Start here
TechDeck is a portable Windows IT toolkit. It runs out of a folder — on a USB stick, or copied to a desktop — and installs nothing into Windows. Close it and the machine is as you found it. Every screen is built on the same rule: it tells you what it actually measured, and when it could not measure something it says so in words rather than showing a blank you might read as good news.
Running it
- Copy the
TechDeckfolder anywhere, or run it straight from the stick. - Run
TechDeck.vbs. A browser window opens onto the app — that window is the application, so closing it shuts TechDeck down. - Check the badge under the name in the sidebar.
adminmeans you have full readings; without it several screens can only report part of what is there, and each says which part. - Pick a screen from the sidebar. Nothing runs until you open it, so opening a screen is always safe.
- Use
Export Reportin the bottom-left to save everything found into one file to hand over or keep on a job sheet. - Use
Shut Down TechDeckrather than just closing the tab, so anything it started in the background is stopped and cleaned up properly.
Worth knowing
- To run as administrator: right-click
TechDeck.vbsand choose Run as administrator. Processor and motherboard temperatures, drive health counters, some security readings and the Test Lab all need it. Everything else works without. - TechDeck keeps its working files in
C:\TechDeck— downloaded tools, harvested drivers, virtual disks. That is one place, deliberately, so a technician can find and clear it. - Anything slow tells you what it is doing and what is normal for that step. If a screen looks stuck, read the sentence under the bar before assuming it has hung.
- This manual is generated from the application itself at every release, so it cannot drift from what the software does. A screen added without a manual page stops the release.
Network
Adapters, connectivity chain and repairs

What it is
Network Doctor tests every link between this PC and a working web connection in order, and names the first one that breaks. The headline is the Connectivity Chain: six nodes — This PC, Router, Internet, DNS Server, Name Lookup, Web (443) — that light up one at a time as each test lands, followed by a verdict box and a table of Link / Result / What it means. Below it a second panel holds five tabs: Adapters, Ping / Trace / DNS, Wi-Fi, Connections and Repairs.
When you would use it
When somebody says the internet is down, is slow, or "connected but nothing loads". Run the chain first — it replaces reading ipconfig output by hand — then use the tabs to confirm the detail or to apply a repair.
How to use it
- Press
Run full test. The six nodes turn from idle to a result one by one; the whole run takes a few seconds when everything answers, and up to about fifteen when links are timing out. - Read the verdict box.
Chain breaks at: <link>names the first failure, and the sentence under it is the diagnosis. The table underneath gives every link with OK, DEGRADED or FAILED plus a plain-English explanation. - Click any node in the chain graphic to open its full explanation in a dialog; hovering shows the same text as a tooltip.
- Open
Adaptersfor each adapter's IPv4, gateway, DNS, MAC, MTU and DHCP-or-static state. A redAPIPA — DHCP failedpill means the machine took a 169.254.x.x address because no DHCP server answered. - Open
Ping / Trace / DNSto test a specific host. The top box doesPing(4 packets, giving average, min, max, jitter and packet loss) andTrace route(hops stream in live as they are found). The lower box doesLook up, which queries A, AAAA, MX, TXT, NS, CNAME and SOA in one pass and reverse-resolves the first A record. - Open
Wi-Fifor signal percentage, SSID, band, channel, radio type, authentication, cipher and link rate.Scan nearby networkslists everything in range and flags any channel carrying three or more networks as congested. - Open
Connectionsfor every established TCP connection with the process that owns it — the fastest way to spot an application beaconing somewhere it should not. - Open
Repairsand pressRunon the card you want. Six are offered: flush DNS cache, release and renew DHCP, clear ARP cache, clear proxy settings, reset Winsock catalog, reset TCP/IP stack. The output appears underneath.
Worth knowing
Trace routedefaults to 20 hops (30 maximum) and waits 1500ms per hop. Against a destination that does not answer it can run for a couple of minutes; hops appear as they arrive so you can see it is still working.- The chain tests fixed public targets:
1.1.1.1for the Internet link, andwww.microsoft.comfor bothName LookupandWeb (443). On a network that allowlists destinations, those two can fail while the customer's own sites work. - The
Adapterstab lists virtual adapters as well as physical ones — Hyper-V switches, VPN adapters and similar carry avirtualpill. Only physical adapters that are up count towards the chain'sThis PCnode. - In
Connections, a process shown asunknownmeans the owning process ended between the two queries or its name could not be read; the connection itself is still real. - The
Wi-Fitab readsnetsh wlan show interfaces. On a machine with no wireless hardware it shows "No wireless adapter" rather than an empty table.Scan nearby networkscan take up to 25 seconds.
Traps
- The
Repairstab needs Administrator. Without it a yellow banner appears, everyRunbutton is disabled, and the server refuses the action with "Network repairs require Administrator". Close TechDeck and relaunchTechDeck.batelevated. Release and renew DHCPrunsipconfig /releasethenipconfig /renew. The machine has no IP address between the two. Never run it over Remote Desktop or any remote session that arrives on the adapter you are repairing — you will disconnect yourself and may not get back in.Reset Winsock catalogandReset TCP/IP stackboth carry areboot neededbadge and mean it. Networking can behave strangely until the machine is restarted, so do not hand the PC back between the repair and the reboot.- A DEGRADED
DNS Serverrow only means that server did not answer a ping. Plenty of resolvers drop ICMP and resolve names perfectly. The row that actually proves DNS works isName Lookup. - A FAILED
Routerrow does not always mean the router is down — many routers and most corporate firewalls refuse ICMP. IfInternetandWeb (443)are green, the router is fine and only the ping was blocked.
Technical detail
Implemented by app/server/modules/15-network.js.
Actions it exposes: adapters, chain, connections, dnsLookup, ping, repair, traceroute, wifi, wifiScan
Network Scan
Find every device on the network and work out what each one is

What it is
Network Scan finds every device on a network range and works out what each one is. It fills in the Range box with this machine's own subnet, and one press of Scan runs several discovery passes — the address (ARP) table, a sweep that makes every address identify itself, a TCP port sweep, and a naming pass that asks by mDNS, SSDP, NetBIOS, LLMNR and reverse DNS. Results are a table of State, Address, Name, What it is, Maker, Hardware address and Open ports, and clicking a row opens everything known about that one device.
When you would use it
Walking into a site and needing to know what is on the network: which box is the router, which is the printer people complain about, what that unnamed thing on the Wi-Fi is, and whether anything has appeared since your last visit.
How to use it
- Check the
Rangebox. It is pre-filled with this machine's own subnet, and the grey hint beside it names the adapter, this machine's address, the gateway and roughly how long a scan will take. - Tick
Check more ports (slower)only if you want the full 20-port list instead of the quick 8. It roughly doubles the sweep. - Press
Scan. A /24 typically finishes in about three seconds of sweeping plus up to eight seconds of naming. - Read the pills across the top: how many devices, how long it took, how many were identified by manufacturer, how many use private (randomised) hardware addresses, and how many are
worth a look. - Read the
Statecolumn against the legend printed under the table: responding answered just now, present means the network confirmed its hardware address but it offers nothing to connect to, remembered means it was seen recently and stayed silent this time. - If the range has been scanned before, a
Since the last scan of this rangeblock appears above the table listing New, Gone and Moved devices. - Type in the
Filter…box to narrow the table by address, name, maker, kind or hardware address. - Click any row for the detail dialog: hardware address, maker and why it was identified that way, model, DNS name, announced name,
Found by(which passes saw it), what it offers on which port, what it announces itself as, and anythingWorth knowing.
Worth knowing
- Nothing here authenticates. Every technique is passive observation or an unauthenticated connect — no credential guessing, no logins, no exploitation.
- Only one scan runs at a time; a second press while one is in flight is refused with "A scan is already running."
- A refused connection counts as proof a device exists, the same as an accepted one. Only silence counts as absence, which is why this finds printers, cameras and firewalled hosts that a ping sweep misses.
- The
Found byline in the detail dialog is worth reading when a result surprises you — a device found only in the address table is a very different situation from one that answered on three ports. - The device's own name can come from several places.
DNS nameandAnnounced nameare shown separately on purpose, because a name a router invented from its lease table is not the same as one the device broadcast about itself.
Traps
- The scan touches every address in the range — it opens sockets to each one to force the network to identify it, then probes ports. On a monitored network this can raise IDS or endpoint-security alerts. Get the site's agreement before scanning a network that is not yours.
- The comparison against last time is keyed on the range text, not the site. Two different client sites both using
192.168.1.0/24are compared against each other, soNewandGonewill be nonsense on your second site. The record lives indata\netscan-history.jsonunder the TechDeck folder and this screen has no button to clear it — delete the file between sites. - remembered is not proof a device is there. It means the address table still holds an entry that answered nothing this time; the device may have left, and the hardware address may even have been replaced.
- Phones and laptops using per-network private Wi-Fi addresses cannot be attributed to a manufacturer and appear as a brand-new device every time they rejoin. The
with private addressespill counts them so a growing device list is not mistaken for intruders. - Only ranges from /22 to /32 are accepted; anything wider is refused with a message rather than run. A /22 is about a thousand addresses and takes roughly twelve seconds of sweeping before naming even starts.
Technical detail
Implemented by app/server/modules/16-netscan.js.
Actions it exposes: clearHistory, history, inspect, progress, ranges, scan
Disk Explorer
TreeSize-style space analysis

