AIS
PowerShell & Windows Admin Script Library · v0.3.1

Clicking scales to one machine. Scripts scale to ten thousand.

48 tested PowerShell scripts for the work Windows admins actually do — health snapshots, service checks, safe log cleanup, inventory, connectivity sweeps, and the security audit: event IDs, credential hygiene, script signing, firewall and TLS. Runs on Windows PowerShell 5.1 and PowerShell 7. No modules to install.

Companion to the daily PowerShell & Windows Admin series. One-time purchase — yours forever after checkout, new tiers added as the series covers them.

Watch free. Run instantly. Own forever.

01

Watch

The daily PowerShell & Windows Admin series on the AIS YouTube channel walks the reasoning behind each script, free.

02

Run

Unzip the library and run any script instantly on a stock Windows box: Windows PowerShell 5.1 or PowerShell 7+, no modules to install. Every script ships with its own Pester test file.

03

Own

Every script emits objects, so it pipes into your existing tooling. Copy the folders into your admin toolkit and keep them forever.

Which file do I run?

Each epNN-* folder is independent — no shared install step, no config. A script, its test, and a README, always the same shape.

  • · The script (e.g. Get-QuickHealth.ps1) does the real admin task and emits objects — pipe them to Sort-Object, Where-Object, Export-Csv, whatever your workflow needs.
  • · The test file (Get-QuickHealth.Tests.ps1) is the proof — Pester assertions that verify the output shape and the behavior on your machine. Pester 3.4 ships with Windows, so it runs with no install.

Run the script first to see it work. Run the test to see it hold. Read both, then copy the pattern into your own tools — the parameter blocks, the object shapes, and the safety rails are the part worth keeping.

What’s in the library

Three tiers, 48 scripts. Foundations: health, services, disks, discovery, safe cleanup, execution policy, inventory and error handling. Administration: event logs, scheduled tasks, registry, shares, patching, remoting, Active Directory and Group Policy. Security & Audit: event IDs, audit policy, lockouts, PowerShell logging, secrets, script signing, AppLocker, JEA, Defender, firewall, TLS and baselines — pulled together in one hashed audit report.

Every script is an advanced function with full comment-based help, typed parameters, and objects out — readable top to bottom in one sitting.

# no modules to install — Windows PowerShell 5.1 or PowerShell 7
cd .\ep01-why-powershell
.\Get-QuickHealth.ps1                        # run the script
Invoke-Pester .\Get-QuickHealth.Tests.ps1    # prove it works on YOUR machine

# read it, then copy what you need into your own tools
01

Quick health snapshot

One command: hostname, OS version, uptime, disk free, and pending-reboot state — the "is this box okay?" answer.

ep01-why-powershell/Get-QuickHealth.ps1

02

Critical service check

Check a defined list of critical services and flag any that are not running.

ep02-running-commands/Get-ServiceStatus.ps1

03

Top processes for trending

Top memory and CPU consumers, stamped with machine name and time so you can trend across runs.

ep03-object-pipeline/Get-TopProcesses.ps1

04

Cmdlet finder

Search every installed module for cmdlets matching a keyword and print each synopsis.

ep04-discovery-tools/Find-AdminCmdlet.ps1

05

Disk threshold warning

Warn when free space drops below a typed GB or percent threshold, per volume.

ep05-variables-and-types/Test-DiskThreshold.ps1

06

OK / WARN / CRIT verdicts

Turns disk, uptime, and service data into explicit verdicts through readable threshold logic.

ep06-comparison-operators/Get-HealthVerdict.ps1

07

The morning check

Services set to Automatic that are not running — the classic first look of the day.

ep07-filter-select-sort/Get-StoppedAutoServices.ps1

08

Table and CSV from one dataset

A clean on-screen table AND a clean CSV export from the same objects — data is not display.

ep08-formatting-vs-data/Get-DiskSpaceReport.ps1

09

Folder size report

Every top-level folder under a path as name, file count, and total size — sorted largest first.

ep09-foreach-loops/Get-FolderSizeReport.ps1

10

Settings audit

Registry values, environment variables, and certificate expiry dates: actual vs expected, one report.

ep10-providers-drives/Get-SettingsAudit.ps1

11

Safe log cleanup

Age-based log cleanup that previews by default and deletes only with an explicit -Execute switch.

