Gutcheck
0.8.3
Gutcheck - an honest look inside a slow or unstable Windows PC. Performance and stability diagnostics for Windows clients, driven by data-defined Checks. A technician runs one command at a customer site and reads the report on the spot.
Minimum PowerShell version
5.1
Installation Options
Owners
Copyright
(c) 2026 MERLIN. Licensed under the MIT License.
Package Details
Author(s)
- MERLIN
Tags
Windows Diagnostics Performance Support Troubleshooting Helpdesk Hardware Reporting
Functions
PSEditions
Dependencies
This module has no dependencies.
Release Notes
0.8.3 - Hints that fit the machine, and a Run in the right session.
- A Run started "as administrator" says so before it examines anything and asks whether
to start again in the logged-on user's session, where it asks for the rights itself.
Started in another account it would read the wrong profile; in the user's own it would
not see the user's network drives. -NoUserSwitch keeps a Run where it was started.
- What to do about a lossy ping or a slow Server follows how the machine reaches it: by
cable, Wi-Fi or VPN, inside its own network or beyond. A machine at a cable is no
longer told to try a cable. One lost ping is a WARN and not a FAIL.
- Blue screens and live kernel events say what the code means and what to do about it,
where "2: 0x193 x2" said neither.
- Scheduled tasks that are not Windows' own are listed with account, trigger, last run
and how it ended. A program a task starts from a share says so and points there.
- An ODBC data source is named with whose driver it uses, which is as near to the
program as a data source gets.
- Every Finding in the Report has a button that copies it as text, for a ticket.
- The Report says "Notiz" where it said "Was tun".
0.8.2 - A stress test that loads the machine.
- The stress test could not load a processor fully: its load was PowerShell loops, which
reach about three quarters of a healthy machine, and the Report then said that
something was limiting the CPU. The load is compiled threads now and reaches 100 %.
"Lasttest: Durchsatz" is on another scale; numbers from earlier Reports do not compare.
- A Server that lost its connection or could not be reached is named by name and by
address, and the evidence sets apart which of the two the machine asked for.
- An example in a code comment no longer uses a name from a real machine.
0.8.1 - What four machines in one afternoon showed.
- Disk errors name the drive: which disk or volume, how many events, and when. Errors on
a drive the machine no longer has - a memory stick, an external disk - no longer fail
the machine, and with admin rights the drive is named by model and serial number.
- A connection to a Server that was lost and one that never came about are two Findings.
A retired server that something still asks for at every start is no longer listed among
the Servers whose connection dropped.
- Two antivirus products are confirmed by asking Defender itself: listed as active in
Security Center, and passive by its own account, it is not a second scanner.
- A Run started in another account than the user's says so in a banner under the
machine's box, and puts its folder on the Desktop all users share.
- A Run that was given admin rights reads the network adapters' power management in the
admin part; "nicht gelesen: Get-NetAdapterPowerManagement" appeared in spite of them.
0.8 - Which machine this is, at the top of the Report.
- A box under the machine's name says what a reader wants first: manufacturer, model,
serial number, board and BIOS; the Windows edition, version, build, when it was
installed and last started, and its domain; processor, memory, graphics and drives.
- The network as ipconfig /all says it, for every adapter that has an address: IPv4 and
IPv6 addresses, gateway, DNS servers, DHCP server and lease, MAC address, link speed.
The same as a table among the evidence.
- The graphics driver with its version and date, and a table of every driver that is
not Microsoft's.
0.7.2 - An update that reaches the window it was started from.
- A PowerShell window keeps the Gutcheck it loaded for as long as it is open. One that
had loaded an old version said "Aktualisierung von 0.4 auf 0.7.1" on every Run,
installed the new version again and started a second process - each time. A Run now
looks at what is installed, installs nothing that is there, and moves the window to
the new version when the restarted Run has finished. A window that still has an older
version loaded needs "Remove-Module Gutcheck", or closing, once more.
- A Run says that it is asking the PowerShell Gallery for a newer version, and what the
Gallery answered. The question takes a few seconds, and the window used to stay empty.
0.7.1 - The database server an application talks to, and what it wrote into its own log.
- AppConnection: the SQL Server and the web service an application is configured for,
read from the application's own configuration file - never its user name or password.
Each is measured like any Server, and a SQL Server is asked who it is: version, whether
it is still supported, whether it encrypts, how long it takes to answer. A named
instance is looked up through the SQL Server Browser, as the application does.
- AppLog: the errors an application caught and wrote into its own log file, which Windows
knows nothing about - counted for the period and grouped by where they came from.
- AppRuntime: which .NET an application runs on. One that ships its own runtime is not
helped by updating .NET on the machine; one that needs an installed runtime is held
against what is installed. Either is held against the day Microsoft's support ends.
- Shipped for c-entron.NET, and usable for any application that keeps its server in an
XML file, logs to a text file, or is built on .NET.
- A Hint that sends a Technician to a piece of evidence names it by its title, and the
Report makes a link of it that opens the piece. "Die Liste der Verzögerungen unten"
named nothing anybody could find.
0.6.2 - A mailbox is where Outlook found it.
- A mailbox on the company's own Exchange is no longer taken for one in Microsoft 365
because Microsoft knows its address too, and the Autodiscover entry in Active Directory
it is found through is no longer reported as left over from a migration. Gutcheck reads
where Outlook itself was last told the mailbox is. With one mailbox on each side, the
Report names which is where.
- Outlook's cached Autodiscover answers are listed. They are hidden files, and the table
was empty on every Run before this one.
- The evidence at the end of the Report is grouped by what was checked: every
application's processes together, every application's servers together.