What it is
Disk Explorer is the TreeSize-style space analyser. It scans a drive or folder with a pool of worker threads — one per CPU core, never fewer than two or more than eight — holds the result in memory as a folder tree, and shows it six ways: Treemap, Folders, Largest Files, Duplicates, Old Files and File Types. It can send what you select to the Recycle Bin, open anything in Explorer, hand a folder that turns out to be an installed program to the Uninstaller, and write the largest-files list to CSV.
When you would use it
When a machine is out of space and you need to show the customer where it went, then remove the biggest safe items. Also when you want to know what one specific folder actually contains before deleting it.
How to use it
- Open Disk Explorer. The cards at the top list every volume that reports a size — fixed, removable, network and optical — with free space against total. Click a card to scan it, or type a path in the box (
C:\,C:\Users\Name\Downloads, or\\server\share) and pressScan. - While it runs, the live panel shows files, size, files per second, queued directories and the folder being read right now.
Stopcancels and keeps whatever has been counted so far. - When it finishes you get four tiles (total size, files, untouched 2+ years, scan speed) and the six tabs. The treemap opens first.
- On the treemap, click a tile to drill in, double-click does the same, and the breadcrumb goes back up. The three buttons under the map —
See what is inside,Largest files hereandExplorer— act on the folder you are currently looking at, not on a tile. - Right-click anything that has a path, on any tab, for the same menu: drill in,
See what is inside,Show largest files here,Open in Explorer, copy the full path or the name, anUninstallentry when TechDeck recognises the folder as an installed program, andSend to Recycle Bin. - On
Duplicates, pick a minimum size (10 MB and up) and pressFind duplicates. Files are grouped by exact size, then a 64 KB head hash, then a full content hash, so only byte-identical copies are listed. The first copy in each set is starred and its tick box is disabled so you cannot delete every copy. - To remove things, tick the rows and press
Recycle selected, then confirm. Everything this screen deletes goes to the Recycle Bin. CSVwrites the largest-files list into TechDeck's owndatafolder and shows the full path in the toast.
Worth knowing
- The scan deliberately skips
WinSxS,$Recycle.Bin,System Volume Information,$Windows.~BT,$Windows.~WSandDocuments and Settings, and it never follows junctions or symbolic links. The total will therefore be smaller than the drive's used space, and that is correct rather than a miscount. - Individual files are only indexed above 8 MB, and the index keeps roughly the 500 biggest.
Largest Files,Duplicates,Old Filesand the drill-down fromFile Typesall read that list, so smaller files never appear there even though their bytes are in the folder totals. See what is insidereads the folder live from disk rather than from the index, so it shows small files and anything created since the scan. It is the way into a folder whose treemap tile is one flat block marked(files in this folder).- The
Untouched 2+ Yearstile is measured across every file scanned; theOld Filestab lists only indexed files over 8 MB. The two numbers are meant to differ. - Only one scan runs at a time. Starting a second while one is running is refused with "A scan is already running".
Traps
- The "freed" figure after a delete counts files only. Recycling a folder reports 0 B freed even when gigabytes moved, because the size of a folder is not measured at delete time. Check the folder's size in the table before you delete it if the number matters.
- The scan index lives only in the TechDeck server's memory. If the service restarts, every tab shows "Scan results expired" and the scan has to be run again from scratch.
- Without administrator rights, folders Windows refuses to read are skipped and counted only as "N unreadable" in the small text under
Scan Speed. A scan ofC:\on someone else's machine will quietly under-report other user profiles. Run TechDeck elevated when the total has to be right. - "No duplicates found" means none among the indexed large files. It is not a statement about the whole drive, and the 10 MB floor on the minimum-size list exists because anything below 8 MB was never indexed to compare.
- The CSV holds the largest-files list only — not the folder tree — and it is written into TechDeck's
datafolder, which travels with the toolkit. Move or delete it before the stick goes anywhere else.
Technical detail
Implemented by app/server/modules/20-disk.js.
Actions it exposes: cancel, duplicates, exportCsv, folder, largest, level, remove, reveal, roots, stale, start, status
Network Drives
Mapped drives that are stuck, hidden, or holding a letter

What it is
Network Drives deals with mapped drives that are stuck, hidden, or holding onto a letter. It merges four sources that each know something the others do not — the HKCU:\Network registry entries, Get-SmbMapping, net use and Get-PSDrive — so a mapping that Windows remembers but has not mounted is visible as exactly that. The table shows Drive, Shared folder, State and Known to, with Why?, Reconnect and Free on each row. Below it is a Map a drive panel, and in the header a Saved logins button.
When you would use it
A drive shows a red X or Explorer hangs on it; a drive the customer can see is invisible to you; or a re-map is refused with "the local device name is already in use".
How to use it
- Let the list load. The
Known tocolumn is the diagnosis in miniature:rememberedonly means Windows will try to restore it at sign-in but has not mounted it, whileconnectedandmountedmean it is live. - If the yellow banner about hidden drives is showing, read it before anything else — Windows keeps separate drive-letter tables for elevated and normal programs, so this list may not be the list the customer sees.
- Press
Why?on a failing drive. It tests the chain in order: does the server name resolve, does it answer on port 445, is the share readable with the credentials in use — then gives a verdict and advice. - If the server and share are both reachable but the letter still shows a red X, the mapping is stale rather than broken. Press
Reconnect, which drops the session and re-establishes it. - If a letter is being refused for a new mapping, press
Free, confirm at theFree up X:?dialog withFree it. This disconnects it and removes both the remembered mapping and the Explorer entry that makes a deleted drive reappear. - To map a share, pick a
Letter(free letters are listed first, existing ones are marked(replace)), type theShared folderas\\server\share, optionally a username and password, leavereconnect at sign-inticked if it should be permanent, and pressMap it. - If a reachable share refuses with access denied, press
Saved logins, find the server, and pressForget. Windows will ask for a username and password on the next connection. - To fix the hidden-drive problem for good, press
Join themin the banner and confirm. It setsEnableLinkedConnectionsmachine-wide.
Worth knowing
Join themneeds Administrator (the button is disabled otherwise) and sets a machine-wide policy. Windows only reads it at sign-in, so the machine has to be restarted, or the user signed out and back in, before it takes effect.- A password typed into the
Map a drivepanel is passed straight to Windows. TechDeck does not store it, and it is masked out of the command output that gets logged. Map itreleases the chosen letter before mapping, so "the local device name is already in use" cannot stop it. That also means picking a letter marked(replace)silently replaces the existing mapping.Saved loginsdeliberately shows only credentials that could belong to a computer or a share, and prints how many of the total that is. Microsoft accounts, browser logins and app tokens are filtered out so nobody deletes somebody's sign-ins while chasing a drive problem.- A drive listed as
not connectedand known only asrememberedis the classic after-a-reboot "my drive is gone": the definition survived, the connection did not.Reconnectis the right button for it.
Traps
- If TechDeck is running as administrator, the drives the customer can see genuinely do not exist as far as this screen is concerned, and vice versa. Both of you are right. This is the single most common reason a drive appears to be missing, and the banner says so when the policy is off.
Reconnectdeletes the mapping first and then re-establishes it — that is what forces a stale session to renegotiate. If the mapping was live but never made persistent, there is nothing in the registry to restore and the drive simply disappears. Note the\\server\sharepath from the table before pressing it.Freeforce-disconnects with/delete /y, which does not care whether files on that drive are open. Anything the user has open from that letter loses its handle. Get work saved and closed first. Nothing on the server is touched.Forgeton a saved login cannot be undone from here. If nobody present knows the password, that share stays inaccessible until somebody does.- The list can take up to about a minute and a half to load when a mapping points at a server that is switched off, because Windows itself waits on it. It is not hung — the loading line reads "Reading every mapping this account has".
Technical detail
Implemented by app/server/modules/24-drives.js.
Actions it exposes: credentials, diagnose, enableLinked, forgetCredential, freeLetter, list, map, reconnect
File Recovery
Recycle Bin and deleted-file recovery

What it is
File Recovery has four tabs. Recycle Bin parses the raw $Recycle.Bin metadata on every fixed drive for every user account, so it shows deleted files belonging to other profiles that Explorer will not. Deep Undelete reads the NTFS Master File Table directly and lists records whose in-use flag is clear — files already emptied from the bin. Carve & Search ignores the file system entirely and reads free clusters for file signatures or for a phrase of text. Shadow Copies lists the Volume Shadow Copy snapshots on the machine.
When you would use it
Someone deleted something and wants it back. Work down the tabs in order: the bin is instant and safe, the MFT scan is next, carving is the last resort, and a shadow copy is often cleaner than any of them.
How to use it
- Start on
Recycle Bin. Filter by name or original folder, or pick a user from the dropdown. Rows whose data file is gone are struck through and markeddata gone. - Tick what you want, then either
Restore(puts each file back where it was deleted from — an existing file is never overwritten, the restored copy is renamed "(restored 1)") orCopy out…(writes copies to a folder you name and leaves the bin untouched). Empty binpermanently deletes. The confirmation states the exact count and size first.- If the file has already gone from the bin, switch to
Deep Undelete. Choose the volume and a minimum size, thenScan MFT. This needs administrator rights and an NTFS volume. - Read the "Where the records went" breakdown and the
Storagecolumn:in MFTmeans the content is inside the record and intact,N runsmeans it is out in disk clusters,no mapmeans there is nothing left to read. The eye button on a row grades that one file as excellent, good, partial or poor. - Tick files and press
Recover selected…, then give a folder on a different drive. A destination on the source drive is refused outright. - If nothing useful is in the MFT, use
Carve & Search. PickFind textand type a phrase you remember from inside the file, orFind files by type; choose how much free space to read; pressScan. ThenSave regionon a text hit, or tick candidates andRecover selected…, again to another drive. Shadow Copiesonly lists snapshots and their dates. Restoring from one is done in Explorer: right-click the folder that held the file and chooseRestore previous versions.
Worth knowing
- Source volumes are opened read-only. Nothing in this screen writes to the drive being recovered.
- A file still sitting in the Recycle Bin will not appear under
Deep Undelete. Binning a file only moves and renames it, so Windows still counts it as in use. That tab is for files that are already gone. - Deep Undelete rebuilds original filenames for emptied bin items by reading the surviving
$Imetadata records; those rows carry aname restoredtag. Where the$Iis gone the row is taggedbin name onlyand the name shown is the internal one Windows gave it — the contents may still recover perfectly. - Carved files have no name and no timestamps, because those lived in the file record rather than in the file. Carving also assumes the file was contiguous, so a fragmented file recovers only its first piece. Anything carrying an embedded date is named by that date.
- Without elevation the
Recycle Bintab shows only the current user's deleted files and says so in an amber banner.Empty binin that state also leaves other profiles' bins untouched, and the result says how many items remain.
Traps
- Recovering onto the source drive can overwrite the very clusters holding the data you are trying to read back. TechDeck refuses it, so have a second internal drive, a USB stick or a share ready before you start.
- The MFT scan and the carve session are held in memory against an open volume handle, and TechDeck releases both when you leave the File Recovery screen. Go to another screen and back and you get "Run a deep scan first" — the whole scan has to run again.
Empty bincannot be undone from here. Afterwards the only routes are Deep Undelete and carving, and on a busy system drive those records are reused within minutes. Restore anything that might be wanted before emptying.- The deep scan returns at most the first 3,000 files and the table shows the first 1,200 of those. "Not there" may mean "not in the part shown" — narrow the filter or raise the minimum size instead of assuming.
All free space (slow)reads every free cluster on the volume, which on a large drive is a long job with no shortcut. Start withFirst 2 GB (quick)orFirst 10 GBto find out whether anything is recoverable at all.
Technical detail
Implemented by app/server/modules/25-recovery.js.
Actions it exposes: assess, bin, binEmpty, binRestore, carveExtract, carveScan, carveTypes, closeCarve, closeDeep, deepScan, deepVolumes, extractRegion, freeSearch, recover, shadowCopies
Port Checker
TCP reachability with hard timeouts

