POWERSHELL ADMIN MEGA REFERENCE

PowerShell
Cheat Sheet

A massive searchable, copy-ready reference for PowerShell, Windows administration, automation, networking, services, Active Directory, remoting, registry, event logs, storage, scripting, and more.

408 commands & snippets
40 sections
1 standalone HTML file
⚠ Admin warning: Commands marked with ⚠ can delete data, users, firewall rules, registry keys, scheduled tasks, or storage. Verify the target before running them.
$x = 42

Assign a value to a variable.

$name = 'Ada'

Assign a string.

$enabled = $true

Assign a Boolean value.

$nothing = $null

Represent no value.

Write-Output 'Hello'

Write an object to the pipeline.

Write-Host 'Hello'

Write directly to the host display.

Read-Host 'Enter name'

Read text input from the user.

[int]$count = 5

Declare a typed variable.

$a, $b = 1, 2

Assign multiple values.

$a, $b = $b, $a

Swap values.

$env:COMPUTERNAME

Read an environment variable.

$PSVersionTable

Show PowerShell version information.

Get-Variable

List variables in the current scope.

Remove-Variable x

Remove a variable.

Clear-Variable x

Clear a variable's value.

Get-Help Get-Process

Show help for a command.

Get-Help Get-Process -Full

Show full help.

Get-Help Get-Process -Examples

Show usage examples.

Get-Help about_Comparison_Operators

Open conceptual help.

Get-Command

List available commands.

Get-Command *service*

Find commands by name pattern.

Get-Command -Noun Service

Find commands by noun.

Get-Command -Verb Get

Find commands by verb.

Get-Member

Inspect properties and methods of pipeline objects.

Get-Alias

List aliases.

Get-Alias dir

Show what an alias maps to.

Set-Alias ll Get-ChildItem

Create an alias for the current session.

Update-Help

Download updated help content.

Get-Content file.txt

Read a text file.

Get-Content file.txt -First 10

Read the first 10 lines.

Get-Content file.txt -Tail 20

Read the last 20 lines.

Get-Content file.txt -Wait

Follow a growing file.

Set-Content file.txt 'hello'

Overwrite a text file.

Add-Content file.txt 'more'

Append text to a file.

'hello' | Out-File file.txt

Write pipeline output to a file.

'hello' | Out-File file.txt -Append

Append pipeline output.

Get-Content file.txt -Raw

Read the whole file as one string.

Select-String -Path file.txt -Pattern 'error'

Search text in a file.

Select-String -Path *.log -Pattern 'failed' -CaseSensitive

Search multiple files.

Get-Process | Sort-Object CPU -Descending

Sort objects by CPU usage.

Get-Process | Select-Object Name, CPU, Id

Select specific properties.

Get-Service | Where-Object Status -eq 'Running'

Filter objects by property.

Get-Process | Where-Object {$_.CPU -gt 100}

Filter with a script block.

Get-Process | ForEach-Object {$_.Name}

Process each pipeline object.

Get-Process | Group-Object ProcessName

Group objects by property.

Get-Process | Measure-Object

Count objects.

Get-Process | Measure-Object CPU -Sum -Average

Aggregate a numeric property.

Get-Process | Tee-Object processes.txt

Save and pass pipeline output.

Get-Process | Format-Table Name, Id, CPU -AutoSize

Display objects as a table.

Get-Service | Format-List *

Display properties as a list.

Get-Process | Out-GridView

View objects in an interactive grid on supported systems.

$text = 'hello'

Create a single-quoted string.

$text = "Hello $name"

Create an expandable string.

"Value: $($obj.Name)"

Embed an expression in a string.

$text.Length

Get string length.

$text.ToUpper()

Convert to uppercase.

$text.ToLower()

Convert to lowercase.

$text.Trim()

Remove surrounding whitespace.

$text.Replace('old','new')

Replace text.

$text.Split(',')

Split a string.

-join ('a','b','c')

Join values without a separator.

('a','b','c') -join ','

Join values with commas.

$text -match 'error'

Regex match.

$text -replace 'old','new'

Regex-based replacement.

$text -like '*admin*'

Wildcard comparison.

$text -contains 'x'

Check collection membership.

'x' -in $items

Check whether a value is in a collection.

$items = @(1,2,3)

Create an array.

$items[0]

Get the first array item.

$items[-1]

Get the last array item.

$items[1..3]

Get a range of array items.

