Gutcheck
0.6.1
Gutcheck - an honest look inside a slow or unstable Windows PC. Performance and stability diagnostics for Windows clients, driven by data-defined Checks. A technician runs one command at a customer site and reads the report on the spot.
Minimum PowerShell version
5.1
Installation Options
Owners
Copyright
(c) 2026 MERLIN. Licensed under the MIT License.
Package Details
Author(s)
- MERLIN
Tags
Windows Diagnostics Performance Support Troubleshooting Helpdesk Hardware Reporting
Functions
PSEditions
Dependencies
This module has no dependencies.
Release Notes
0.6.1 - Four Findings say what they left unsaid.
- A default printer under a warning says what is wrong with it: offline, connection
attempts that failed, or a slow connection.
- Disk health names the counters a drive does not report, instead of leaving a gap.
- Check Definitions published shortly before midnight read "gestern um 23:58 Uhr
erstellt" rather than "1 Tag alt".
- Findings that were still in English are German: skipped and failed Checks, folder
size, name resolution, the stress test's errors.
0.6 - A Report that says what to do, and what it is talking about.
- The Report is rebuilt. What needs doing comes first: every FAIL and WARN as a card,
with what was found taken apart into lines and what to do as a list. Then every Check,
folded by area and by application; then the evidence, folded and searchable. Dark on a
screen, light on paper, and still one file that needs no network.
- Every Finding and every evidence table names the application it is about. Five tables
called "Laufzeitmessungen (Server)" now each say whose Servers.
- Event messages are whole. They used to be cut at 500 characters, in mid-sentence.
- What stands under "Was tun" says what to do: the Hints for crash codes named the code,
in English, and are now instructions. An application's crashes are counted in words.
- findings.csv has two new columns at the end, App and CheckName.
- A program on a share does not crash the second its connection drops: it runs on from
memory and dies when it next reads from the share, minutes later. A drop up to ten
minutes before a crash now counts, and so does the connection being re-established
within two minutes after it. On the notebook this was built for, that is six of eight
crashes where it used to be one.
- Lost connections are counted, not the events that report them: one loss is logged as
five events or more, and the Report said a Server had dropped 86 times when it had
dropped sixteen. The Finding now says both numbers.
- A drive letter is no longer listed as a Server that dropped.
0.5.2 - Which Check Definitions did this Run use?
- Every Report shows a Kennung beside the version of its Check Definitions: eight
characters worked out from the document the Run read. Two Reports with the same Kennung
used the same Checks, whether or not anybody updated the version.
- A document that carries a time says when today it was created.
0.5.1 - A click no longer freezes a Run.
- A click in the admin window, or in the window Gutcheck was started from, started a text
selection, and Windows then held the Run still until somebody pressed Enter. Gutcheck
switches that behaviour off for its windows while a Run lasts, and puts the Technician's
own window back as it was afterwards.
0.5 - Did the application crash because its server dropped?
- A Run finds out which programs depend on which Servers, with no Check Definition per
application: running programs and the DLLs they load, services, scheduled tasks,
startup entries, shortcuts, redirected folders, offline files, printers, ODBC sources
and the configuration files beside a program. Each Server is measured. A program
running from a share is a warning before the first crash.
- Crashes are counted as incidents - the events of one crash are one row - and every
program that crashes repeatedly gets a Finding of its own: where it runs from, what
the exceptions were, how many incidents coincided with a network disruption, and a
verdict drawn from that evidence. Where the evidence does not reach, it says so.
- What Windows logged about the network going away is read with admin rights: SMB
disconnects and timeouts, adapter and Wi-Fi drops, standby and resume.
- Network adapters: whether the machine is on a USB adapter, and its power saving.
- Installed .NET versions, held against the version a crash happened on.
- The admin part runs again. In 0.4 it ended within a second on every machine, without
results and without saying why.
- No more false alarms from healthy-volume messages counted as disk errors, old driver
hangs reported again and again, or one antivirus registered several times.
0.4 - Progress while a Check waits.
- A Run shows a bar for the Run - which Check, of how many - and one beneath it while a
Check waits: sampling, pings and connections, the disk write test, the stress test and
the admin part. A Run no longer looks hung.
- The banner says "Trust your gut. Check everything."
0.3 - Outlook connectivity.
- Outlook connectivity, for Microsoft 365 and on-premises Exchange, without anybody's
password:
- Autodiscover: per mail domain, whether its DNS and endpoints answer the way Outlook
needs, whether the mailbox is in Exchange Online, registry overrides that bend the
lookup, and an Active Directory pointer still aiming on-premises after a migration.
- HttpsEndpoint: whether an HTTPS service is reachable end to end - not blocked, not
held by a proxy, not intercepted - with a valid certificate. Ships for Exchange Online
and the Microsoft sign-in service; usable for any application's endpoint.
- OutlookAuth: modern authentication, the Windows sign-in broker, MAPI over HTTP,
client TLS 1.2, sign-in errors, the Entra device and its sign-in token, and for
on-premises Exchange the NTLM level and stale saved Office credentials.
- Mail files on a network drive, sizes against the limit Outlook actually enforces,
lost connections to Exchange; whether the Office build is still supported for its
channel and the product for Microsoft 365; the proxy Outlook's background requests
use, against the user's.
- The application list shows in two columns when the window allows.
- Mail files are found the same way on Windows PowerShell 5.1 as on PowerShell 7; 5.1
listed every file in the Outlook folder as one.
