Published investigation guide
Active Directory
Investigate client configuration, domain discovery, member secure channels, controller advertising, services, replication, time, and logs.
Investigate domain health →
Published tool available
DNS
Name resolution, record types, resolver selection, response evidence, and the DNS dependencies that affect domains, services, and applications.
Use the read-only DNS tool →
Published investigation guide
DHCP
Scopes, leases, options, reservations, relay paths, and the client configuration that connects addressing to DNS and routing.
Investigate scope capacity →
Published storage investigation guide
Windows Server
Begin with evidence-first low-disk-space investigation. Broader roles, features, update, scheduled-work, and administration guidance remains in development.
Investigate server storage →
Published investigation guide
Replication and Domain Health
Review replication, SYSVOL and NETLOGON evidence, time, domain-controller reachability, and signals that distinguish local from domain-wide failures.
Use the evidence-first guide →
Content in development
Windows Services
Service state, dependencies, startup behavior, recovery, accounts, and the difference between a stopped service and an underlying failure.
Content in development
Event Logs
Time-bounded evidence, provider context, event correlation, useful filters, and ways to avoid treating isolated warnings as root cause.
Content in development
Networking and Connectivity
Addressing, routes, ports, firewall boundaries, name resolution, path testing, and the evidence that separates reachability from application health.
Content in development
Hybrid Identity and Dependencies
On-premises identity health, synchronization boundaries, DNS, time, authentication, and the dependencies that surface in Microsoft cloud services.
Two public tools
Windows PowerShell
Read-only discovery and stable output now include Test-KTDNS and Get-KTNetworkConfig. Other Windows, server, and Active Directory tools remain private or in development.
Explore the PowerShell Library →