$items += 4

Append to an array.

$items.Count

Get array length.

$items | Sort-Object -Unique

Return unique sorted values.

$hash = @{Name='Ada'; Age=18}

Create a hashtable.

$hash['Name']

Read a hashtable value.

$hash.Name

Read a key using property syntax.

$hash['Email']='a@example.com'

Add or update a hashtable key.

$hash.Remove('Age')

Remove a hashtable key.

$hash.Keys

List keys.

$hash.Values

List values.

[ordered]@{Name='Ada'; Age=18}

Create an ordered hashtable.

if ($x -gt 0) { 'positive' }

Basic if statement.

if ($x -gt 0) { } else { }

if/else.

if ($x -gt 0) { } elseif ($x -eq 0) { } else { }

if/elseif/else.

$status = if ($age -ge 18) {'adult'} else {'minor'}

Assign from an if expression.

switch ($value) { 'A' {'Alpha'} default {'Other'} }

Switch statement.

switch -Regex ($text) { '^ERR' {'Error'} }

Regex switch.

if ($null -eq $value) { }

Check for null.

if (-not $items) { }

Check a falsy/empty value.

foreach ($item in $items) { $item }

Loop over a collection.

$items | ForEach-Object { $_ }

Pipeline-style iteration.

for ($i=0; $i -lt 10; $i++) { $i }

Classic for loop.

while ($condition) { }

Repeat while a condition is true.

do { } while ($condition)

Run once, then repeat while true.

do { } until ($condition)

Run until a condition becomes true.

break

Exit the nearest loop or switch.

continue

Skip to the next loop iteration.

function Get-Greeting { param($Name) "Hello $Name" }

Define a simple function.

function Add-Numbers { param([int]$A,[int]$B) $A+$B }

Function with typed parameters.

function Test-Thing { [CmdletBinding()] param([string]$Name) }

Create an advanced function.

param([Parameter(Mandatory)] [string]$Name)

Require a parameter.

param([ValidateSet('Dev','Prod')] [string]$Mode)

Restrict allowed parameter values.

return $value

Return a value.

$args

Access unbound arguments.

$PSBoundParameters

Inspect explicitly bound parameters.

Get-Command MyFunction -Syntax

Show function syntax.

$global:x = 1

Create a global-scope variable.

$script:x = 1

Create a script-scope variable.

$local:x = 1

Create a local-scope variable.

Get-Variable -Scope Global

List global variables.

$PROFILE

Show the current user's PowerShell profile path.

Test-Path $PROFILE

Check whether the profile exists.

New-Item -ItemType File -Path $PROFILE -Force

Create a profile file.

notepad $PROFILE

Open the profile in Notepad on Windows.

try { risky } catch { $_ }

Catch terminating errors.

try { } catch [System.IO.IOException] { }

Catch a specific exception type.

try { } finally { cleanup }

Always run cleanup.

throw 'Something failed'

Raise an exception.

$Error[0]

View the most recent error.

$Error.Clear()

Clear the error collection.

$ErrorActionPreference = 'Stop'

Make non-terminating errors terminate.

Get-Item missing -ErrorAction SilentlyContinue

Override error behavior for one command.

Write-Error 'Failure'

Write an error record.

Write-Warning 'Warning'

Write a warning.

Write-Verbose 'Details'

Write verbose output.

Write-Debug 'Debug'

Write debug output.

Get-Process

List running processes.

Get-Process powershell

Get processes by name.

Get-Process -Id 1234

Get a process by PID.

Get-Process | Sort-Object CPU -Descending | Select-Object -First 10

Show top CPU-consuming processes.

Stop-Process -Id 1234

Stop a process.

Stop-Process -Name notepad -Force

Force-stop processes by name.

Start-Process notepad.exe

Start a process.

Start-Process powershell -Verb RunAs

Start a process elevated.

Start-Process cmd -ArgumentList '/c ipconfig'

Start a process with arguments.

Wait-Process -Name notepad

Wait for a process to exit.

Get-Service

List services.

Get-Service Spooler

Get one service.

Get-Service | Where-Object Status -eq 'Running'

List running services.

Start-Service Spooler

Start a service.

Stop-Service Spooler

Stop a service.

Restart-Service Spooler

Restart a service.

Suspend-Service ServiceName

Pause a service if supported.

Resume-Service ServiceName

Resume a paused service.

Set-Service Spooler -StartupType Automatic

Set service startup type.