What it is
Port Checker tests whether TCP ports are reachable, with a hard timeout so a black-holed port can never hang the tool. It has four tabs: SMTP2GO, Custom Check, Outbound and Listening Here, plus a permanent Reading the results panel explaining the three outcomes. The distinction it is built around is CLOSED versus FILTERED — closed means the host answered with a refusal and the network path is fine, filtered means nothing came back at all and something is silently dropping the traffic.
When you would use it
When mail will not send, a service will not connect, or you need to prove whether a block is on the server, on the local firewall, or upstream at the ISP. Listening Here answers the separate question of what this machine itself is accepting connections on.
How to use it
SMTP2GO: pick the relay host from the dropdown (global, or one of the three regional hosts), pickTimeout per port, then pressTest all SMTP2GO ports. It tests all eight documented ports — 2525, 587, 8025, 80, 25 plain, and 465, 8465, 443 with TLS.- Read the SMTP2GO verdict box and the
Recommended portpill. TheSMTPcolumn is the important one:220 OKmeans a real mail server greeted us,no greetingmeans something answered that is not SMTP2GO. Custom Check: type a host or IP, type ports as a list or a range (25,80,443or1-1024) or press one of the preset buttons —Email,Web,Remote,Windows/AD,Databases,First 1024— set the timeout, then pressCheck.- Read the four tiles: Open, Closed, Filtered, and what the name resolved to. The table gives every port with its result, how long it took, the reason, and any banner the service sent.
Outbound: pressTest outbound connectivity. It tries nine well-known destinations (general web, HTTP, SMTP2GO, Microsoft 365 SMTP, Gmail SMTP, IMAP, Windows Update, and DNS over TCP to Google and Cloudflare) and tells you how many are reachable — the fastest way to characterise a restrictive firewall.Listening Here: opens straight away and lists every port this machine is accepting connections on, with the owning process, its PID and its path.
Worth knowing
- Nothing on this screen needs Administrator, including
Listening Here— only the path column is affected by elevation. - The custom check reads a service banner where one is offered. That is what puts the version string in the Detail column, and it means the target logs an inbound connection.
- Ports given as a range are capped at 5000 in total, so an accidental
1-65535is trimmed rather than run. - The three regional SMTP2GO hosts in the dropdown are there for when the global name resolves somewhere unhelpful. The result panel prints the first three addresses the name resolved to and counts the rest as "+N more".
Outbounduses a 4-second timeout per destination and runs six at a time, so a fully blocked network still finishes in well under a minute.
Traps
First 1024against a host that silently drops traffic takes about two minutes at the default 3-second timeout — 1024 ports, 24 at a time, each waiting the full timeout. Nothing is stuck; lower the timeout or shorten the range if you cannot wait.- OPEN on a TLS port does not mean the certificate is good. TLS probes deliberately do not verify the chain, so an expired or self-signed certificate still reports OPEN — the certificate line underneath will say
untrusted chain, and that is the only warning you get. - On the SMTP2GO tab, a port that is OPEN but shows
no greetingis a failure, not a success. Something between this machine and SMTP2GO is accepting the connection itself — a transparent proxy, a security appliance or a captive portal — and mail will fail even though the port looks fine. - A DNS failure is reported as DNS FAIL on every row rather than as hundreds of filtered ports. Fix name resolution in Network Doctor before drawing any conclusion about ports.
Listening Hereprints—in the Path column for processes this session cannot read, which mostly means protected and system processes. Run TechDeck elevated if you need those paths; the port, PID and process name are still correct either way.
Technical detail
Implemented by app/server/modules/30-ports.js.
Actions it exposes: check, listening, outbound, presets, smtp2go
Printers
Find the network's printers, see what each can do, and install them with the features on

What it is
Finds every printer on the network, asks each one what it can actually do, gets the manufacturer's own driver if one is needed, and installs the queues you pick with the right features switched on. The capabilities shown are read from the device itself over IPP, not guessed from its model name, so what you see is what that machine really has.
When you would use it
Setting up a new PC or a new starter, moving someone to a different floor, or replacing a machine and needing the same printers back. Also useful on its own as a survey: it will tell you what is on the network, what each one supports, and whether anything is reporting a fault.
How to use it
- Choose where to look. The dropdown offers networks this machine knows about, grouped by how certain each one is — This machine is on, Reachable through a gateway, Seen on the network. The box beside it takes anything you type, which is what you want on a client site.
- You can sweep several ranges at once, separated by commas:
192.168.1.0/24, 10.0.5.10-60, 172.16.4.20. Ranges can be a CIDR block, a from-to pair,10.0.5.10-60for just the last octet, or a single address. - Press
Find printers. A progress bar shows each phase — sweeping, waking anything asleep, then asking everything that answered to describe itself. - You get a list — one line per printer. Tick one to open everything it can do underneath: colour, two-sided, trays, finishing, and how it will install.
- Under Driver, decide where the driver comes from. If TechDeck has the manufacturer's universal driver on file there is a one-click button for it; otherwise point the box at a folder,
.inf,.zip,.msior the maker's own download link. If the printer is driverless, you can skip this entirely. - Tick the queues you want under Queues to create — you can have more than one per printer, and each name is editable.
- Press
Install selected queues. It creates a port per queue, resolves a driver that actually exists, creates each queue and applies that queue's defaults. - Check the report underneath. It lists every step, including anything that fell back, and reads the finished queues back out of Windows.
Worth knowing
- Two queues on one printer is the point, not a workaround. The classic setup is a colour queue and a black-and-white queue on the same device, so people can be pointed at the B&W one by default and choose colour deliberately. Windows supports any number of queues sharing a port, each with its own defaults.
- The queue choices are built from what the printer reported. A mono-only device is never offered a colour queue, and a printer with no duplex unit is never offered a two-sided default — so you cannot accidentally set something the hardware cannot do.
- Everything that is not a printer is still listed, under Other devices seen, with the reason it was set aside. This is deliberate: a device that answered and was rejected as a NAS is a completely different problem from a device that never answered at all, and a short list with nothing underneath it means the sweep really did reach an empty network. Anything made by a printer manufacturer that did not answer is flagged — that is what a sleeping or firewalled printer looks like, and scanning again often wakes it.
- Drivers come from the manufacturer, never from anywhere else. TechDeck carries verified downloads for HP, Ricoh, Xerox, Lexmark, Canon, Brother and Kyocera — each one fetched, unpacked and read before being written down. Downloads only ever come from the maker's own site over HTTPS, and most are pinned to an exact checksum.
- Vendor
.exedriver packages are opened as archives and never run. Several of them, executed, silently launch the manufacturer's own installer — which is a much bigger change than asking for a driver should make. - Driverless (IPP Everywhere) is a first-class route, not a fallback. Windows negotiates the real capabilities from the device and nothing is downloaded or left behind. It is also where Microsoft is taking printing — third-party print drivers are being wound down.
- Modern printers usually require encrypted IPP; a printer marked
encryptedin its feature table is talking over TLS. Printers use self-signed certificates, which is normal for a device on your own network. - A printer that answers a printing port but will not describe itself is still listed and still installable — it just gets a generic driver and fewer options. It is reported rather than hidden, because a missing printer looks like a broken scan.
- Re-running an install is safe and says so. Queues that were already there are reported as already there, not as newly added — and they are never put on the undo list, so
Removecan only ever take away queues TechDeck itself created. - If a package holds several drivers and none matches this printer, it stops and shows you the list rather than picking one. Choose the right entry and it installs that, without downloading the package again.
Traps
- Installing needs administrator rights. Scanning does not, and neither does downloading and checking a driver. If TechDeck is not elevated the Install button is disabled and the screen says so — restart with
Run as administrator. - The dropdown cannot know about a network this machine has never touched. If a client's printers are on their own VLAN, nothing will offer it to you — type the range in the box. A scan that finds three printers when you know there are ten is almost always this.
- A driver download that fails with "This is not the file TechDeck expects at that address" is not necessarily an attack. Manufacturers rebuild these packages and put the version in the filename, so the URL eventually points at something new. The message shows both checksums; if the file is genuinely the maker's, download it yourself and point the box at it.
- Kyocera's universal driver is a 251 MB download. Every other one is between 12 and 40 MB. Worth knowing before starting it on a client's broadband.
- The colour setting on a queue is its default, not a restriction. Someone can still choose colour for a single job from the print dialog unless a policy prevents it.
- A driver download that stops on "needs administrator rights" has not wasted the download: nothing was changed and nothing has to be repeated except the click, once TechDeck is restarted elevated.
Technical detail
Implemented by app/server/modules/33-printers.js.
Actions it exposes: driverInfo, install, ranges, remove, scan, stageDriver
Mail & DNS
MX, SPF, DKIM, DMARC, blacklists and DNS

What it is
Mail & DNS runs the MXToolbox jobs locally, using this machine's own resolver and raw sockets rather than any third-party service. Four tabs: Domain health checks MX, SPF, DKIM and DMARC in one pass and rolls the problems into a findings list; Blacklist check queries 13 DNSBLs; DNS lookup reads any record type or all the common ones; SMTP test opens a real SMTP session and shows the conversation.
When you would use it
"Their email stopped working." Nine times in ten the cause is one of five things — no MX, a broken SPF record, no DMARC, the sending IP on a blacklist, or a mail host that is not actually answering — and this checks all of them from one screen.
How to use it
Domain health: type the domain (likecontoso.com, not a URL or an email address), add a DKIM selector if the customer knows theirs, and pressCheck everything.- Read the four tiles. MX shows how many mail hosts or
cannot receive mail; SPF shows lookups used out of the limit of 10; DKIM shows keys found; DMARC shows the policy. The findings list underneath grades each problem HIGH, MEDIUM or LOW. - Read the four panels below for the raw records: MX with priority, host and address (flagging any MX host with no address); the SPF record with its include chain indented and each include marked found or not; the DMARC record broken into tags; each DKIM key with its type, size and whether it has been revoked.
Blacklist check: enter the sending IP address, or a mail hostname to resolve, and pressCheck 13 blacklists. The result gives the address checked, how many lists it is listed on, and how many lookups failed, then splits the lists into Listed and Clean.DNS lookup: enter a name, choose a record type or leave it onAll common, and pressLook up.All commonqueries A, AAAA, CNAME, MX, TXT, NS, SOA and CAA one after another.SMTP test: enter the mail host and port (587 by default) and pressOpen a session. It connects, reads the banner, sends EHLO and negotiates STARTTLS where offered.- Read the SMTP tiles — Connection, Banner, STARTTLS, AUTH — then the
Conversationpanel, which is the actual dialogue with the server, and the certificate details underneath it.
Worth knowing
- The domain is confirmed to exist before anything else is checked, so a typo reads as a typo rather than as four separate "no record published" failures.
- Nothing is sent to an outside API. Customer domains never leave the machine except as ordinary DNS queries, so this still works on a locked-down network.
- The SPF tile counting
n/10is the DNS lookup limit. Over 10 and receivers are entitled to fail the check outright, which is why it is shown as a fraction rather than a pass or fail. - A DKIM key with an empty
p=tag is a revoked key, and it is called out as HIGH — it looks like a published key from the outside but signs nothing. - The
SMTP testtimeout is 10 seconds by default, so a host that accepts the connection and then says nothing takes that long to report.
Traps
- Testing port 465 with
SMTP testwill look broken when it is not. That port expects TLS before anything is said, and this test speaks plain SMTP first, so it waits for a greeting that never comes and reports "the port is open but no SMTP banner arrived". Use the Port Checker'sSMTP2GOtab for implicit-TLS ports (465, 8465, 443), which does connect with TLS. no common selector matchedin the DKIM tile does not mean DKIM is missing. Without a selector the check tries 22 common ones, and plenty of providers use something else. Open a real message header from that domain, read thes=value, and enter it in theDKIM selectorbox.- Everything here uses this machine's resolver. On a customer network with internal or split-horizon DNS, the answers are what that network sees, not what the internet sees. Check from a normal internet connection before telling anyone their records are wrong.
- If every blacklist lookup fails, the screen says so and the result means nothing — DNS is being filtered on this network. A row of
no answerpills is not a clean result. - Entering a domain rather than an IP into
Blacklist checkresolves its A record, which is usually the website and not the mail server. Receivers judge the IP that actually delivered the message, so check the MX host or the real sending IP.
Technical detail
Implemented by app/server/modules/35-mailtools.js.
Actions it exposes: blacklist, blacklistSources, dkim, dmarc, dns, dnsAll, domain, mx, smtp, spf
PC Migration
Capture a machine and put it back on a new one

