Published investigation guide
Active Directory
Investigate client configuration, domain discovery, member secure channels, controller advertising, services, replication, time, and logs.
Investigate domain health →
Published tool available
DNS
Name resolution, record types, resolver selection, response evidence, and the DNS dependencies that affect domains, services, and applications.
Use the read-only DNS tool →
Content in development
DHCP
Scopes, leases, options, reservations, relay paths, and the client configuration that connects addressing to DNS and routing.
Content in development
Windows Server
Roles, features, dependencies, update state, storage, scheduled work, and practical server administration evidence.
Published investigation guide
Replication and Domain Health
Review replication, SYSVOL and NETLOGON evidence, time, domain-controller reachability, and signals that distinguish local from domain-wide failures.
Use the evidence-first guide →
Content in development
Windows Services
Service state, dependencies, startup behavior, recovery, accounts, and the difference between a stopped service and an underlying failure.
Content in development
Event Logs
Time-bounded evidence, provider context, event correlation, useful filters, and ways to avoid treating isolated warnings as root cause.
Content in development
Networking and Connectivity
Addressing, routes, ports, firewall boundaries, name resolution, path testing, and the evidence that separates reachability from application health.
Content in development
Hybrid Identity and Dependencies
On-premises identity health, synchronization boundaries, DNS, time, authentication, and the dependencies that surface in Microsoft cloud services.
One public tool
Windows PowerShell
Read-only discovery and stable output begin with Test-KTDNS. Other Windows, server, and Active Directory tools remain private or in development.
Explore the PowerShell Library →