Skip to content

SysAdmin PowerShell Diagnostic Toolkit

When troubleshooting performance degradation, blue screens (BSOD), or unresponsive Windows workstations and servers, this toolkit gathers system, event, and storage information. The DISM /RestoreHealth and SFC /scannow commands can repair Windows components and system files, so the workflow is not entirely read-only; run those repair steps under your normal change process.

Step 1: Open PowerShell as Administrator

01

Open and Verify an Elevated PowerShell Session

Prerequisite

System file repairs and hardware diagnostics require elevated administrative rights. Launch PowerShell elevated using any of these simple methods:

  • Quick Shortcut: Press Win + X, then select Terminal (Admin) or PowerShell (Admin).
  • Start Menu: Press Win, type powershell, and click Run as administrator.
  • From Run Prompt: Press Win + R, type powershell, and press Ctrl + Shift + Enter.
Terminal window
# Stop here if this session is not elevated. Reopen PowerShell with Run as administrator.
if (-not ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole(544)) {
throw 'Open PowerShell with Run as administrator, then rerun these checks.'
}
❯ View Expected Console Output

Prompt: User Account Control (UAC) → Click “Yes” to confirm elevated rights.

Step 2: Automated Component Store & System File Integrity Scan

02

Scan & Repair Windows Component Store (DISM + SFC)

OS Repair

Run DISM to scan and restore the Windows Component Store image against official Windows Update sources, followed by the System File Checker (SFC) to repair corrupt DLLs:

Terminal window
# 1. Scan and restore Windows Component Store health
Write-Host "Running DISM Component Store Restore..." -ForegroundColor Cyan
DISM.exe /Online /Cleanup-Image /RestoreHealth
# 2. Verify and repair protected operating system files
Write-Host "Running System File Checker (SFC)..." -ForegroundColor Cyan
sfc /scannow
❯ View Expected Console Output

[==========================100.0%==========================]
The restore operation completed successfully.
The operation completed successfully.
Beginning system scan. This process will take some time.
Windows Resource Protection did not find any integrity violations.

Step 3: Inspect Event Logs for Critical Hardware & Kernel Errors

03

Query Last 24 Hours of Critical Events

Log Audit

Instead of clicking through Event Viewer, query the System and Application logs for errors and critical warnings logged within the last 24 hours:

Terminal window
# Extract Error and Critical level events from System and Application logs
$pastDay = (Get-Date).AddDays(-1)
Get-WinEvent -FilterHashtable @{
LogName = 'System', 'Application'
Level = 1, 2 # 1 = Critical, 2 = Error
StartTime = $pastDay
} -ErrorAction SilentlyContinue |
Select-Object -First 10 TimeCreated, ProviderName, Id, Message |
Format-Table -AutoSize
❯ View Expected Console Output

TimeCreated ProviderName Id Message
----------- ------------ — -------
10/01/2026 14:22:10 Microsoft-Windows-Kernel-Power 41 The system has rebooted without cleanly shutting down first…
10/01/2026 11:05:42 Service Control Manager 7001 The Computer Browser service depends on the Server service…

Step 4: Storage Provider Health and Volume Free Space

04

Inspect Physical NVMe/SSD Health & Free Space

Storage

Query the Storage Management provider’s disk health status and evaluate volume capacity. These fields do not expose raw vendor SMART telemetry on every controller; use the storage or drive vendor’s tools when detailed device telemetry is required.

Terminal window
# Query disk status reported by the Windows Storage Management provider
Get-PhysicalDisk | Select-Object DeviceId, FriendlyName, MediaType, OperationalStatus, HealthStatus
# Calculate free disk percentage across all fixed volumes
Get-Volume | Where-Object { $_.DriveType -eq 'Fixed' } |
Select-Object DriveLetter, FileSystemLabel,
@{Name="Size(GB)"; Expression={[math]::Round($_.Size / 1GB, 2)}},
@{Name="Free(GB)"; Expression={[math]::Round($_.SizeRemaining / 1GB, 2)}},
@{Name="PercentFree"; Expression={[math]::Round(($_.SizeRemaining / $_.Size) * 100, 1)}}
❯ View Expected Console Output

DeviceId FriendlyName MediaType OperationalStatus HealthStatus
-------- ------------ --------- ----------------- ------------
0 Samsung SSD 990 PRO 2TB SSD OK Healthy


DriveLetter FileSystemLabel Size(GB) Free(GB) PercentFree
----------- --------------- -------- -------- -----------
C Windows 1906.50 1240.20 65.1%

Comments