What it is
Two sides of one job on one screen, Capture this PC and Restore onto this PC. Capture writes the invisible half of a machine — Wi-Fi networks and keys, mapped drives, printers, Quick Access, taskbar pins, Explorer preferences, Outlook signatures and the AutoComplete cache, browser bookmarks, Office AutoCorrect and templates, wallpaper and theme, region and power plan, ODBC sources, environment variables, terminal and git config, startup programs — into one self-describing bundle folder containing manifest.json and a customer-facing handover.html. Restore reads that bundle on the new machine and puts the items back in a fixed order.
When you would use it
Any time a user moves to a new computer. Run the capture on the old machine while it still works — before the wipe, not after — and the restore on the new one once the user profile exists.
How to use it
- On the old machine open
PC Migrationand stay onCapture this PC. - Pick a destination. They are ranked: OneDrive first, because the bundle then arrives on the new PC by itself once the same account signs in; then mapped shares; then removable drives; then local disks.
Re-scanafter plugging something in. - Read
What is on this machine. Each row shows a size, what was found, and one of three labels:Autolands by itself,Reviewapplies then wants a quick check,Listedis written down for reference and cannot be moved. Rows with nothing to capture are greyed and cannot be ticked.allandnoneset a whole group. - Press
Capture N items · sizeand confirm. Nothing on the PC is changed or removed. The log names each item as it goes and the failures are listed at the end. - Note the bundle path.
Open the folder,Customer handover pageandCopy pathare on the finished panel. - On the new machine open
PC Migration, switch toRestore onto this PC, and pick the bundle from the list found automatically, or type its folder and pressOpen it. - Untick anything you do not want, close Outlook, Office and Explorer windows first, then press
Restore N item(s)and confirm. - Sign out and back in so Explorer, the theme and Quick Access pick everything up.
Worth knowing
- PST archives are the one item off by default; tick it if the user has local archive files and you have room for them.
- The
Reference — cannot transfergroup — Credential Manager, the installed programs list, BitLocker recovery keys, network identity — is captured as a written list. Saved passwords are encrypted to one user on one machine and no tool can move them. - Order matters and is fixed by the items themselves: mapped drives are restored first, Quick Access afterwards, because the pins are paths that must already exist.
- Paths inside the bundle refer to the old profile and are rewritten to the new one. The screen shows both paths before you restore.
- OneDrive Files On Demand placeholders are skipped rather than copied, because a cloud-only file looks exactly like a real one until it is opened and copying it would produce a bundle that restores empty documents.
Traps
- A captured bundle is a credential store: plaintext Wi-Fi keys, SSH private keys and BitLocker recovery keys can all be in it. The screen says so after a capture. Delete the bundle once the new PC is working.
- Restore overwrites existing files with the same names, adds printers and maps drives on the machine you are sitting at. Check you are on the new PC — a bundle captured from the same machine is flagged, but only after you open it.
- Nothing on this screen checks for administrator rights. Items that read protected data — the Wi-Fi keys via
netsh wlan export profile key=clear, the BitLocker recovery keys — come back short or fail into that item's error line when TechDeck is not elevated, and the failure is only visible in the per-item results. - A bundle written by a newer TechDeck can name items this build has never heard of. Those are skipped and reported by name; update TechDeck and restore again rather than assuming they were empty.
- Surveying is capped so a huge folder cannot stall the screen, which means a size shown next to an item can be lower than what is really there.
Technical detail
Implemented by app/server/modules/38-migrate.js.
Actions it exposes: capture, destinations, inspect, list, restore, survey
Common Fixes
One-click fixes for everyday Windows annoyances

What it is
Common Fixes. A list of registry toggles grouped into Windows 11 Shell, File Explorer, Start Menu & Search, Performance & Boot and Privacy, each of which reads its own current state and can be switched back off. Below them sits a set of one-shot Repair actions for specific symptoms: search index, Explorer, print spooler, network stack, Store apps, icon cache and Windows Update components.
When you would use it
On a machine still set up the way Windows shipped it, and on the everyday symptoms a technician gets handed — a stuck print job, Start search returning nothing, blank or wrong icons, "connected but no internet" after a bad VPN or malware removal, updates failing repeatedly with the same error.
How to use it
- Opening the screen reads the current registry state of every toggle first, so what you see is measured rather than assumed. Four tiles summarise it, including whether you are in
AdminorLimitedmode. - Flip a switch to apply, flip it back to revert. The pill beside the title updates to the state read back from the registry afterwards.
Apply all recommendedapplies the high-value set in one pass: full right-click menu, visible file extensions, no web search in Start, no Start menu ads, no advertising ID and no menu delay — plus Fast Startup off and verbose boot messages when elevated. Explorer restarts once at the end.- For a Repair action, press
Runon its card and confirm. Progress appears in the Activity console at the bottom of the window, and a modal reports the outcome when it finishes.
Worth knowing
- Toggles tagged
machine-widewrite under HKLM and need Administrator. They appear disabled without it. Everything else writes under HKCU and works unelevated. - Many toggles restart Windows Explorer to take effect. Applying several at once restarts it once at the end rather than once per toggle.
Reduce diagnostic data to the minimumsets the lowest level the edition allows, and on Windows Home that is "Required", not off — the toggle's own description says so. Its state pill reports the raw registry value:Default (Full)before,Level 0after.Re-register built-in Store appsprints errors as it goes — it re-registers every package and some are always in use. Sign out and back in to see the result.- If a toggle reads "could not read", its detection failed and the switch position is not evidence of anything. Do not treat it as off.
Traps
- Restarting Explorer closes every open File Explorer window and briefly blanks the taskbar and desktop. Warn the customer before applying a batch on a machine they are watching.
Reset the network stackresets Winsock and TCP/IP, flushes DNS and releases and renews DHCP, so the connection drops mid-run. Never run it over a remote session you depend on, and expect to reboot before it is fully in effect.Reset Windows Update componentsrenamesSoftwareDistributionandcatroot2with a timestamped.oldsuffix. The download cache is gone afterwards and the next scan re-downloads everything pending.Rebuild the Windows Search indexresets the index and restarts the search service. Start menu search and Outlook search return little or nothing until reindexing finishes in the background, which can take hours on a large profile.- Turning off Fast Startup is machine-wide and changes how shutdown behaves for everyone on the PC. It is the right call on most bench machines, but it is a permanent behaviour change, not a temporary one.
Technical detail
Implemented by app/server/modules/40-fixes.js.
Actions it exposes: apply, applyMany, list, repair
App Installer
Install and update the standard apps in one pass, via Ninite

What it is
App Installer. Two halves on one screen. The upper panel, Updates available, asks the Windows Package Manager (winget) what is installed on this machine with a newer version available. The lower panel is the Ninite catalog — roughly sixty applications in groups, with everything this machine already has marked installed — and one Run that fetches a single Ninite installer for the whole selection.
When you would use it
A fresh build that needs the standard set of applications, or a neglected machine where nothing has been updated in a year. It is also the fastest way to bring everything already installed up to date without visiting fifteen vendor websites and declining fifteen bundled toolbars.
How to use it
- The screen opens by reading installed programs from the registry and marks the catalog accordingly. The header reads "N of M already installed".
- Press
Check for updatesto ask winget what is out of date. Tick the rows you want, pressUpdate N appsand confirm withUpdate them. Each one runs separately and its result is listed individually. - For an update pass through Ninite instead, press
Tick what is installed— that selects exactly what the machine already has. Running it then brings all of them current. - For a fresh build, tick apps by hand. The Ninite URL for the current selection is shown at the bottom, and
Copy the linkcopies it if you would rather run it elsewhere. - Press
Run for N appsand confirm withRun it. TechDeck downloads the installer fromninite.comover HTTPS, checks its Authenticode signature, runs it, and then re-reads the installed programs to report what is genuinely present afterwards.
Worth knowing
- Ninite installs and updates in the same pass. Anything already current is skipped, anything older is brought up to date, nothing is uninstalled and nothing is bundled.
- The download is refused unless it comes from
ninite.comover HTTPS, and it is deleted rather than executed if the signature is not valid and signed by Ninite's own certificate. - Ninite's free installer reports success whether or not each individual app worked, so the result table is built by re-reading the registry afterwards, not from the exit code. That is why the table can honestly show one app missing.
- winget updates run silently with package agreements accepted, because a prompt nobody can see is a hang.
- If winget is not on the machine the updates panel says so plainly. It ships with Windows 11 and current Windows 10; on an older build, install "App Installer" from the Microsoft Store.
Traps
- Ninite shows its own small window while it works and Windows may ask for permission once. Declining that prompt is the usual reason an app is missing from the result table afterwards.
- The Ninite run downloads each application from its maker and is allowed up to an hour. With many apps ticked on a slow connection this is a long unattended job — start it before you go and do something else, not five minutes before you hand the machine back.
- Checking for updates contacts the package sources and can take a couple of minutes before anything appears.
- An application that is running usually refuses to be replaced underneath itself. Close browsers, Teams and anything else on the list before updating, or expect those rows to fail.
- The
installedmarks come from matching names against the registry. An app installed under an unusual name will not be recognised, soTick what is installedcan miss it and it will be treated as a fresh install.
Technical detail
Implemented by app/server/modules/68-ninite.js.
Actions it exposes: catalog, link, run, update, updates
Stress Test
Load the parts you choose and watch for heat, throttling and instability

What it is
Stress Test (Diagnostics group) loads the parts of the machine you tick, samples the machine every two seconds while it runs, and tells you whether the CPU held its rated clock speed. Its subtitle on screen is "Load the parts you choose and watch for heat and throttling". It can load the processor (one worker thread per selected thread, doing integer, floating-point and memory work), memory (a separate node child process that allocates and keeps touching the amount you choose), and the disk (a 64 MB file written and read back in a loop inside a TechDeck-stress folder on the drive root). Graphics can be watched but not loaded. Nothing is deleted or overwritten outside the test's own temporary file.
When you would use it
Use it for intermittent faults that only appear once the machine is warm: crashes that only happen in games, shutdowns twenty minutes in, a laptop that goes slow and never recovers. It is also the way to answer "is this thing thermally limited?" on a machine that reports no temperature at all, because throttling is detected from clock speed against the chip's rated maximum rather than from degrees. It is not a benchmark and produces no score.
How to use it
- Open
Stress Test. It reads the machine before showing anything — a PowerShell sample plus a disk list — so expect a few seconds of "Looking at what this machine has" on first open. - Read the banner at the top. It says either "Temperatures are readable on this machine" (green, and it names the source, for example the ACPI thermal zone) or "This machine will not report a CPU temperature" (amber). The three pills below it —
CPU temperature,GPU temperature,throttling— are the honest list of which readings you will get. - Under "What should it load?", tick the parts:
Processor,Memory,Disk.Graphicsis deliberately disabled — TechDeck can watch a graphics card but cannot load one. If nothing is ticked you get a "Nothing selected" warning instead of a run. - Set the load in the middle column:
Threads(all, half or a quarter of the machine's threads),Memory to fill(only sizes that fit in 60 per cent of the memory free right now are offered),Disk to test(fixed drives with their free space). - Set
Duration(2, 5, 15 or 30 minutes) andStop if it reaches(85, 95 or 100 degrees C). - Click
Start the test, thenStart itin the confirmation. The machine will be loud and slow from this point; anything already open keeps running but will stutter. - Watch the
Runningpanel. Four tiles show CPU load,Clockas a percentage of rated speed, CPU temperature, and either the GPU or memory free. Below them is a sparkline of load (accent colour) against clock (green): a clock line sagging while the load line stays high is the throttle, and the screen says so under the chart. - Press
Stopto end the run. The Running panel closes and a result panel appears with the verdict, peak CPU load, lowest clock under load, peak CPU temperature and peak GPU temperature, plus a disk line showing how much was written, read back and roughly how many MB/s.
Worth knowing
- No administrator rights are needed for any part of this screen. What varies is not permission but drivers: temperature and GPU figures depend on what the machine exposes.
- GPU figures come from
nvidia-smi.exeinSystem32, so they appear only on machines with an NVIDIA driver installed. With no NVIDIA card the fourth live tile showsMemory freeinstead of the GPU, andPeak GPU tempin the result shows a dash. That dash means "nothing reported it", not "cool". - A run shorter than three minutes can never return a healthy verdict. Under 180 seconds the result reads "No throttling in N seconds — but that is too short to prove much", because heat builds over minutes. The
2 minutes — a quick lookoption is for checking the test itself works, not for clearing a machine. - Throttling is only called when it is sustained: the CPU must be at 80 per cent load or more and under 75 per cent of its rated clock for eight consecutive samples, which is about sixteen seconds. Brief dips when load ramps or a core parks are normal and are deliberately not flagged.
- If no temperature source answers, the banner names LibreHardwareMonitor as the free tool that adds one. It publishes its sensors over WMI while it is open, so it has to be running in the background during the test, not just installed. Throttle detection also needs the Windows performance counter for processor frequency; if that counter does not answer, the
throttlingpill shows a cross and theClocktile stays at 0 per cent.
Traps
- The temperature limit does nothing on a machine with no temperature sensor. The abort check compares the hottest reported reading against your
Stop if it reachesvalue, and a machine that reports no CPU temperature and has no NVIDIA GPU reports nothing to compare. On those machines the run will go the full duration whatever happens thermally. If the amber banner is showing, stay with the machine and stop it yourself if it smells hot, gets a screaming fan, or shuts down. - Let it reach its own end time and you lose the summary. When the run finishes on its own the server discards it, and the screen then has nothing to report — the
Runningpanel simply disappears and no result panel replaces it. To get the verdict, peak figures and disk throughput in writing, pressStopa few seconds before the timer runs out. - The disk test writes a great deal. It rewrites and re-reads the same 64 MB file continuously at
<drive>\TechDeck-stress\techdeck-stress.tmp, which on a fast SSD is well over a hundred gigabytes of writes in a thirty-minute run — real endurance, spent to measure the drive. It refuses to start if the drive has under 5 GB free, or if the drive root will not accept a new folder ("Cannot write to ... Pick another drive"). The file and folder are deleted when the run ends normally, so if TechDeck is force-closed mid-run, delete theTechDeck-stressfolder by hand. - Leaving the screen does not stop the run. Navigating away only stops the display polling; the machine stays loaded until the duration is up or TechDeck closes. Coming back picks the run up again, though the chart restarts empty. Starting a second run while one is going is refused with "A stress test is already running."
- The memory load lives in a separate process, and only killing it gives the memory back. Normal
Stopdoes that. If TechDeck is force-killed mid-run, a straynode.execan be left holding several gigabytes of the customer's memory until it is ended in Task Manager. Also note the memory sizes offered are worked out from free memory at the moment the screen loaded; if memory has been taken since, the run is refused with a message naming a smaller figure to try.
Technical detail
Implemented by app/server/modules/44-stress.js.
Actions it exposes: capabilities, sample, start, status, stop
Tune-Up
Measure, then clean

What it is
PC Tune-Up, in five tabs: Junk Cleanup, Startup, Services, System Repair and Drive Health. Its rule is measure first — every cleanup location is sized before anything is offered, so you can tell the customer what will be freed before you click and show them afterwards whether it was.
When you would use it
Full-disk and slow-machine work. Also for a machine with too much launching at logon, for sfc and DISM when Windows itself is misbehaving, and for TRIM or defragment when a drive has been full for a long time.
How to use it
Junk Cleanupopens by walking and sizing twelve locations. Each row shows its size, file count and full path. UseSelect all safeor tick individually, thenClean selectedand confirm withClean now. The result panel lists what each location freed and how many files were in use and skipped.- The
Old downloadspanel underneath is separate on purpose. Choose an age (30 days, 90 days, 6 months or 1 year), pressShow me, tick the individual files you recognise as junk, thenSend to Recycle Bin. Startuplists everything launching at logon from the Run keys and both Startup folders. Toggling a switch disables the entry — it does not uninstall anything.Serviceslists every service, with the handful that carry a plain-English recommendation shown first. A dropdown setting Automatic, Manual or Disabled appears only where the recommendation is something other than "keep enabled", and only when you are elevated — so Windows Search, which is flagged "keep enabled", shows advice and no control.System Repairoffers six tools with their expected durations shown on the card.Runstreams the output with a live percentage, a phase label and an elapsed timer, and ends with a plain verdict such as "No problems found".Drive Healthlists physical disks and NTFS volumes.Optimiseon a volume first shows what it is about to do — TRIM on an SSD, defragment on a hard drive — with its safety and expected duration, and only runs after you confirm.
Worth knowing
- The cleanup tab does real work before it draws: it walks each folder to size it. On a machine with large caches that pause is measurement, not a hang.
- Caches and temp files are deleted outright because Windows rebuilds them for free. Files currently in use are skipped automatically and counted in the result as "in use, skipped".
- Downloads is deliberately left out of the sweep — it holds installers, licence keys and files people never copied anywhere else. Its age is judged on last-modified, which is when the file was downloaded, not last-access, which antivirus and indexing touch constantly.
- The Recycle Bin action only accepts absolute paths inside the signed-in user's profile. Anything else is refused before it runs.
- The
Optimiseresult is summarised into real numbers ("Trimmed 358 GB across 20,785 allocations"), with the full log behindShow the full log.
Traps
- Junk Cleanup permanently deletes. Only the Old downloads review sends anything to the Recycle Bin. Read the row descriptions before ticking.
- Several cleanup locations need Administrator — Windows temp, Prefetch, the error reporting archive, Delivery Optimisation and Windows Update downloads. Unelevated they show a lock and cannot be ticked. Clearing Prefetch makes the next boot slightly slower, and clearing the update caches means those packages download again.
- System Repair tools need Administrator and are genuinely long:
sfc /scannowaround 15 minutes, DISM deep scan around 15, DISM repair around 30, component cleanup around 20, disk check around 20. DISM repair also contacts Windows Update for its source files. - Defragmenting a hard drive can run from several minutes to a few hours and wants the machine left alone; heavy use during the run makes it far longer. TRIM on an SSD is usually under a minute. Either way, optimising needs Administrator.
- Startup switches always write the per-user Run approval key. Entries that came from a Startup folder or the machine-wide Run key are recorded elsewhere by Windows, so after toggling one of those, re-open the tab and confirm the state actually changed.
Technical detail
Implemented by app/server/modules/45-tuneup.js.
Actions it exposes: analyze, clean, driveHealth, oldDownloads, optimizeDrive, optimizePlan, powerPlan, recycle, services, setPowerPlan, setService, setStartup, startup, systemRepair
Test Lab
Boot a build in a throwaway virtual machine before putting it near a real one

What it is
A screen that runs a build all the way through in a throwaway virtual machine — QEMU by default, Hyper-V only when it is already switched on — with a virtual disk to install onto and a network to fetch through. It is meant for checking a stick you just built: does Windows load, did the answer file take, did the applications land. It lives under Advanced, next to the USB builder.
When you would use it
After building an install stick, before you wipe a real machine with it. Also to check an ISO boots at all. Not a substitute for testing on real hardware — a virtual machine proves the media and the answer file, not the drivers for a particular model.
How to use it
- Open
Test Lab. It showsRoute, this machine's memory, cores and free space, and any blockers. Virtualisation turned off in the BIOS and less than 40 GB free are both blockers. - If it says QEMU is needed, press
Get QEMU: a 197 MB download that unpacks to 1.2 GB, then the emulators for machines you will never test are removed, leaving about 213 MB inC:\TechDeck\lab\qemu. It installs nothing into Windows and needs no restart. The percentage and the current step are shown while it runs. - Under
What to boot, pick one of three: the stick copied here first (marked recommended), the stick booted directly (marked slow), or an.isofound in TechDeck's image folders or yourDownloads. - Set
Memory (GB),CoresandDisk (GB). The defaults are sized from this machine — memory capped at 8 GB because Setup does not use more, cores up to half the host's threads, 64 GB disk. - Press
Start the test. On the copy route the copy runs first with its own percentage bar and takes a few minutes. On the direct-USB route you confirm that the drive goes offline for the duration. - Watch the running panel. It names the phase, says what is normal for that phase, and shows one of
working,quiet,moving, but far slower than expectedorpaused — not executing, with CPU and disk MB/s.Show the screenraises the QEMU window if it is buried. - When you are done, press
Stop and clean up. That kills the machine, deletes its virtual disk, deletes any local copy of the stick, and puts the USB drive back online.
Worth knowing
- A full unattended install takes fifteen to thirty minutes when hardware acceleration is available. The panel says whether it is
hardware acceleratedorsoftware only — slow. - Setup will still stop and ask which drive to install to. That is the one question the answer file deliberately leaves alone, and seeing it is a sign the file is working.
- What this machine is capable of is cached for ten minutes and warmed when TechDeck starts, so the screen opens quickly. The USB drive list is never cached, because sticks get plugged in while you are looking at the screen.
Resume the test machineonly appears while the machine actually reports itself paused. A pause from QEMU's own window key cannot be lifted by the control channel, so TechDeck sends the keystroke; if that fails it tells you to press Ctrl+Alt+P in the window yourself.- Reusing an existing local copy is checked by comparing the first megabyte plus sixteen sampled regions against the drive, not the whole 57 GB. A stick that has been rebuilt since is detected and copied again.
Traps
- Reading a stick as a raw device needs administrator rights — that applies to both drive routes, booting it and copying it. Only the disc-image route works without them, and the drive options are disabled with a warning rather than offered and failing.
- Booting the stick directly was measured at 0.33 MB/s, which is over four hours for a 4.5 GB image. Use it only when you need to prove the stick itself boots; otherwise copy it here first.
Stop and clean updeletes the local copy of the drive. A second test copies it again — measured at 337 seconds for a 57.6 GB stick.- The direct-USB route takes the drive offline so the guest can own it, so the stick disappears from Explorer until the test is stopped. TechDeck writes nothing to it, but the test machine is given it read/write, exactly as a real PC would have it.
- A machine that pauses with
WHPX: Unexpected VP exit code 4in QEMU's output has been dropped by Windows' own hardware acceleration. Resume cannot lift it — every processor hits the same fault immediately. Stop and clean up, then start the test again.
Technical detail
Implemented by app/server/modules/46-testlab.js.
Actions it exposes: capabilities, connect, enableHyperV, installQemu, resume, stageLocal, start, status, stop
Windows USB
Build a Windows 11 install stick that patches, configures and installs apps by itself

What it is
A six-step wizard, listed in the sidebar as Windows USB (Under Development) under Advanced, that erases a USB stick and writes a Windows 11 install drive which answers Setup's questions for itself. The updates already published in the media, the drivers you supply, the local account, region, edition and hardware-check bypass are all built in; applications and Office are downloaded onto the stick while it is built and installed at first sign-in from the stick, not from the internet. Setup still stops on its drive-selection page, deliberately.
When you would use it
When you build or rebuild machines and want the same install every time without sitting through Setup and eight application installers. Build the stick on a machine with a good connection and 40 GB free before you go to site, not at a customer's desk.
How to use it
- Open
Windows USB (Under Development). Step 1,Before we start, reads this machine and shows three lines: administrator rights, a usable USB drive, and working space onC:. TheChoose Windowsbutton stays disabled until all three pass, and any blocker is spelled out under Not ready yet. - Step 2,
Which Windows: pick one of Microsoft's published images (each row shows the build, size and editions), or type the path of an ISO or ESD you already have intoOr use a file you already have.Check for updatesasks Microsoft what the current cumulative update is for that release; it is a button, not automatic, because Microsoft rate-limits that endpoint hard. - Step 3,
Which drive: pick the stick. Internal drives, the drive Windows is running from, and anything holding a recovery partition are refused outright and cannot be selected.Look againre-reads after you plug something in. A drive markedconfirmasks a second time before it is accepted. - Step 4,
How it sets itself up: computer name, local account and optional password, time zone, keyboard/region, the edition name to install, the hardware-check bypass, theWhich drive Windows installs torule, and the shop name, phone and website that appear in System Properties. - Step 5,
What goes on it: choose an Office edition, tick applications, and give it drivers — a vendor pack found from this machine, a model or a Lenovo serial;Check the folderfor a folder of extracted drivers; orHarvest this machine's driverswhen the stick is for an identical model. The panelHow big a stick this needsre-totals on every tick, with each application size read live from its vendor. - Step 6,
Review and build: readWhat is about to happen, useShow itif you want to seeautounattend.xml, then pressBuild the stick. The confirmation makes you typeERASE, orBUILD ANYWAYwhen the size check says the selection does not fit. - Watch the
Buildingpanel. It shows the percentage to two decimals, elapsed time, when the figure last moved and which stage is running. You can leave the screen: the build keeps going on the server and the page rejoins it when you come back, or reports how it went if it finished while you were away.
Worth knowing
- The wizard keeps its answers between visits, so leaving mid-way and returning puts you back on the same step with the same choices.
- A downloaded Windows image is kept and reused by the next build. The build's own scratch copies — the exported
install.wimand the staged driver folder — are deleted whether the build succeeds or fails. - Applications and Office are fetched onto the stick during the build, and the first-logon script installs them from the stick with each SHA-256 re-checked, so the new machine needs no internet. The caption on the
Applicationspanel still reads "installed on first sign-in — the new machine needs internet", which does not match what the build actually does. - Applications with no winget package — Skype, Avast, AVG and FileZilla among them — are shown greyed and marked
unavailable, and the size estimate does not charge for them. - A quiet stretch during the split stage is normal: DISM writes gigabytes there without printing anything. The screen keeps a four-second heartbeat that reports whether new bytes are landing on the drive, which is the signal to trust over a still percentage.
Traps
- Everything on the drive you pick is destroyed. The size check can also say the selection does not fit and the build will still erase the drive if you type
BUILD ANYWAY. - The whole screen needs administrator rights, about 40 GB free on
C:, and a 16 GB stick as a floor. Applications and Office go on a second NTFS volume that only exists on a stick over about 34.6 GB — below that the build writes Windows fine and logs "The drive has no second volume for applications, so none were added". - Putting the updates inside the image is not built. The panel prices it live from Microsoft's catalogue and then says it is not wired into the build; a machine installed from this stick still fetches its own updates afterwards.
Which drive Windows installs tois a real choice about somebody else's data.Always the first internal drivenever stops and wipes disk 0 without anyone looking at what is on it.Ask at the machineandThe only drive, otherwise askstop whenever there is any doubt.- There is no cancel button on the build screen. A build that is abandoned or killed leaves a part-written drive that will not boot, and on a first run the 4-5 GB download from Microsoft happens inside the build, after
Build the stickis pressed but before the drive is erased.
Technical detail
Implemented by app/server/modules/48-usb.js.
Actions it exposes: apps, build, cancel, capabilities, checkUpdates, disks, download, driverPacks, drivers, images, inspect, previewAnswerFile, size, slipstreamEstimate, status
Remote Reimage
Rebuild a machine over a remote session, leaving the old Windows bootable until you have proved the new one works

What it is
An under-development screen, listed as Remote Reimage (Under Development) under Advanced. What exists and runs for real is a fifteen-check preflight and the partition arithmetic for the plan. Nothing on this screen writes to a disk, and this build contains no code that could: shrinking, carving, applying the image, the boot entry, verification and reclaim are not built. The intended design is that nothing is ever overwritten — C: is shrunk, the new Windows goes into the freed space, a second boot entry is added, and the old Windows stays bootable until you say the new one works.
When you would use it
Today, only to grade a machine and see the plan: whether a given PC could be rebuilt this way, and what would stop it. It is also useful run without administrator rights, because every gate should then refuse — that is the fail-closed behaviour working, not a fault.
How to use it
- Open
Remote Reimage (Under Development)and read the notice at the top before anything else. - Fill in
Type this machine's namewith the hostname of the machine you are actually looking at. It is typed by hand on purpose: the one failure nothing else can catch is a technician acting on the wrong remote session. - Fill in
Who can press the power button— a name and number, or a smart plug you can reach. If the new Windows hangs before it finishes starting, nothing in software can recover it. - Press
Run the checks. It reads only, takes a few seconds on most machines, and shows a percentage while it runs. - Read the board. Each of the fifteen gates shows a verdict —
clear,needs youorstops this— a sentence you can repeat to the machine's owner, the command that produced the reading, andwhat it actually saidfor the raw output. - Tick
I have read this and accept iton anyneeds yougate, then pressRun the checksagain so the acknowledgement is counted in the result. - Open
The planto read the arithmetic: how farC:shrinks, how much is freed, the offset and size of the new Windows and the staging area, and the assertions those numbers were checked against.
Worth knowing
- The fifteen gates are: administrator rights, UEFI firmware, Secure Boot, BitLocker, other disk encryption, ethernet cable, mains power, nothing half-installed, a clean filesystem, hibernation off, not a managed machine, a partition table this can work with, the firmware boots Windows first, somebody who can press the power button, and the right machine.
- The 12 GB set aside for staging is an assumption, not a measurement. The real figure comes from whichever build is chosen, and choosing a build is not wired into this screen.
- The six write buttons are shown disabled rather than hidden, so nothing about what is missing is concealed. The matching actions on the server throw a plain "not built yet" if they are called.
- They are built in a fixed order — arithmetic, checks, boot entries, then a rehearsal against a copy of the boot store — so each step can be tested before the next one can destroy anything.
- A
confirmgate is not a failure. It is something you have read and accepted;stops thisis the verdict that ends the job.
Traps
- Nothing on this screen reimages a machine. If you came here to rebuild a PC remotely, that half does not exist in this build.
- BitLocker still on is a hard refusal, and suspending it is not enough — it has to be fully removed beforehand. Other disk encryption is refused the same way.
- A wired ethernet connection and mains power are both hard requirements. Wi-Fi or battery is a refusal, not a warning.
- A domain-joined machine is refused: it is somebody else's managed estate and rebuilding it is not this tool's call.
- Run without administrator rights and most gates refuse. That is correct behaviour, not a broken screen — do not read a board full of refusals as a verdict on the machine until TechDeck is elevated.
Technical detail
Implemented by app/server/modules/49-reimage.js.
Actions it exposes: apply, arm, capabilities, carve, plan, preflight, reclaim, shrink, verify
Hardware
Inventory, disk health and battery

