#
dir # List directory dir /a # Show all (including hidden) dir /ah # Hidden files only dir /s # Recursive listing dir /b # Bare format (names only) dir /o:s # Order by size dir /o:d # Order by date dir /o:-d # Order by date descending dir /q # Show owner dir *.txt # Filter by extension dir /s /b *.exe # Find all exe files
WILDCARDS#
* # Match any characters ? # Match single character dir *.txt # All txt files dir file?.txt # file1.txt, file2.txt, etc. dir ???.* # 3 character names
FILE OPERATIONS#
copy src dest # Copy file copy file1+file2 merged # Concatenate files copy /y src dest # Copy without confirm xcopy src dest /s # Copy with subdirs xcopy src dest /e # Include empty dirs xcopy src dest /h # Include hidden xcopy src dest /c # Continue on error robocopy src dest # Robust copy (better) move src dest # Move/rename file ren oldname newname # Rename file rename oldname newname # Rename file del file.txt # Delete file del /f file.txt # Force delete del /s /q folder\* # Delete all in folder del /a:h file # Delete hidden file erase file.txt # Same as del
DIRECTORY OPERATIONS#
mkdir foldername # Create directory md foldername # Create directory mkdir path\to\nested # Create nested dirs rmdir foldername # Remove empty directory rmdir /s foldername # Remove with contents rmdir /s /q foldername # Remove without confirm rd /s /q foldername # Short form
FILE ATTRIBUTES#
attrib file.txt # Show attributes attrib +h file.txt # Set hidden attrib -h file.txt # Remove hidden attrib +r file.txt # Set read-only attrib +s file.txt # Set system attrib -r -h -s file.txt # Remove all attrib /s /d +h folder\* # Recursive # Attributes: R=ReadOnly H=Hidden S=System A=Archive
FILE CONTENT#
type file.txt # Display file contents type file.txt | more # Page by page more file.txt # Page by page echo text > file.txt # Write to file (overwrite) echo text >> file.txt # Append to file copy con file.txt # Type content, Ctrl+Z to save
SEARCHING#
find "text" file.txt # Search in file find /i "text" file.txt # Case insensitive find /c "text" file.txt # Count occurrences find /n "text" file.txt # Show line numbers find /v "text" file.txt # Lines NOT containing findstr "text" file.txt # Regex search findstr /i "text" file.txt # Case insensitive findstr /r "pattern" file.txt # Regex pattern findstr /s "text" *.txt # Recursive search findstr /m "text" *.txt # Files names only findstr /n "text" file.txt # Line numbers findstr /c:"exact phrase" file.txt # Literal string # Find files dir /s /b *filename* # Find file by name where /r C:\ filename.exe # Find executable
PROCESS MANAGEMENT#
tasklist # List processes tasklist /v # Verbose (window titles) tasklist /svc # Show services tasklist /m # Show loaded DLLs tasklist /fi "imagename eq cmd.exe" # Filter by name tasklist /fi "pid eq 1234" # Filter by PID tasklist /fi "status eq running" # Filter by status taskkill /pid 1234 # Kill by PID taskkill /im notepad.exe # Kill by name taskkill /f /pid 1234 # Force kill taskkill /f /im chrome.exe # Force kill all chrome taskkill /t /pid 1234 # Kill process tree start notepad.exe # Start program start "" "C:\path with spaces\app.exe" start /min notepad.exe # Start minimized start /max notepad.exe # Start maximized start /wait program.exe # Wait for completion
NETWORK#
ipconfig # IP configuration ipconfig /all # Detailed info ipconfig /release # Release DHCP ipconfig /renew # Renew DHCP ipconfig /flushdns # Clear DNS cache ipconfig /displaydns # Show DNS cache ping host # Ping host ping -t host # Continuous ping ping -n 10 host # 10 pings ping -l 1000 host # Packet size 1000 tracert host # Traceroute pathping host # Path and latency nslookup domain # DNS lookup nslookup -type=mx domain # MX records nslookup -type=ns domain # NS records nslookup domain 8.8.8.8 # Use specific DNS netstat -a # All connections netstat -an # Numeric addresses netstat -ano # With PIDs netstat -b # Show executables netstat -r # Routing table arp -a # ARP table route print # Routing table hostname # Show hostname net view # Network computers net view \\computer # Shared resources net use # Mapped drives net use Z: \\server\share # Map drive net use Z: /delete # Unmap drive net use \\server\share /user:domain\user password
SERVICES#
sc query # List services sc query servicename # Service status sc start servicename # Start service sc stop servicename # Stop service sc config servicename start=auto # Set auto start sc config servicename start=disabled # Disable service sc qc servicename # Service config sc delete servicename # Delete service net start # Running services net start servicename # Start service net stop servicename # Stop service
USERS & GROUPS#
net user # List users net user username # User info net user username password /add # Create user net user username /delete # Delete user net user username /active:yes # Enable user net user username /active:no # Disable user net localgroup # List groups net localgroup groupname # Group members net localgroup administrators user /add net localgroup administrators user /delete whoami # Current user whoami /all # User SID, groups, privileges whoami /priv # Privileges whoami /groups # Group memberships
SYSTEM INFO#
systeminfo # System information systeminfo | findstr /i "boot" # Boot time hostname # Computer name ver # Windows version date # Current date time # Current time set # Environment variables wmic os get caption,version # OS version wmic computersystem get model,manufacturer wmic bios get serialnumber # Serial number wmic cpu get name # CPU info wmic memorychip get capacity # RAM info
SCHEDULED TASKS#
schtasks /query # List tasks schtasks /query /tn "taskname" # Specific task schtasks /query /fo list /v # Verbose list schtasks /run /tn "taskname" # Run task schtasks /end /tn "taskname" # Stop task schtasks /delete /tn "taskname" /f # Delete task # Create scheduled task schtasks /create /tn "MyTask" /tr "C:\script.bat" /sc daily /st 09:00
DISK OPERATIONS#
chkdsk C: # Check disk chkdsk C: /f # Fix errors chkdsk C: /r # Locate bad sectors diskpart # Disk partitioning fsutil fsinfo drives # List drives fsutil volume diskfree C: # Disk free space label D: NewLabel # Change volume label
REDIRECTION & PIPES#
command > file.txt # Output to file (overwrite) command >> file.txt # Append to file command < file.txt # Input from file command 2> error.txt # Stderr to file command > file.txt 2>&1 # Both stdout and stderr command | command2 # Pipe output command && command2 # Run if success command || command2 # Run if failure command & command2 # Run both
BATCH SCRIPTING#
@echo off # Disable command echo echo message # Print message pause # Wait for keypress exit # Exit script exit /b # Exit without closing window set VAR=value # Set variable echo %VAR% # Use variable set /p VAR=Prompt: # User input set /a RESULT=5+3 # Arithmetic if "%VAR%"=="value" (command) if exist file.txt (command) if not exist file.txt (command) for %%f in (*.txt) do echo %%f for /r %%f in (*.log) do del %%f for /l %%i in (1,1,10) do echo %%i goto :label :label call script.bat # Call another batch call :subroutine goto :eof :subroutine echo In subroutine goto :eof
USEFUL COMMANDS#
cls # Clear screen title Window Title # Set window title color 0A # Green text on black mode con cols=120 lines=40 # Resize window doskey /history # Command history clip < file.txt # Copy file to clipboard echo text | clip # Copy text to clipboard shutdown /s /t 0 # Shutdown now shutdown /r /t 0 # Restart now shutdown /l # Log off shutdown /a # Abort shutdown cipher /e folder # Encrypt folder cipher /d folder # Decrypt folder cipher /w:C:\ # Wipe deleted data
QUICK REFERENCE#
# File operations copy, xcopy, robocopy, move, del, ren, mkdir, rmdir # System info systeminfo, hostname, ver, ipconfig, netstat # Process control tasklist, taskkill, start # Network ping, tracert, nslookup, netstat, arp, route # Users net user, net localgroup, whoami # Services sc, net start, net stop
CMD CHEATSHEET ============== Source: https://cheatsheet.johlem.net Windows Command Prompt: Classic Windows command-line interpreter. Essential for batch scripting and system administration. HELP ---- command /? # Help for command help # List built-in commands where command # Find command location NAVIGATION ---------- cd # Current directory cd \ # Go to root cd .. # Parent directory cd path\to\folder # Change directory cd /d D:\path # Change drive and directory pushd path # Save current dir, change to path popd # Return to saved directory DIRECTORY LISTING ----------------- dir # List directory dir /a # Show all (including hidden) dir /ah # Hidden files only dir /s # Recursive listing dir /b # Bare format (names only) dir /o:s # Order by size dir /o:d # Order by date dir /o:-d # Order by date descending dir /q # Show owner dir *.txt # Filter by extension dir /s /b *.exe # Find all exe files WILDCARDS --------- * # Match any characters ? # Match single character dir *.txt # All txt files dir file?.txt # file1.txt, file2.txt, etc. dir ???.