Skip to content

Latest commit

Β 

History

31 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸš€ ITechBR Windows Maintenance

PowerShell Windows Version Status License

Automated Windows maintenance, repair and update workflow for technical service and enterprise infrastructure environments.


πŸ‘¨β€πŸ’» Author

Ernesto Nurnberg
IT Infrastructure & Technical Support Specialist
Founder of ITechBR
Windows Maintenance Automation


πŸš€ Overview

This project provides a real-world automation workflow for Windows maintenance and repair.

Designed to:

  • Reduce manual maintenance time
  • Standardize technician workflows
  • Improve system reliability
  • Automate Windows repair and update routines
  • Generate structured logs for traceability

🧠 Key Highlights

  • Enterprise Deployment Ready: Designed to seamlessly integrate into corporate OS staging, provisioning pipelines, and reference machine engineering.
  • Headless Operation Flow: Fully scriptable and policy-compliant automation that runs cleanly via administrative shells or remote deployment agents.
  • Multi-Language Parsing Resiliency: Resolves OS language locale boundaries during runtime text audits, ensuring reliable diagnostic capture across localized Windows installations.
  • Telemetry-Ready Records: Generates persistent, auditable execution logs optimized for compliance mapping and hardware degradation analysis.

πŸ›  Technologies Used

  • PowerShell
  • Batch scripting
  • Windows Update API
  • DISM
  • SFC
  • CHKDSK
  • Windows 10 / 11

βš™οΈ Features

🧼 System Cleanup

  • Temporary files cleanup
  • User temp directory cleanup
  • Prefetch cleanup
  • Recycle bin cleanup
  • Windows Update cache cleanup
  • Windows catalog cache cleanup
  • Structured logging with timestamps

πŸ”„ Windows Update Automation

  • Automatic update search
  • Automatic update download
  • Automatic update installation
  • EULA acceptance when required
  • Restart detection after update installation
  • Fully unattended execution

πŸ›  Windows Repair

  • Conditional DISM RestoreHealth: Runs ScanHealth first; executes RestoreHealth only when component-store corruption is repairable (exit code 10). Healthy systems skip RestoreHealth entirely.
  • Storage preflight: Configurable minimum free space threshold (default 10 GB, -MinimumFreeGB parameter) before RestoreHealth. Runs lightweight cleanup and re-checks on failure.
  • Storage telemetry: Captures free space (GB and %) at 5 pipeline points β€” before Repair, after ScanHealth, before/after RestoreHealth, after StartComponentCleanup.
  • RestartRequired detection: Reports when DISM servicing requires reboot (exit code 3010).
  • DISM StartComponentCleanup: Post-repair component store cleanup.
  • System File Checker: sfc /scannow with multi-language output parsing.
  • System volume scan: Repair-Volume for online volume integrity.
  • Error handling and execution status reporting.

πŸ’½ Disk Maintenance

  • Deep CHKDSK scheduling for the next boot
  • Automatic restart when required
  • Post-restart CHKDSK result collection
  • CHKDSK output appended to the same maintenance log

⚑ Power Configuration Handling

  • Temporarily disables hibernation during maintenance
  • Temporarily disables Fast Startup during maintenance
  • Restores hibernation before finishing (or after CHKDSK post-reboot collector)
  • Restores Fast Startup before finishing (or after CHKDSK post-reboot collector)
  • Prevents clients from noticing slower boot behavior after service

🧾 Logging

A structured logging system is implemented across the workflow.

  • Logs are stored in: C:\Logs
  • Files are generated using timestamps
  • Maintenance logs use the itechbr prefix
  • CHKDSK results are appended after restart when available

Example:

C:\Logs
└── itechbr-20260515_081500.log

This enables:

  • Full execution traceability
  • Easier troubleshooting
  • Historical tracking of maintenance tasks
  • Clear service reporting

πŸ” Automated Workflow

The script executes a deterministic, sequential pipeline designed for unattended operations:

[Init] ──> [Power Staging] ──> [Inventory] ──> [Deep Clean] ──> [Conditional Repair] ──> [OS Patching] ──> [Disk Check] ──> [Unified Reboot] ──> [Rollback State]
  1. Privilege & Environment Initialization: Validates administrative privileges, generates a timestamped execution log path (C:\Logs), and provisions background logging structures.
  2. Power Subsystem Staging: Temporarily captures initial state and suspends Hibernation and Fast Startup (powercfg.exe) to isolate the OS from hybrid boot locks during maintenance tasks.
  3. System Inventory: Collects hardware, OS, software, and asset inventory for baseline documentation.
  4. Storage & Cache Purging: Executes automated system volume cleanup (cleanmgr.exe /sagerun) and purges temporary files, system distribution caches, and update download folders.
  5. Conditional Component Store Repair:
    • Runs DISM ScanHealth to evaluate component store integrity.
    • Executes RestoreHealth only when corruption is repairable (exit code 10); skips on healthy systems.
    • Storage preflight checks free space (configurable, default 10 GB) before RestoreHealth; runs lightweight cleanup on failure.
    • Captures storage telemetry at 5 pipeline points (before/after each DISM phase).
    • Runs StartComponentCleanup post-repair.
  6. System File Verification: Runs sfc /scannow with automated localized output parsing (supporting multi-language responses).
  7. Automated OS Patching: Interface orchestration with the Windows Update API to search, accept EULAs, download, and install pending security updates without manual prompts.
  8. Post-Boot Disk Diagnostics: Schedules deep file system diagnostics (CHKDSK) for the next boot sequence and registers a transient persistence script (Scheduled Task) to aggregate post-reboot disk results into the primary session log.
  9. Unified Reboot Coordination: Single final restart consolidates all reboot reasons β€” DISM servicing, Windows Update, CHKDSK scheduled.
  10. Power Configuration Rollback: Restores original machine hibernation and fast-startup states (after CHKDSK collector completes) to preserve the native end-user boot experience.