Get-CimInstance Win32_Service

Query detailed service information.

Get-ComputerInfo

Display broad system information.

Get-CimInstance Win32_OperatingSystem

Show OS information.

Get-CimInstance Win32_ComputerSystem

Show computer system information.

Get-CimInstance Win32_Processor

Show CPU information.

Get-CimInstance Win32_PhysicalMemory

Show installed memory modules.

Get-CimInstance Win32_BIOS

Show BIOS information.

Get-CimInstance Win32_BaseBoard

Show motherboard information.

Get-CimInstance Win32_LogicalDisk

Show logical disks.

Get-CimInstance Win32_DiskDrive

Show physical disks.

Get-HotFix

List installed Windows hotfixes.

systeminfo

Run the classic Windows systeminfo command.

Get-NetIPConfiguration

Show interface IP configuration.

Get-NetIPAddress

List IP addresses.

Get-NetAdapter

List network adapters.

Get-NetAdapter | Where-Object Status -eq 'Up'

Show active adapters.

Get-NetRoute

Show routing table entries.

Get-NetNeighbor

Show neighbor/ARP information.

Test-Connection 8.8.8.8

Send ICMP echo requests.

Test-NetConnection example.com -Port 443

Test TCP connectivity to a port.

Resolve-DnsName example.com

Query DNS.

Get-DnsClientServerAddress

Show configured DNS servers.

Get-NetTCPConnection

List TCP connections.

Get-NetTCPConnection -State Listen

Show listening TCP sockets.

Get-NetUDPEndpoint

List UDP endpoints.

Get-NetAdapterStatistics

Show interface counters.

ipconfig /all

Run classic Windows IP configuration output.

arp -a

Run classic ARP table display.

route print

Run classic routing table display.

nslookup example.com

Run classic DNS lookup.

Get-NetFirewallProfile

Show Windows Firewall profiles.

Get-NetFirewallRule

List firewall rules.

Get-NetFirewallRule -Enabled True

List enabled rules.

New-NetFirewallRule -DisplayName 'Allow HTTP' -Direction Inbound -Protocol TCP -LocalPort 80 -Action Allow

Allow inbound TCP port 80.

Disable-NetFirewallRule -DisplayName 'Rule Name'

Disable a firewall rule.

Enable-NetFirewallRule -DisplayName 'Rule Name'

Enable a firewall rule.

Remove-NetFirewallRule -DisplayName 'Rule Name'

Delete a firewall rule. ⚠

Get-NetFirewallPortFilter

Inspect firewall port filters.

Get-LocalUser

List local users.

Get-LocalUser administrator

Get a local user.

New-LocalUser 'student' -NoPassword

Create a local user without a password.

Set-LocalUser 'student' -Description 'Lab account'

Modify a local user.

Disable-LocalUser student

Disable a local account.

Enable-LocalUser student

Enable a local account.

Remove-LocalUser student

Delete a local account. ⚠

Get-LocalGroup

List local groups.

Get-LocalGroupMember Administrators

List members of the Administrators group.

Add-LocalGroupMember Administrators student

Add a local user to Administrators.

Remove-LocalGroupMember Administrators student

Remove a member from Administrators.

whoami

Show current user.

whoami /groups

Show current user's groups.

Import-Module ActiveDirectory

Load the Active Directory module.

Get-ADUser -Filter *

List AD users.

Get-ADUser username -Properties *

Show all user properties.

Get-ADComputer -Filter *

List AD computers.

Get-ADGroup -Filter *

List AD groups.

Get-ADGroupMember 'Domain Admins'

List group members.

New-ADUser -Name 'Test User' -SamAccountName tuser -Enabled $true

Create an AD user.

Set-ADUser tuser -Department IT

Modify an AD user.

Disable-ADAccount tuser

Disable an AD account.

Enable-ADAccount tuser

Enable an AD account.

Unlock-ADAccount tuser

Unlock an AD user account.

Add-ADGroupMember 'IT Staff' tuser

Add a user to an AD group.

Remove-ADGroupMember 'IT Staff' tuser -Confirm:$false

Remove a user from an AD group.

Get-ADDomain

Show domain information.

Get-ADForest

Show forest information.

Get-ChildItem HKLM:\Software

List registry keys.

Get-Item HKLM:\Software\Microsoft

Get a registry key.

Get-ItemProperty HKLM:\Software\Microsoft

Read registry values.