* # 3 character names FILE OPERATIONS =============== copy src dest # Copy file copy file1+file2 merged # Concatenate files copy /y src dest # Copy without confirm xcopy src dest /s # Copy with subdirs xcopy src dest /e # Include empty dirs xcopy src dest /h # Include hidden xcopy src dest /c # Continue on error robocopy src dest # Robust copy (better) move src dest # Move/rename file ren oldname newname # Rename file rename oldname newname # Rename file del file.txt # Delete file del /f file.txt # Force delete del /s /q folder\* # Delete all in folder del /a:h file # Delete hidden file erase file.txt # Same as del DIRECTORY OPERATIONS -------------------- mkdir foldername # Create directory md foldername # Create directory mkdir path\to\nested # Create nested dirs rmdir foldername # Remove empty directory rmdir /s foldername # Remove with contents rmdir /s /q foldername # Remove without confirm rd /s /q foldername # Short form FILE ATTRIBUTES --------------- attrib file.txt # Show attributes attrib +h file.txt # Set hidden attrib -h file.txt # Remove hidden attrib +r file.txt # Set read-only attrib +s file.txt # Set system attrib -r -h -s file.txt # Remove all attrib /s /d +h folder\* # Recursive # Attributes: R=ReadOnly H=Hidden S=System A=Archive FILE CONTENT ------------ type file.txt # Display file contents type file.txt | more # Page by page more file.txt # Page by page echo text > file.txt # Write to file (overwrite) echo text >> file.txt # Append to file copy con file.txt # Type content, Ctrl+Z to save SEARCHING ========= find "text" file.txt # Search in file find /i "text" file.txt # Case insensitive find /c "text" file.txt # Count occurrences find /n "text" file.txt # Show line numbers find /v "text" file.txt # Lines NOT containing findstr "text" file.txt # Regex search findstr /i "text" file.txt # Case insensitive findstr /r "pattern" file.txt # Regex pattern findstr /s "text" *.txt # Recursive search findstr /m "text" *.txt # Files names only findstr /n "text" file.txt # Line numbers findstr /c:"exact phrase" file.txt # Literal string # Find files dir /s /b *filename* # Find file by name where /r C:\ filename.exe # Find executable PROCESS MANAGEMENT ================== tasklist # List processes tasklist /v # Verbose (window titles) tasklist /svc # Show services tasklist /m # Show loaded DLLs tasklist /fi "imagename eq cmd.exe" # Filter by name tasklist /fi "pid eq 1234" # Filter by PID tasklist /fi "status eq running" # Filter by status taskkill /pid 1234 # Kill by PID taskkill /im notepad.exe # Kill by name taskkill /f /pid 1234 # Force kill taskkill /f /im chrome.exe # Force kill all chrome taskkill /t /pid 1234 # Kill process tree start notepad.exe # Start program start "" "C:\path with spaces\app.exe" start /min notepad.exe # Start minimized start /max notepad.exe # Start maximized start /wait program.exe # Wait for completion NETWORK ======= ipconfig # IP configuration ipconfig /all # Detailed info ipconfig /release # Release DHCP ipconfig /renew # Renew DHCP ipconfig /flushdns # Clear DNS cache ipconfig /displaydns # Show DNS cache ping host # Ping host ping -t host # Continuous ping ping -n 10 host # 10 pings ping -l 1000 host # Packet size 1000 tracert host # Traceroute pathping host # Path and latency nslookup domain # DNS lookup nslookup -type=mx domain # MX records nslookup -type=ns domain # NS records nslookup domain 8.8.8.8 # Use specific DNS netstat -a # All connections netstat -an # Numeric addresses netstat -ano # With PIDs netstat -b # Show executables netstat -r # Routing table arp -a # ARP table route print # Routing table hostname # Show hostname net view # Network computers net view \\computer # Shared resources net use # Mapped drives net use Z: \\server\share # Map drive net use Z: /delete # Unmap drive net use \\server\share /user:domain\user password SERVICES ======== sc query # List services sc query servicename # Service status sc start servicename # Start service sc stop servicename # Stop service sc config servicename start=auto # Set auto start sc config servicename start=disabled # Disable service sc qc servicename # Service config sc delete servicename # Delete service net start # Running services net start servicename # Start service net stop servicename # Stop service USERS & GROUPS ============== net user # List users net user username # User info net user username password /add # Create user net user username /delete # Delete user net user username /active:yes # Enable user net user username /active:no # Disable user net localgroup # List groups net localgroup groupname # Group members net localgroup administrators user /add net localgroup administrators user /delete whoami # Current user whoami /all # User SID, groups, privileges whoami /priv # Privileges whoami /groups # Group memberships SYSTEM INFO =========== systeminfo # System information systeminfo | findstr /i "boot" # Boot time hostname # Computer name ver # Windows version date # Current date time # Current time set # Environment variables wmic os get caption,version # OS version wmic computersystem get model,manufacturer wmic bios get serialnumber # Serial number wmic cpu get name # CPU info wmic memorychip get capacity # RAM info SCHEDULED TASKS =============== schtasks /query # List tasks schtasks /query /tn "taskname" # Specific task schtasks /query /fo list /v # Verbose list schtasks /run /tn "taskname" # Run task schtasks /end /tn "taskname" # Stop task schtasks /delete /tn "taskname" /f # Delete task # Create scheduled task schtasks /create /tn "MyTask" /tr "C:\script.bat" /sc daily /st 09:00 DISK OPERATIONS =============== chkdsk C: # Check disk chkdsk C: /f # Fix errors chkdsk C: /r # Locate bad sectors diskpart # Disk partitioning fsutil fsinfo drives # List drives fsutil volume diskfree C: # Disk free space label D: NewLabel # Change volume label REDIRECTION & PIPES =================== command > file.txt # Output to file (overwrite) command >> file.txt # Append to file command < file.txt # Input from file command 2> error.txt # Stderr to file command > file.txt 2>&1 # Both stdout and stderr command | command2 # Pipe output command && command2 # Run if success command || command2 # Run if failure command & command2 # Run both BATCH SCRIPTING =============== @echo off # Disable command echo echo message # Print message pause # Wait for keypress exit # Exit script exit /b # Exit without closing window set VAR=value # Set variable echo %VAR% # Use variable set /p VAR=Prompt: # User input set /a RESULT=5+3 # Arithmetic if "%VAR%"=="value" (command) if exist file.txt (command) if not exist file.txt (command) for %%f in (*.txt) do echo %%f for /r %%f in (*.log) do del %%f for /l %%i in (1,1,10) do echo %%i goto :label :label call script.bat # Call another batch call :subroutine goto :eof :subroutine echo In subroutine goto :eof USEFUL COMMANDS =============== cls # Clear screen title Window Title # Set window title color 0A # Green text on black mode con cols=120 lines=40 # Resize window doskey /history # Command history clip < file.txt # Copy file to clipboard echo text | clip # Copy text to clipboard shutdown /s /t 0 # Shutdown now shutdown /r /t 0 # Restart now shutdown /l # Log off shutdown /a # Abort shutdown cipher /e folder # Encrypt folder cipher /d folder # Decrypt folder cipher /w:C:\ # Wipe deleted data QUICK REFERENCE --------------- # File operations copy, xcopy, robocopy, move, del, ren, mkdir, rmdir # System info systeminfo, hostname, ver, ipconfig, netstat # Process control tasklist, taskkill, start # Network ping, tracert, nslookup, netstat, arp, route # Users net user, net localgroup, whoami # Services sc, net start, net stop
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.