0.2 - Services, printing and Group Policy.
- Service: whether the Windows services an application depends on are installed, running
and set to start the way they should, and how often they crashed. Configured per
application in the Check Definitions; shipped for DATEV, Lexware, Sage, FortiClient and
GlobalProtect.
- Printing: the print spooler, whether the default printer can be reached - Office waits
on it whenever a document opens - offline printers, stuck jobs and print service errors.
- GroupPolicy: how long Group Policy holds up boot and logon, the slowest and failing
extensions, slow-link detection, and a domain controller that could not be reached.
Needs the admin prompt.
- Applications a Run now offers: Lexware, Sage, ADDISON, StarMoney, SFirm, DocuWare,
ELO Java Client and ELOoffice; SwyxIt!, estos ProCall and STARFACE; Citrix Workspace,
FortiClient, GlobalProtect and Securepoint VPN; pcvisit; Securepoint Antivirus, ESET,
G DATA and Sophos; Server-Eye. Identifiers are sourced in docs/research.
- A Service Check can name OptionalServices: reported with their state, never judged for
being stopped or disabled - the Server-Eye OCC Connector runs on one machine per site.
- An application whose installer records no install path is no longer merged with another
one that does not either, so an old and a new VPN client side by side both appear.
0.1 - Gutcheck is a module.
The single-file script is retired. Everything it examined is now a Check described by
data: a Check Definition names a Kind the module implements and supplies that Kind's
parameters, and every threshold is one of those parameters rather than a literal.
- One command, one Report, as before. Technicians install once and update with the same
command they installed with.
- The privileged half of a Run happens behind one UAC prompt, so an admin colleague can
enter their own credentials while the rest of the Run stays in the technician's session.
- Every Finding states the Privilege it was gathered with, and Checks that could not run
appear in the Report rather than being absent from it.
- Every Report states where its Check Definitions came from, which version they were and
how old.
Upgrading from the script: see the project page. There is no compatibility shim.
FileList
- Gutcheck.nuspec
- Definitions\checks.json
- Gutcheck.psd1
- Gutcheck.psm1
- Invoke-GutcheckElevated.ps1
- Private\AppSelection.ps1
- Private\Autoupdate.ps1
- Private\Console.ps1
- Private\Data.ps1
- Private\Definition.ps1
- Private\Elevation.ps1
- Private\Finding.ps1
- Private\KeepSignIn.ps1
- Private\Kind.ps1
- Private\Kinds\App.ps1
- Private\Kinds\Autodiscover.ps1
- Private\Kinds\Battery.ps1
- Private\Kinds\BootPerformance.ps1
- Private\Kinds\Cpu.ps1
- Private\Kinds\CrashDump.ps1
- Private\Kinds\DiskHealth.ps1
- Private\Kinds\DiskTest.ps1
- Private\Kinds\DotNet.ps1
- Private\Kinds\FolderSize.ps1
- Private\Kinds\GroupPolicy.ps1
- Private\Kinds\HttpsEndpoint.ps1
- Private\Kinds\ImageIntegrity.ps1
- Private\Kinds\Memory.ps1
- Private\Kinds\Network.ps1
- Private\Kinds\NetworkDependency.ps1
- Private\Kinds\NetworkDisruption.ps1
- Private\Kinds\Odbc.ps1
- Private\Kinds\OfficeAddins.ps1
- Private\Kinds\OutlookAuth.ps1
- Private\Kinds\OutlookData.ps1
- Private\Kinds\Power.ps1
- Private\Kinds\Printing.ps1
- Private\Kinds\Security.ps1
- Private\Kinds\Server.ps1
- Private\Kinds\Service.ps1
- Private\Kinds\Stability.ps1
- Private\Kinds\Startup.ps1
- Private\Kinds\Storage.ps1
- Private\Kinds\Stress.ps1
- Private\Kinds\System.ps1
- Private\Kinds\Temperature.ps1
- Private\Kinds\Updates.ps1
- Private\Parameter.ps1
- Private\Probe.ps1
- Private\Progress.ps1
- Private\PublishedDefinitions.ps1
- Private\QrCode.ps1
- Private\Report.ps1
- Private\Sampling.ps1
- Private\Section.ps1
- Private\Text.ps1
- Private\TokenCache.ps1
- Public\Invoke-Gutcheck.ps1
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 0.11.1 | 8 | 10/10/2026 |
| 0.11 | 5 | 10/10/2026 |
| 0.10 | 5 | 10/10/2026 |
| 0.9.1 | 10 | 10/10/2026 |
| 0.9 | 8 | 10/10/2026 |
| 0.8.3 | 5 | 10/9/2026 |
| 0.8.2 | 4 | 10/9/2026 |
| 0.8.1 | 3 | 10/9/2026 |
| 0.8 | 3 | 10/9/2026 |
| 0.7.2 | 4 | 10/9/2026 |
| 0.7.1 | 5 | 10/9/2026 |
| 0.6.2 | 6 | 10/8/2026 |
| 0.6.1 (current version) | 5 | 10/8/2026 |
| 0.6 | 4 | 10/8/2026 |
| 0.5.2 | 6 | 10/7/2026 |
| 0.5.1 | 8 | 10/7/2026 |
| 0.5 | 5 | 10/7/2026 |
| 0.4 | 19 | 9/25/2026 |
| 0.3 | 7 | 9/25/2026 |
| 0.2 | 7 | 9/24/2026 |