New-Item HKCU:\Software\MyApp

Create a registry key.

New-ItemProperty HKCU:\Software\MyApp -Name Enabled -Value 1 -PropertyType DWord

Create a registry value.

Set-ItemProperty HKCU:\Software\MyApp -Name Enabled -Value 0

Modify a registry value.

Remove-ItemProperty HKCU:\Software\MyApp -Name Enabled

Delete a registry value. ⚠

Remove-Item HKCU:\Software\MyApp -Recurse

Delete a registry key tree. ⚠

Get-WinEvent -ListLog *

List Windows event logs.

Get-WinEvent -LogName System -MaxEvents 20

Show recent System events.

Get-WinEvent -LogName Application -MaxEvents 20

Show recent Application events.

Get-WinEvent -FilterHashtable @{LogName='System'; Level=2}

Show System errors.

Get-WinEvent -FilterHashtable @{LogName='System'; StartTime=(Get-Date).AddHours(-1)}

Show System events from the last hour.

Get-EventLog -LogName System -Newest 20

Legacy event log query.

Clear-EventLog -LogName Application

Clear an event log. ⚠

Get-CimClass

List CIM classes.

Get-CimInstance Win32_OperatingSystem

Query OS information.

Get-CimInstance Win32_Process

Query processes.

Get-CimInstance Win32_NetworkAdapterConfiguration

Query network adapter configuration.

Invoke-CimMethod -ClassName Win32_Process -MethodName Create -Arguments @{CommandLine='notepad.exe'}

Invoke a CIM method.

New-CimSession -ComputerName Server01

Create a remote CIM session.

Get-CimInstance Win32_OperatingSystem -CimSession $session

Query through a CIM session.

Remove-CimSession $session

Close a CIM session.

Enable-PSRemoting -Force

Enable PowerShell remoting on Windows.

Test-WSMan Server01

Test WinRM connectivity.

Enter-PSSession Server01

Open an interactive remote session.

Exit-PSSession

Leave an interactive remote session.

Invoke-Command -ComputerName Server01 -ScriptBlock { Get-Service }

Run a command remotely.

Invoke-Command -ComputerName Server01,Server02 -ScriptBlock { hostname }

Run across multiple computers.

$s = New-PSSession Server01

Create a persistent remote session.

Invoke-Command -Session $s -ScriptBlock { Get-Process }

Use a persistent session.

Remove-PSSession $s

Close a persistent session.

Copy-Item file.txt C:\Temp -ToSession $s

Copy a file into a remote session.

Get-ScheduledTask

List scheduled tasks.

Get-ScheduledTask -TaskName 'TaskName'

Get one scheduled task.

Start-ScheduledTask -TaskName 'TaskName'

Run a scheduled task now.

Stop-ScheduledTask -TaskName 'TaskName'

Stop a running task.

Enable-ScheduledTask -TaskName 'TaskName'

Enable a task.

Disable-ScheduledTask -TaskName 'TaskName'

Disable a task.

Unregister-ScheduledTask -TaskName 'TaskName' -Confirm:$false

Delete a scheduled task. ⚠

$action = New-ScheduledTaskAction -Execute 'notepad.exe'

Create a scheduled-task action.

$trigger = New-ScheduledTaskTrigger -Daily -At 9am

Create a daily trigger.

Register-ScheduledTask -TaskName 'Demo' -Action $action -Trigger $trigger

Register a scheduled task.

Get-Disk

List physical disks.

Get-PhysicalDisk

List physical disks through Storage Spaces.

Get-Partition

List partitions.

Get-Volume

List volumes.

Get-PSDrive -PSProvider FileSystem

List filesystem drives.

Get-StoragePool

List storage pools.

Get-VirtualDisk

List virtual disks.

Initialize-Disk -Number 1 -PartitionStyle GPT

Initialize a disk. ⚠

New-Partition -DiskNumber 1 -UseMaximumSize -AssignDriveLetter

Create a partition.

Format-Volume -DriveLetter E -FileSystem NTFS -NewFileSystemLabel Data

Format a volume. ⚠

Resize-Partition -DriveLetter C -Size 200GB

Resize a partition when supported.

Get-SmbShare

List SMB shares.

Get-SmbSession

List SMB client sessions.

Get-SmbOpenFile

List open files on SMB shares.

New-SmbShare -Name Data -Path C:\Data -FullAccess Administrators

Create an SMB share.

Remove-SmbShare -Name Data -Force

Delete an SMB share. ⚠

Get-SmbShareAccess -Name Data

Show share permissions.

Grant-SmbShareAccess -Name Data -AccountName 'DOMAIN\User' -AccessRight Change -Force

Grant SMB share access.

Revoke-SmbShareAccess -Name Data -AccountName 'DOMAIN\User' -Force

Revoke SMB share access.

Get-Printer

List printers.

Get-PrinterDriver

List printer drivers.

Get-PrinterPort

List printer ports.

Add-PrinterPort -Name 'IP_10.0.0.50' -PrinterHostAddress 10.0.0.50

Create a TCP/IP printer port.

Add-Printer -Name 'Office Printer' -DriverName 'Driver Name' -PortName 'IP_10.0.0.50'

Add a printer.

Remove-Printer -Name 'Office Printer'

Remove a printer. ⚠

Get-PrintJob -PrinterName 'Office Printer'

List print jobs.

Remove-PrintJob -PrinterName 'Office Printer' -ID 3

Delete a print job.

Get-Package

List installed packages known to PackageManagement.

Find-Package -Name 7zip

Search package sources.

Install-Package -Name PackageName

Install a package through PackageManagement.

Uninstall-Package -Name PackageName

Uninstall a package.

winget search vscode

Search Windows Package Manager.

winget install Microsoft.VisualStudioCode

Install a package with winget.

winget upgrade --all

Upgrade all available winget packages.

winget list

List installed packages visible to winget.

winget uninstall PackageName

Uninstall with winget.

Get-Module

List currently loaded modules.

Get-Module -ListAvailable

List available modules.

Import-Module ActiveDirectory

Import a module.

Remove-Module ModuleName

Unload a module from the current session.

Find-Module Pester

Search PowerShell Gallery.

Install-Module Pester -Scope CurrentUser

Install a module from PowerShell Gallery.

Update-Module Pester

Update an installed module.

Uninstall-Module Pester

Remove a module.

Import-Csv users.csv

Read CSV rows as objects.

$data | Export-Csv users.csv -NoTypeInformation

Write objects to CSV.

ConvertTo-Csv $data -NoTypeInformation

Convert objects to CSV text.

Get-Content data.json -Raw | ConvertFrom-Json

Parse JSON from a file.

$obj | ConvertTo-Json -Depth 5

Convert an object to JSON.

$obj | ConvertTo-Json | Set-Content data.json

Write JSON to a file.

[xml]$xml = Get-Content file.xml

Load XML into an XML document object.

$xml.SelectNodes('//item')

Query XML nodes.

Invoke-WebRequest https://example.com

Make a web request.

Invoke-WebRequest https://example.com/file.zip -OutFile file.zip

Download a file.

Invoke-RestMethod https://api.example.com/items

Call a REST API and deserialize JSON.

Invoke-RestMethod -Method Post -Uri $uri -Body ($body | ConvertTo-Json) -ContentType 'application/json'

POST JSON to a REST API.

$response.StatusCode

Read HTTP status code from Invoke-WebRequest.

$response.Content

Read raw response content.

Get-Date

Get current date and time.

Get-Date -Format 'yyyy-MM-dd HH:mm:ss'

Format date/time.

(Get-Date).AddDays(7)

Add seven days.

(Get-Date).AddHours(-1)

Subtract one hour.

New-TimeSpan -Start $start -End $end

Calculate a time span.

[datetime]'2026-09-18'

Convert text to a DateTime.

[timespan]::FromMinutes(5)

Create a TimeSpan.

'abc123' -match '\d+'

Regex match.

$Matches[0]

Read the latest regex match.

'abc123' -replace '\d+','X'

Regex replacement.

[regex]::Matches($text,'\b\w+\b')

Return all regex matches.

[regex]::Escape($text)

Escape regex metacharacters.

Select-String -Pattern '^ERROR' -Path *.log

Regex search across files.

Get-ExecutionPolicy

Show current script execution policy.

Get-ExecutionPolicy -List

Show execution policies by scope.

Set-ExecutionPolicy RemoteSigned -Scope CurrentUser

Set current-user execution policy.

Get-Credential

Prompt for a PSCredential.

$cred.UserName

Read username from a PSCredential.

$cred.GetNetworkCredential().Password

Extract plaintext password from a credential object; handle carefully.

ConvertTo-SecureString 'password' -AsPlainText -Force

Create a SecureString from plaintext; avoid hardcoding secrets.

Get-AuthenticodeSignature .\script.ps1

Inspect a script's code signature.

Set-AuthenticodeSignature .\script.ps1 $cert

Sign a script using a certificate.

Start-Job { Get-Process }

Start a background job.

Get-Job

List background jobs.

Receive-Job -Id 1

Receive job output.

Wait-Job -Id 1

Wait for a job.

Stop-Job -Id 1

Stop a job.

Remove-Job -Id 1

Remove a job record.

1..10 | ForEach-Object -Parallel { $_ * 2 }

Run pipeline work in parallel in PowerShell 7+.

Start-ThreadJob { Get-Service }

Start a lightweight thread job if ThreadJob is available.

Start-Transcript -Path session.log

Record a PowerShell session transcript.

Stop-Transcript

Stop transcript recording.

Write-Information 'Info message'

Write to the information stream.

Write-Verbose 'Verbose message' -Verbose

Emit verbose output.

Write-Debug 'Debug message' -Debug

Emit debug output.

.\script.ps1

Run a PowerShell script from the current directory.

powershell.exe -File script.ps1

Run a script with Windows PowerShell.

pwsh -File script.ps1

Run a script with PowerShell 7+.

powershell.exe -ExecutionPolicy Bypass -File script.ps1

Run a script with a process-specific execution-policy override.

& 'C:\Path With Spaces\app.exe')

Invoke an executable or script path.

. .\functions.ps1

Dot-source a script into the current scope.

$PSScriptRoot

Directory containing the running script.

$PSCommandPath

Full path to the running script.

$a -eq $b

Equal.

$a -ne $b

Not equal.

$a -gt $b

Greater than.

$a -ge $b

Greater than or equal.

$a -lt $b

Less than.

$a -le $b

Less than or equal.

$text -like '*admin*'

Wildcard comparison.

$text -notlike '*admin*'

Negated wildcard comparison.

$text -match '^A'

Regex comparison.

$text -notmatch '^A'

Negated regex comparison.

$items -contains 'x'

Collection contains a value.

'x' -in $items

Value exists in collection.

Get-Process | Sort-Object CPU -Descending | Select-Object -First 10 Name,CPU,Id

Top 10 processes by CPU.

Get-Process | Sort-Object WS -Descending | Select-Object -First 10 Name,@{N='MB';E={[math]::Round($_.WS/1MB,1)}}

Top 10 processes by working-set memory.

Get-Service | Where-Object Status -eq 'Stopped' | Sort-Object Name

List stopped services.

Get-ChildItem C:\ -File -Recurse -ErrorAction SilentlyContinue | Sort-Object Length -Descending | Select-Object -First 20 FullName,Length

Find large files. Can take a while.

Get-ChildItem -Recurse -File | Measure-Object | Select-Object Count

Count files recursively.

Get-WinEvent -FilterHashtable @{LogName='System';Level=2;StartTime=(Get-Date).AddHours(-24)}

Show System errors from the last 24 hours.

Get-NetTCPConnection -State Listen | Sort-Object LocalPort

Show listening TCP ports.

Get-LocalGroupMember Administrators

Quickly list local admins.

Get-CimInstance Win32_OperatingSystem | Select-Object Caption,Version,LastBootUpTime

Show OS version and last boot time.

Get-Disk | Select-Object Number,FriendlyName,Size,PartitionStyle,OperationalStatus

Summarize disks.

Get-Volume | Sort-Object DriveLetter | Format-Table DriveLetter,FileSystemLabel,FileSystem,SizeRemaining,Size

Summarize volumes.

Get-ChildItem *.log | Select-String 'error|failed' -CaseSensitive:$false

Search log files for common failure terms.

1..20 | ForEach-Object { Test-Connection 192.168.1.$_ -Count 1 -Quiet }

Basic ping sweep result list.

Format-Table | Export-Csv

Do not format objects before exporting; formatting converts objects into display metadata.

Where-Object {$_.Property = 'x'}

Use -eq for comparison; = assigns a value.

Write-Host $obj | Export-Csv file.csv

Write-Host does not emit normal pipeline objects for export.

Remove-Item -Recurse -Force

Double-check target paths before destructive recursive deletion.

$array += $item

Repeated += on very large arrays can be inefficient; prefer List[T] or pipeline collection.

Get-WmiObject

Prefer Get-CimInstance for modern PowerShell automation.