ep11-whatif-confirm/Remove-OldLogs.ps1

12

Execution policy report

Effective policy plus every scope, with drift flagged — for one machine or a list.

ep12-execution-policy/Get-ExecutionPolicyReport.ps1

13

Team profile deploy

Deploy a standard profile to the correct path, backing up any existing one first.

ep13-profiles-customization/Install-AdminProfile.ps1

14

System inventory

OS, hardware, and installed-update inventory written to CSV — a first full script done right.

ep14-first-script/Get-SystemInventory.ps1

15

Parameterized service health

[ValidateSet] service groups, a mandatory output path, CSV results — param blocks that make a script a tool.

ep15-param-blocks/Get-ServiceHealth.ps1

16

Connectivity sweep

Sweep a server list with a real per-host timeout, log failures without stopping, emit a success/fail summary.

ep16-error-handling-basics/Test-ServerConnectivity.ps1

17

Patch status from a list

Read machines from CSV, report installed updates per host, export a JSON summary.

ep17-csv-json-files/Get-PatchStatusFromList.ps1

18

Server audit (capstone)

A small function library auditing disks, services, and uptime with CSV/JSON output — built to extend fleet-wide.

ep18-simple-functions/Invoke-ServerAudit.ps1

19

Service baseline

Auto-start services that are stopped, non-standard logon accounts, and unquoted paths; exports a CSV baseline and diffs against it.

ep19-services-audit/Get-ServiceBaseline.ps1

20

Critical event report

Errors plus the admin event IDs that matter (dirty shutdown, kernel-power, new service) for the last N hours, as one HTML report.

ep20-event-log-basics/Get-CriticalEvents.ps1

21

Scheduled task inventory

Every task with its principal, action and triggers; flags non-Microsoft tasks and any that store a password.

ep21-scheduled-tasks/Get-TaskInventory.ps1

22

Registry baseline

Applies key/value/type from JSON, exporting every key first and reading each value back to verify. Previews with -WhatIf.

ep22-registry-administration/Set-RegistryBaseline.ps1

23

Local admin audit

Administrators membership including orphaned SIDs, diffed against your approved list. Survives the cloud-SID bug that breaks the obvious one-liner.

ep23-local-users-groups/Get-LocalAdminAudit.ps1

24

Asset inventory

Agentless hardware, OS, disk and installed-software inventory to JSON or CSV. Never touches Win32_Product.

ep24-wmi-cim-inventory/Get-AssetInventory.ps1

25

Network health check

Link state, addressing, gateway, DNS and required ports in one pass/fail object per machine.

ep25-network-configuration/Test-NetworkHealth.ps1

26

Disk space alert

Flags volumes low by percent OR absolute GB, lists the biggest folders on each, checks physical disk health. HTML report.

ep26-disk-storage/Get-DiskSpaceAlert.ps1

27

Share permission audit

Share grants plus non-inherited NTFS entries beneath each share; flags Everyone-write, orphaned SIDs and broken inheritance.

ep27-shares-ntfs-acls/Get-SharePermissionAudit.ps1

28

Print server toolkit

Printer, driver and port inventory across servers; clears jobs older than N minutes with -WhatIf first.

ep28-printers-devices/Invoke-PrintServerToolkit.ps1

29

Patch compliance

Installed AND missing updates, pending-reboot state and days-behind per machine. Proof for the auditor.

ep29-windows-updates/Get-PatchComplianceReport.ps1

30

App baseline installer

Installs or upgrades a pinned list of winget packages in machine scope, and resolves winget when running as SYSTEM.

ep30-package-management/Install-AppBaseline.ps1

31

Fleet script runner

Runs a script block across a machine list with per-host timeout, error capture and a status summary per host.

ep31-powershell-remoting/Invoke-FleetScript.ps1

32

SSH remoting setup

Six reported steps to make a box an SSH remoting target, including the strict ACL on the admin keys file that sshd demands.

ep32-openssh-windows/Install-SshRemoting.ps1

33

AD quick query

Users, computers or group members with sensible default properties and OU scoping. Never -Properties star.

ep33-active-directory-basics/Get-AdQuickQuery.ps1

34

Stale AD accounts

Inactive users and computers, old passwords and never-expiring passwords, as detail rows or one summary object.