🏭 Production Ready

This workflow is meticulously engineered for production-grade IT infrastructures:

  • Zero Prompt Intervention: Completely unattended execution model, eliminating manual technician interaction and GUI blocking.
  • Deterministic Behavior: Consistent execution profiles across heterogeneous hardware setups and different Windows 10/11 builds.
  • Observability Framework: Built-in structured logging system that acts as a telemetry foundation for historical system tracking.
  • Fail-Safe State Containment: Hardened error handling (trap blocks) that triggers automated environmental rollbacks (restoring power and subsystem states) if execution breaks unexpectedly.

πŸ“‚ Project Structure

itechbr-windows-maintenance/
β”‚
β”œβ”€β”€ README.md
β”œβ”€β”€ LICENSE
β”œβ”€β”€ .gitignore
β”‚
β”œβ”€β”€ scripts/
β”‚   β”œβ”€β”€ ITech.bat
β”‚   β”œβ”€β”€ main.ps1                    # Modular orchestrator (v2.3.1)
β”‚   β”œβ”€β”€ ITech-Maintenance.ps1       # Legacy monolithic script
β”‚   β”‚
β”‚   β”œβ”€β”€ core/                       # Infrastructure modules
β”‚   β”‚   β”œβ”€β”€ Logging.psm1
β”‚   β”‚   β”œβ”€β”€ Reporting.psm1
β”‚   β”‚   β”œβ”€β”€ Security.psm1
β”‚   β”‚   β”œβ”€β”€ NativeCommand.psm1
β”‚   β”‚   β”œβ”€β”€ PowerManagement.psm1
β”‚   β”‚   └── TextNormalization.psm1
β”‚   β”‚
β”‚   β”œβ”€β”€ modules/                    # Functional modules
β”‚   β”‚   β”œβ”€β”€ CleanUp.psm1
β”‚   β”‚   β”œβ”€β”€ Diagnostics.psm1
β”‚   β”‚   β”œβ”€β”€ Repair.psm1
β”‚   β”‚   β”œβ”€β”€ WindowsUpdate.psm1
β”‚   β”‚   └── Inventory.psm1
β”‚   β”‚
β”‚   └── tests/                      # Test suites
β”‚       β”œβ”€β”€ All.Tests.ps1
β”‚       β”œβ”€β”€ Core.Tests.ps1
β”‚       β”œβ”€β”€ Logging.Tests.ps1
β”‚       β”œβ”€β”€ Security.Tests.ps1
β”‚       β”œβ”€β”€ Reporting.Tests.ps1
β”‚       β”œβ”€β”€ NativeCommand.Tests.ps1
β”‚       β”œβ”€β”€ Diagnostics.Tests.ps1
β”‚       β”œβ”€β”€ Inventory.Tests.ps1
β”‚       β”œβ”€β”€ Cleanup.Tests.ps1
β”‚       └── chkdsk-Test.ps1
β”‚
β”œβ”€β”€ docs/
β”‚   β”œβ”€β”€ changelog.md
β”‚   └── how-it-works.md
β”‚
└── examples/
    └── sample-log.txt

▢️ Usage

To execute the modular automation framework with administrative privileges:

scripts\ITech.bat

Or invoke the PowerShell orchestrator directly:

.\scripts\main.ps1               # Production orchestrator (v2.3.1)

Script Parameters

# Run validation self-test suite
.\scripts\main.ps1 -SelfTest

# Block automatic reboots after patch orchestration
.\scripts\main.ps1 -NoRestart

# Bypass Windows Update pipeline
.\scripts\main.ps1 -SkipWindowsUpdate

# Skip CHKDSK scheduling
.\scripts\main.ps1 -SkipChkdsk

# Set minimum free space (GB) for DISM RestoreHealth preflight (default: 10)
.\scripts\main.ps1 -MinimumFreeGB 15

Legacy Script (kept for rollback)

.\scripts\ITech-Maintenance.ps1 -SelfTest  # Legacy versions < 2.0

πŸ“Œ Use Cases

🏒 Corporate Infrastructure & SysAdmin

  • Golden Image Staging: Automated preparation, deep cleanup, and optimization of Windows reference machines before disk image capture (Sysprep/Clonezilla).
  • Post-Deployment Validation: Unattended validation runner (-SelfTest) to ensure core OS integrity, logging access, and subsystem functionality immediately after mass provisioning.
  • Enterprise Patch Management: Safe, unattended execution of critical Windows Updates across staged environments without requiring manual technician GUI interaction.
  • SysAdmin Staging Routines: Automated compliance run for newly unboxed hardware units prior to enterprise enrollment.

πŸ› οΈ Technical Service & Field Operations

  • Preventive Maintenance Workflows: Standardized routine for client devices to maximize operating system reliability and longevity.
  • Automated OS Recovery & Repair: One-click deployment script to systematically isolate and repair corrupted system files (DISM/SFC) and volume errors.
  • Post-Service Optimization: Deep system cache purging and power settings restoration to deliver a clean, fast, and stable OS to the end user.
  • Client Device Preparation: Turnkey delivery preparation script guaranteeing optimized state delivery before client handoff.

πŸ“š Documentation

Detailed documentation is available in the docs directory.


⚠️ Requirements

  • Administrator privileges
  • Windows 10 or Windows 11
  • Windows PowerShell 5.1 or newer
  • Internet connection for Windows Update

πŸ“ˆ Future Improvements

  • HTML maintenance report generation
  • Remote execution support
  • Configurable task profiles

πŸ“„ License

MIT License

About

Automated Windows maintenance, repair, and update workflow designed for IT service environments and system administration tasks

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages