SysAdmin PowerShell Diagnostic Toolkit
When troubleshooting performance degradation, blue screens (BSOD), or unresponsive Windows workstations and servers, this toolkit gathers system, event, and storage information. The DISM /RestoreHealth and SFC /scannow commands can repair Windows components and system files, so the workflow is not entirely read-only; run those repair steps under your normal change process.
Step 1: Open PowerShell as Administrator
Open and Verify an Elevated PowerShell Session
PrerequisiteSystem file repairs and hardware diagnostics require elevated administrative rights. Launch PowerShell elevated using any of these simple methods:
- Quick Shortcut: Press Win + X, then select Terminal (Admin) or PowerShell (Admin).
- Start Menu: Press Win, type
powershell, and click Run as administrator. - From Run Prompt: Press Win + R, type
powershell, and press Ctrl + Shift + Enter.
# Stop here if this session is not elevated. Reopen PowerShell with Run as administrator.if (-not ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole(544)) { throw 'Open PowerShell with Run as administrator, then rerun these checks.'}❯ View Expected Console Output
Prompt: User Account Control (UAC) → Click “Yes” to confirm elevated rights.
Step 2: Automated Component Store & System File Integrity Scan
Scan & Repair Windows Component Store (DISM + SFC)
OS RepairRun DISM to scan and restore the Windows Component Store image against official Windows Update sources, followed by the System File Checker (SFC) to repair corrupt DLLs:
# 1. Scan and restore Windows Component Store healthWrite-Host "Running DISM Component Store Restore..." -ForegroundColor CyanDISM.exe /Online /Cleanup-Image /RestoreHealth
# 2. Verify and repair protected operating system filesWrite-Host "Running System File Checker (SFC)..." -ForegroundColor Cyansfc /scannow❯ View Expected Console Output
[==========================100.0%==========================]
The restore operation completed successfully.
The operation completed successfully.
Beginning system scan. This process will take some time.
Windows Resource Protection did not find any integrity violations.
Step 3: Inspect Event Logs for Critical Hardware & Kernel Errors
Query Last 24 Hours of Critical Events
Log AuditInstead of clicking through Event Viewer, query the System and Application logs for errors and critical warnings logged within the last 24 hours:
# Extract Error and Critical level events from System and Application logs$pastDay = (Get-Date).AddDays(-1)
Get-WinEvent -FilterHashtable @{ LogName = 'System', 'Application' Level = 1, 2 # 1 = Critical, 2 = Error StartTime = $pastDay} -ErrorAction SilentlyContinue |Select-Object -First 10 TimeCreated, ProviderName, Id, Message |Format-Table -AutoSize❯ View Expected Console Output
TimeCreated ProviderName Id Message
----------- ------------ — -------
10/01/2026 14:22:10 Microsoft-Windows-Kernel-Power 41 The system has rebooted without cleanly shutting down first…
10/01/2026 11:05:42 Service Control Manager 7001 The Computer Browser service depends on the Server service…
Step 4: Storage Provider Health and Volume Free Space
Inspect Physical NVMe/SSD Health & Free Space
StorageQuery the Storage Management provider’s disk health status and evaluate volume capacity. These fields do not expose raw vendor SMART telemetry on every controller; use the storage or drive vendor’s tools when detailed device telemetry is required.
# Query disk status reported by the Windows Storage Management providerGet-PhysicalDisk | Select-Object DeviceId, FriendlyName, MediaType, OperationalStatus, HealthStatus
# Calculate free disk percentage across all fixed volumesGet-Volume | Where-Object { $_.DriveType -eq 'Fixed' } |Select-Object DriveLetter, FileSystemLabel, @{Name="Size(GB)"; Expression={[math]::Round($_.Size / 1GB, 2)}}, @{Name="Free(GB)"; Expression={[math]::Round($_.SizeRemaining / 1GB, 2)}}, @{Name="PercentFree"; Expression={[math]::Round(($_.SizeRemaining / $_.Size) * 100, 1)}}❯ View Expected Console Output
DeviceId FriendlyName MediaType OperationalStatus HealthStatus
-------- ------------ --------- ----------------- ------------
0 Samsung SSD 990 PRO 2TB SSD OK Healthy
DriveLetter FileSystemLabel Size(GB) Free(GB) PercentFree
----------- --------------- -------- -------- -----------
C Windows 1906.50 1240.20 65.1%