What it is
An inventory and health screen with four tabs across the top: Disk Health, Inventory, Battery and Problem Devices. It opens on Disk Health. It reads what Windows and the drives themselves report — it changes nothing on the machine.
When you would use it
When you need to know what is in the machine, whether a drive is dying, how worn a laptop battery is, or which device has a yellow triangle in Device Manager. It is also where you get the serial number and a warranty link without hunting for a sticker.
How to use it
- Open Hardware. It lands on
Disk Health: one card per physical disk showing health status, SSD wear, power-on time, temperature, read/write error counts and that drive's serial number. - Read the amber lines under a disk. They are written out in full ("SSD wear indicator at 84% — the drive is near the end of its rated write life"). A red banner reading SMART predicts imminent drive failure appears only when the disk itself reports a failure prediction; back up before doing anything else.
- Switch to
Inventoryfor processor, memory, graphics, motherboard and storage, plus a "This machine" card at the top with manufacturer, model, serial, approximate age and Windows install date. - On that card the warranty button is labelled for the case TechDeck found:
Check warranty on <vendor>when both a serial and a known vendor are present,<vendor> warranty checkwhen no serial is programmed,<vendor> supporton a self-built machine. Dell and Lenovo open the page for this exact machine. Every other vendor cannot take a serial in a URL, so TechDeck copies the serial to the clipboard and you paste it into their form.Copy serialon its own is there for the same reason. - Open
Batteryon a laptop: charge, battery health as a percentage (full-charge capacity measured against design capacity), wear, and both capacities in mWh. - Open
Problem Devicesfor every device with a non-zero Device Manager error code, with the code translated into words — "Cannot start", "Drivers not installed", "Not currently connected".
Worth knowing
- Approximate age is estimated from the BIOS release date, which is set at the factory and survives reinstalls. A BIOS update moves that date forward, so treat the figure as a floor. The screen prints this caveat under the card.
- SMBIOS filler is treated as missing rather than shown.
To be filled by O.E.M.,Default string, all-zero UUIDs and similar never appear as a serial. On a self-built desktop the card says "Self-built machine — no system warranty" and explains that such machines are covered part by part. - The memory panel shows how many slots are populated of the total and says when free slots exist, which is what you need when quoting an upgrade.
- The Graphics panel gives the adapter name, driver version and date, and the current display mode and refresh rate. There is no VRAM figure on it. Windows publishes that through
Win32_VideoController.AdapterRAM, a signed 32-bit field that wraps above 4 GB, so a large card reports a nonsense value — TechDeck shows nothing rather than a wrong number. - Nothing on this screen writes to the machine. The only outbound action is opening a vendor web page, with the serial in the URL for Dell and Lenovo and on the clipboard for everyone else.
Traps
- SSD Wear, Power-On Time and Temperature come from the storage reliability counters, which return nothing at all without administrator rights. Blank columns are not a reading that the drive is healthy. The footnote on screen blames controllers and USB enclosures; elevation is the other cause and usually the real one.
- USB enclosures and some RAID controllers never pass SMART through to Windows. A drive in a caddy can look clean because it was never read.
- A serial shown as
—on the "This machine" card means no usable serial is programmed, not that TechDeck failed — the sticker on the case or under the battery is then the only source. A blank serial on a disk card means that drive did not report one. - Battery health needs
BatteryStaticDataandBatteryFullChargedCapacityunderroot\wmi. Where the firmware does not publish them the field reads—and "not reported". That is missing data, not a perfect battery. - In
Problem Devices, code 45 "Not currently connected" is normal for docks, removable hardware and anything unplugged. Do not report it as a fault without checking what the device is.
Technical detail
Implemented by app/server/modules/50-hardware.js.
Actions it exposes: battery, identity, inventory, problemDevices, smart, temps
Temperatures
Every temperature this machine will report, and an honest account of the ones it will not

What it is
A single page listing every temperature this machine will report, and underneath it every source that produced nothing and the reason why. At the bottom are Read again and Watch over time. The design rule is that a source with nothing to say is listed rather than left out, so a blank is never mistaken for cool.
When you would use it
Overheating complaints, shutdowns or freezes under load, fan noise, a laptop that cooks its battery, and before-and-after checks on a dust clean or a re-paste. It is also the screen to use when the machine reports no degrees at all, because the throttling check still works.
How to use it
- Open Temperatures. The line at the top is the worst reading found and what it means. If TechDeck is not elevated, a warning sits directly under it saying which readings are therefore blank.
- Read
What answered. Sensors are grouped by device, the bands are printed once per group (warm / hot / very hot, in °C) and each row carries a coloured word. A comfortable row gets no sentence; anything warmer explains itself in place. - Read
Is heat costing this machine speed?. This is the processor's current clock as a percentage of its rated clock, plus any thermal throttling Windows recorded in the last 30 days. Above 100% means the chip is boosting, which is the opposite of thermally limited. - Read
Every source, including the silent ones. Each source saysreading,needs administrator,starting…,still looking…ornot available on this machine, with a sentence. Expand "what Windows actually said" for the raw error text. - Where Core Temp is installed but was not started, press
Start Core Temp now. The screen keeps checking for about ten seconds and fills in on its own. - Press
Watch over timeto sample every 5 seconds and draw a sparkline per sensor under "Over the last few minutes". Put the machine under load — the Stress Test screen is built for it — and watch whether the line climbs or plateaus. - Press
Stop watchingwhen you are finished.
Worth knowing
- The bands are general operating ranges per class of part, not the datasheet for the exact component: processor 80 / 90 / 95, graphics 75 / 84 / 90, NVMe 60 / 70 / 80, SATA SSD 50 / 60 / 70, mechanical drive 45 / 50 / 60, battery 40 / 45 / 50 °C. Where a device publishes its own thresholds — NVMe drives usually do — those are used for that group instead, so the figures in a group header can differ from the list above. Nothing on the row says which set is in use.
- A modern processor sitting at 85 °C under sustained load is not a fault; current desktop parts are designed to run to their limit and hold there. Hot at idle is the finding, hot under load usually is not, and the sentences on screen make that distinction using the current load.
- The graphics reading comes from
nvidia-smi.exe, which the NVIDIA display driver installs intoSystem32. Nothing is downloaded for it and it answers without administrator rights, which makes it the one temperature a standard user can always see. AMD and Intel ship no equivalent, so those cards report nothing here. - Windows reports no fans on almost every machine, because case and processor fans are run by the motherboard and never published to the operating system. A graphics-card fan is the exception.
- A wide sweep of every sensor class the machine publishes runs when TechDeck starts and takes about a minute the first time. If you open this screen very early it says "still looking…" and fills in by itself.
Traps
- The first time this screen is opened, TechDeck fetches LibreHardwareMonitor (about 6 MB, from GitHub) and installs the PawnIO kernel driver on the machine in front of you. It needs administrator rights and internet access, it creates an Add/Remove Programs entry and a DriverStore entry, and it is removed again when TechDeck closes. This happens on the click rather than at launch precisely because it is somebody else's computer.
- If TechDeck is force-killed instead of closed, that driver stays behind. It is removed the next time somebody opens this screen — the first reading looks for the marker TechDeck left behind and clears up before starting anything, so a TechDeck that never visits this screen never tidies it. Only a driver TechDeck installed is ever removed; a machine that already had PawnIO keeps it.
- A
PawnIOsetup window can appear on the client's screen. It belongs to LibreHardwareMonitor, not to TechDeck, and it means the silent pre-install did not run. Nothing is broken, but the client will see it. - Unelevated, drive temperatures come back completely blank, and the processor's thermal zone is unreadable on most desktops in any case. The screen labels these
needs administratorandnot availablerather than showing a cool number. Never repeat a blank as a reading. Watch over timekeeps recording on the server after you navigate away. If you come back the button correctly readsStop watching, but the figures no longer update by themselves — pressRead again, or stop and restart the watch. Stop it before you leave the machine.
Technical detail
Implemented by app/server/modules/52-temps.js.
Actions it exposes: history, read, startCoreTemp, stopWatch, watch
Security
Defender, firewall, encryption and updates

What it is
A posture screen with three tabs: Posture (antivirus, firewall, encryption, UAC, update history and administrator accounts, with findings ranked by severity), Autoruns (everything set to run automatically) and Threat History (what Defender has actually detected).
When you would use it
Handover checks, answering "is this machine protected", first-pass infection triage, and any time you need a Windows Update history that is genuinely complete rather than the hotfix table.
How to use it
- Open Security.
Postureruns first and lists findings at the top, worst first: CRITICAL, then HIGH, then MEDIUM. With no findings you get a single green "Security posture looks sound" line. - Check the Antivirus panel: every product registered with Windows Security Center marked active or inactive, then Defender's own real-time state, behaviour monitor, definition age, days since the last quick scan and tamper protection.
- Check Firewall & Encryption: each firewall profile with its default inbound and outbound action, BitLocker per volume, UAC state, and the date of the last update.
- Read the Windows Update history panel: installs, failures, days since the last real update and days since the last definition update.
Break down by typeopens a table of every category, with a note comparing it to whatGet-HotFixalone would have shown. - Scroll to Administrator accounts. Every member of the local Administrators group is listed, and any enabled account that requires no password is called out in red.
- When TechDeck is elevated, three action buttons appear:
Update defs,Quick scan, andEnable allon the firewall panel when a profile is off. They are absent, not merely disabled, when unelevated. - Open
Autorunsfor the Run and RunOnce keys (machine, user and 32-bit) and every scheduled task that is enabled and triggers at logon or boot — a task that is disabled is not listed. Entries launching fromAppData,Temp,ProgramData,Users\PublicorDownloadsare highlighted and pilled as flagged. - Open
Threat Historyfor Defender's detections: when, what, which file, and whether the action succeeded.
Worth knowing
- Update figures come from the Windows Update Agent's own history, not
Get-HotFix. On one current machineGet-HotFixlisted 7 installs where the agent's history held 955 — definitions, drivers and most non-CBS packages never reach the hotfix table at all. - The "days since last update" judgement deliberately ignores antivirus definitions. Definitions land daily and would otherwise disguise a machine that has not taken a real patch in six months. Definition age is judged separately.
- An empty BitLocker list renders as "BitLocker is not available or not configured". That one sentence covers both a Windows edition without BitLocker management and a query that returned nothing, so confirm the edition before quoting it.
- The severity of a finding is TechDeck's own judgement from the readings, not a Microsoft rating. Read the sentence, not only the pill.
Traps
Posturecan take a minute or more the first time. It queries the Windows Update Agent through COM for up to 400 history entries, and is allowed two minutes for that one call before the tab paints.- Flagged in
Autorunsdoes not mean malware. Teams, Discord, several updaters and most per-user installs legitimately live inAppData. The flag means the command line is worth reading, nothing more. Autorunsis read-only. Nothing on that tab disables, deletes or quarantines an entry — removal is a separate job with separate tools.Threat Historydistinguishes "nothing found" from "could not look". If a warning box appears where the all-clear would be, Defender did not answer and nothing has been checked. Run TechDeck as administrator and try again rather than reporting a clean machine.Update defsis a foreground action allowed up to five minutes and holds the button until it returns.Quick scancomes back at once because it starts a background job — the message says it started, not that it found anything, and progress appears in Windows Security rather than here.
Technical detail
Implemented by app/server/modules/55-security.js.
Actions it exposes: autoruns, defenderAction, firewallEnable, posture, threats
Windows Update
View, remove and block Windows updates