- A crashing program is held against network disruptions only where the network concerns
it: it runs or loads from a share, its exceptions are those of a lost share, or a crash
did coincide with a disruption. A program installed on the machine is no longer told to
enlarge its SMB event logs, nor that the evidence against it is incomplete.
0.6.1 - Four Findings say what they left unsaid.
- A default printer under a warning says what is wrong with it: offline, connection
attempts that failed, or a slow connection.
- Disk health names the counters a drive does not report, instead of leaving a gap.
- Check Definitions published shortly before midnight read "gestern um 23:58 Uhr
erstellt" rather than "1 Tag alt".
- Findings that were still in English are German: skipped and failed Checks, folder
size, name resolution, the stress test's errors.
0.6 - A Report that says what to do, and what it is talking about.
- The Report is rebuilt. What needs doing comes first: every FAIL and WARN as a card,
with what was found taken apart into lines and what to do as a list. Then every Check,
folded by area and by application; then the evidence, folded and searchable. Dark on a
screen, light on paper, and still one file that needs no network.
- Every Finding and every evidence table names the application it is about. Five tables
called "Laufzeitmessungen (Server)" now each say whose Servers.
- Event messages are whole. They used to be cut at 500 characters, in mid-sentence.
- What stands under "Was tun" says what to do: the Hints for crash codes named the code,
in English, and are now instructions. An application's crashes are counted in words.
- findings.csv has two new columns at the end, App and CheckName.
- A program on a share does not crash the second its connection drops: it runs on from
memory and dies when it next reads from the share, minutes later. A drop up to ten
minutes before a crash now counts, and so does the connection being re-established
within two minutes after it. On the notebook this was built for, that is six of eight
crashes where it used to be one.
- Lost connections are counted, not the events that report them: one loss is logged as
five events or more, and the Report said a Server had dropped 86 times when it had
dropped sixteen. The Finding now says both numbers.
- A drive letter is no longer listed as a Server that dropped.
Versions 0.1 to 0.5.2: https://github.com/kort3x/gutcheck/blob/main/docs/release-notes-earlier.md
FileList
- Gutcheck.nuspec
- Definitions\checks.json
- Gutcheck.psd1
- Gutcheck.psm1
- Invoke-GutcheckElevated.ps1
- Private\AppSelection.ps1
- Private\Autoupdate.ps1
- Private\Console.ps1
- Private\Data.ps1
- Private\Definition.ps1
- Private\Elevation.ps1
- Private\Finding.ps1
- Private\KeepSignIn.ps1
- Private\Kind.ps1
- Private\Kinds\App.ps1
- Private\Kinds\AppConnection.ps1
- Private\Kinds\AppLog.ps1
- Private\Kinds\AppRuntime.ps1
- Private\Kinds\Autodiscover.ps1
- Private\Kinds\Battery.ps1
- Private\Kinds\BootPerformance.ps1
- Private\Kinds\Cpu.ps1
- Private\Kinds\CrashDump.ps1
- Private\Kinds\DiskHealth.ps1
- Private\Kinds\DiskTest.ps1
- Private\Kinds\DotNet.ps1
- Private\Kinds\FolderSize.ps1
- Private\Kinds\GroupPolicy.ps1
- Private\Kinds\HttpsEndpoint.ps1
- Private\Kinds\ImageIntegrity.ps1
- Private\Kinds\Memory.ps1
- Private\Kinds\Network.ps1
- Private\Kinds\NetworkDependency.ps1
- Private\Kinds\NetworkDisruption.ps1
- Private\Kinds\Odbc.ps1
- Private\Kinds\OfficeAddins.ps1
- Private\Kinds\OutlookAuth.ps1
- Private\Kinds\OutlookData.ps1
- Private\Kinds\Power.ps1
- Private\Kinds\Printing.ps1
- Private\Kinds\Security.ps1
- Private\Kinds\Server.ps1
- Private\Kinds\Service.ps1
- Private\Kinds\Stability.ps1
- Private\Kinds\Startup.ps1
- Private\Kinds\Storage.ps1
- Private\Kinds\Stress.ps1
- Private\Kinds\System.ps1
- Private\Kinds\Temperature.ps1
- Private\Kinds\Updates.ps1
- Private\Parameter.ps1
- Private\Probe.ps1
- Private\Progress.ps1
- Private\PublishedDefinitions.ps1
- Private\QrCode.ps1
- Private\Report.ps1
- Private\Sampling.ps1
- Private\Section.ps1
- Private\Text.ps1
- Private\TokenCache.ps1
- Public\Invoke-Gutcheck.ps1
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 0.11.1 | 8 | 10/10/2026 |
| 0.11 | 5 | 10/10/2026 |
| 0.10 | 5 | 10/10/2026 |
| 0.9.1 | 10 | 10/10/2026 |
| 0.9 | 8 | 10/10/2026 |
| 0.8.3 (current version) | 5 | 10/9/2026 |
| 0.8.2 | 4 | 10/9/2026 |
| 0.8.1 | 3 | 10/9/2026 |
| 0.8 | 3 | 10/9/2026 |
| 0.7.2 | 4 | 10/9/2026 |
| 0.7.1 | 5 | 10/9/2026 |
| 0.6.2 | 6 | 10/8/2026 |
| 0.6.1 | 5 | 10/8/2026 |
| 0.6 | 4 | 10/8/2026 |
| 0.5.2 | 6 | 10/7/2026 |
| 0.5.1 | 8 | 10/7/2026 |
| 0.5 | 5 | 10/7/2026 |
| 0.4 | 19 | 9/25/2026 |
| 0.3 | 7 | 9/25/2026 |
| 0.2 | 7 | 9/24/2026 |