ep34-ad-stale-accounts/Get-StaleAdAccounts.ps1

35

GPO hygiene report

Every GPO with its links and whether it contains settings; flags unlinked and empty policies. Exports full HTML documentation.

ep35-group-policy-reporting/Get-GpoHygieneReport.ps1

36

Security event watch

Failed and privileged logons, lockouts, new accounts, group changes, new services and cleared logs from one or many servers — one flat row per event, noise dropped.

ep36-windows-event-ids/Watch-SecurityEvents.ps1

37

Audit policy drift

The effective advanced audit policy, captured with auditpol and diffed subcategory by subcategory against a documented baseline, with a severity on every gap.

ep37-audit-policy/Compare-AuditPolicy.ps1

38

Lockout source finder

Reads event 4740 from the PDC emulator and names the computer sending the bad password, grouped by account and caller — nine lockouts are one row.

ep38-account-lockout/Find-LockoutSource.ps1

39

PowerShell logging audit

Script block, module and transcription logging across a fleet, plus what quietly defeats them: the PowerShell 2 engine, unlogged pwsh, open transcript shares.

ep39-powershell-logging/Get-PSLoggingStatus.ps1

40

Plaintext secret finder

Hardcoded passwords, connection strings, API keys and private keys across a script share: file, line, rule and a redacted value, with vault-migration tracking. Read-only.

ep40-credential-hygiene/Find-PlaintextSecrets.ps1

41

Script signing audit

Finds unsigned, tampered, untrusted and untimestamped scripts under a path. With -Sign it signs, timestamps and reads every signature back to verify.

ep41-script-signing/Invoke-ScriptSigning.ps1

42

AppLocker audit report

Weeks of AppLocker audit-mode events collapsed to one row per file, publisher or machine, each with a suggested rule — the pilot becomes a short rule list.

ep42-applocker-clm/Get-AppLockerAuditReport.ps1

43

JEA service desk endpoint

Lets one group restart an approved list of services and nothing else: role capability, virtual account, transcripts, registration and a verify step. Previews with -WhatIf.

ep43-jea-endpoints/New-JeaServiceDeskEndpoint.ps1

44

Defender health report

Protection state, signature and scan age, tamper protection, and every exclusion anyone quietly added, each rated by risk. One row per host.

ep44-defender-admin/Get-DefenderHealthReport.ps1

45

Firewall rule audit

Every enabled inbound allow rule with its real addresses, ports, program and service joined in, scored for the any-address, any-port pattern. Group Policy rules included.

ep45-firewall-audit/Get-FirewallRuleAudit.ps1

46

TLS configuration check

Schannel protocols, .NET strong-crypto settings and cipher suites per machine; flags legacy TLS and weak suites, and proves a handshake after the change.

ep46-tls-hardening/Get-TlsConfiguration.ps1

47

Security baseline drift

A host against a stored baseline, from an LGPO export or the live registry: Match, Drift, Missing or Extra for every setting. Ships a sample baseline to try first.

ep47-security-baselines/Compare-SecurityBaseline.ps1

48

Security audit report (capstone)

Runs the other twelve collectors and turns what they find into one timestamped, hashed HTML report: claim, evidence and remediation per control. Plans first, collects only with -Run.

ep48-audit-report/New-SecurityAuditReport.ps1

Where it sits

Copy-paste snippets from forums

  • · Untested on your version of PowerShell
  • · Print text instead of objects — dead end for the pipeline
  • · No safety rails: one typo deletes the wrong logs

PowerShell & Windows Admin Script Library

$49 · one-time
  • · 48 admin scripts, implemented + Pester-tested
  • · Runs on Windows PowerShell 5.1 AND PowerShell 7 — no modules to install
  • · Objects out of every script — pipe, sort, export
  • · Destructive scripts preview by default (-WhatIf built in)

Enterprise automation suites

  • · Licensing per node, agents to deploy
  • · Abstractions you do not control
  • · The scripting is still on you underneath

Get the library

$49 · one-time, no subscription

Buy — $49 →
  • ✓ All 48 scripts, implemented + Pester-tested
  • ✓ Windows PowerShell 5.1 and PowerShell 7+ · no modules to install
  • ✓ Comment-based help on every script — Get-Help just works
  • ✓ Safe by default — anything destructive supports -WhatIf
  • ✓ Grows with the series — later tiers added free
  • ✓ Email support at [email protected]