What it is
The Windows Update screen. Four tabs — Installed, Blocked, Pending, History — with a pause banner across the top and a Windows settings button that opens the Windows Update page in Settings. It lists what is installed, removes an update, and keeps it from coming back by hiding it through the Windows Update Agent, the same mechanism as Microsoft's "Show or hide updates" tool.
When you would use it
When an update is suspected of breaking something and has to be removed and kept off. Also when you need to know what is genuinely pending — including the optional updates Windows will never install on its own — or when you need to see failed update attempts rather than just successful ones.
How to use it
- The screen opens on
Installed, listing hotfixes newest first with a filter box that matches on KB number or description. This needs no elevation. - The banner above it shows whether updates are paused. Unpaused it offers
Pause 7 daysandPause 35 days; paused it offersResume updates. All three write to HKLM and need Administrator. - To remove one, press
Removeon its row and confirm withRemove it.wusa.exeruns quietly with no restart and the modal stays up while it works. - After a successful removal TechDeck asks whether to block it.
Yes, block itrecords the KB and tries to hide it immediately;No, leave it unblockedmeans Windows will reinstall it on the next scan. - The
Blockedtab lists everything on the block list withRe-apply blocks now,Check what Windows is hiding, and anUnblockbutton per row. - On
Pending, pressCheck for pending updates. Each row offersInstall(Administrator) and, where a KB exists and it is not hidden or mandatory,Block. Make Windows check againasks Windows to re-contact Microsoft, waits 20 seconds, searches again and reports anything that was not being offered before.Historyshows the last 150 entries from the Windows Update Agent, including failures with their HRESULT — usually the fastest way to spot an update that keeps retrying.
Worth knowing
- The block list is TechDeck's own file,
blocked-updates.json, in its data folder. Hiding in Windows is a separate step applied on top of it. - The pending search runs five different criteria, not one. Optional updates — preview builds and most vendor drivers — form a set the plain search cannot see at all.
- Installing goes through the Windows Update Agent, so the download source, servicing stack and restart behaviour are identical to the Settings app. A hidden update is unhidden first so it can install.
- Every installed update gets a live
Removebutton, including the ones Windows will refuse to remove. The screen does not grey out service packs or servicing stack updates in advance — you find out afterwards, from the decoded exit code. - The install panel shows a running timer and the current phase ("Downloading 412 MB", "Installing — do not power off") rather than a bare spinner.
Traps
- Removing, installing, pausing, resuming, re-applying blocks and hiding all need Administrator. Unelevated, the Remove buttons are disabled and a block is recorded but never applied in Windows.
- Removing an update regularly takes several minutes and can return "a restart is required to finish". Do not close TechDeck while the removal modal is up.
- An update can only be hidden while Windows is actively offering it. A block set right after an uninstall will normally say it could not hide anything yet — that is expected, and
Re-apply blocks nowafter the next scan is the second half of the job. - Servicing stack updates cannot be removed at all, and some security updates cannot be hidden. TechDeck decodes the exit code and says which case you hit.
- The
Pendingtab can report could not check instead of an empty list. That means the search never ran — offline machine, or a dead Windows Update service. It is not the same as up to date, and patching should not be skipped on the strength of it.
Technical detail
Implemented by app/server/modules/65-updates.js.
Actions it exposes: available, block, blocked, classified, enforceBlocks, history, install, installed, openSettings, pause, pauseStatus, rescan, resume, unblock, uninstall
Licenses & Keys
Recover product keys already licensed to this machine

What it is
Licenses & Keys is the Belarc Advisor job: it reads the product keys already licensed to this machine. Windows (the firmware key from the UEFI MSDM table, the installed key decoded from DigitalProductId, activation state and channel), Microsoft Office, a curated list of third-party registry locations plus a dedicated Adobe and SQL Server pass, an optional deep registry sweep, and an HTML report that is masked by default.
When you would use it
Before rebuilding or reinstalling somebody's PC, to capture what the machine is licensed for while it still boots. Also to answer "is Office actually activated?" on the spot.
How to use it
- Open Licenses & Keys. The three panels fill in on their own and the header says how many keys were recovered.
- Read the Windows panel: edition, build,
Installed key,OEM / firmware key, the last five characters Windows itself reports, and the activation status and channel pills at the top right of that panel. - If a red panel says That is not the customer's key, the decoded key is a public generic edition key and will not activate anything. Use the firmware key if there is one; if there is not, this machine is on a digital licence and there is no key to take away.
- Tick
reveal full keysto unmask them. A copy button appears beside each revealed key. - Check the Office panel. Rows come from the registry (a full key on MSI-era installs), from the Windows licensing service and from
ospp.vbs— the last two give the last five characters only, plus the activation state. - Press
Sweep registryfor software TechDeck has no specific entry for. It lists values whose name looks like a licence field and whose content looks like a key, with the field name and full registry path. - Press
Export key reportto write an HTML file into TechDeck'sdatafolder, thenOpento view it. It is masked unlessreveal full keysis ticked, and a full export asks you to confirm first. Refreshre-reads everything from the machine instead of from memory. Expect ten to fifteen seconds for the Office read alone.
Worth knowing
- Everything on this screen reads licences already present on the machine. Nothing is generated, cracked or bypassed.
- A Windows 10 or 11 retail upgrade is a digital licence — an entitlement tied to the hardware and a Microsoft account, not a key stored on disk. No tool can recover one because there is nothing to recover, and reinstalling the same edition on the same hardware reactivates by itself. The screen says this instead of showing a wrong key.
- Microsoft 365 and Click-to-Run Office keep only the last five characters of the key locally. That is Microsoft's design, not a limitation of the decoder.
- Products licensed to an account — Acrobat DC, Creative Cloud, Microsoft 365, current Autodesk — appear under "Installed, but no key is stored on this machine" with the reason and where the licence actually lives, so you have an answer to give the customer rather than a blank panel.
- The sweep walks three levels below each
SOFTWAREroot in HKLM, the 32-bit view and HKCU, and skips the subtrees that hold almost every key and never a licence (Classes, installer, servicing, driver store, policies). A key buried deeper than that, or in a skipped subtree, is out of its reach.
Traps
- A full export is a plain-text list of usable product keys sitting in TechDeck's
datafolder, which is normally the USB stick. Treat it like a password list, and remove it when the job is done. none in firmwareis the correct answer for a self-built PC or a retail install, and it is also what you get when the read was refused. This screen does not require elevation and will not warn you, so run TechDeck elevated whenever the firmware key matters.- The deep sweep stops at an internal time budget of about 45 seconds and returns whatever it found by then. The panel shows the counts but does not say it stopped early — only the activity log line does. The on-screen wording says a minute or two.
- Sweep results are candidates, not verified keys. Some rows will be internal identifiers that merely look right. Check the field name and the registry path before handing one to a customer.
- A value found at a known licence location is shown even when it is not in the usual five-block shape, marked as stored in a format TechDeck does not recognise. That is deliberate — it is shown exactly as found, and judging it is your call, not the tool's.
Technical detail
Implemented by app/server/modules/58-licenses.js.
Actions it exposes: apps, deepScan, export, office, open, windows
Processes
Running processes, software inventory and crash history

What it is
A live, sortable table of every running process — sampled CPU%, memory, threads, handles and PID — that refreshes every 4 seconds, with a details dialog per process giving the full path, the signer, SHA-256 and MD5.
When you would use it
Something is eating processor or memory and you need to see what. Also for taking the hash of a suspicious binary to paste into VirusTotal, and for ending a hung application.
How to use it
- Open Processes. The table loads sorted by memory, largest first, and the header shows the process count and total memory.
- Click any column header to sort by it; click the same header again to reverse. Sorting does not stop the refresh.
- Narrow the list with the
Filter by name, company or path…box, or tickonly flagged locationsto show only processes running from user-writable folders (AppData\Local\Temp,Temp,Downloads,Users\Public). - Press the eye button on a row to open details: path, company, description, file size, start time, working set and private memory, signer, SHA-256 and MD5.
Copy SHA-256puts the hash on the clipboard for VirusTotal. - Press
Verify signaturein that dialog for full Authenticode validation including revocation checking. It contacts the certificate authority and can take up to a minute; the result appears under the button. - Press the red X on a row to end a process. A confirmation names the process and PID and warns that unsaved work in it will be lost.
- Untick
auto-refreshto freeze the list while you read it, and useRefreshfor a single reading.
Worth knowing
- CPU% is derived from two samples of accumulated processor time over wall time, divided by core count. A process shows
—until it has been seen twice, so the whole column is dashes for the first few seconds after the screen opens and for anything newly started. - Opening the details dialog pauses the 4-second refresh, because both compete for the same PowerShell and the dialog would otherwise be slower still.
- The signer shown in the dialog is read straight out of the embedded certificate with no network call, which is why it returns in milliseconds. "No embedded certificate" is not the same as unsigned — most of
C:\Windowsis catalog-signed instead, and the dialog says so in place of the issuer. - Only the first 400 rows are drawn. The count under the filter box tells you how many actually matched, and a line under the table says when it is showing 400 of more.
Traps
- Ending a process discards unsaved work in that application immediately. The application gets no chance to prompt. Ask before you do it on a client machine.
- TechDeck refuses PIDs below 5 and the critical system processes
csrss,wininit,winlogon,services,lsass,smssandsystem, because terminating them bugchecks the machine. Everything else is permitted, including processes the desktop depends on —explorerrestarts itself, many others do not. - Without administrator rights, processes owned by other users and by SYSTEM report no path. No eye button appears for them, they cannot be hashed, and ending them usually fails with an access error.
flaggedis a test of where the file lives, not a verdict on the file. Installers, updaters and portable tools run legitimately fromTempandDownloads. Hash it and check before saying anything to the client.Verify signatureneeds network access to the certificate authority. On an offline or filtered machine it stalls until its 90-second limit and reports a failure — that is the network, not a bad signature. The embedded-certificate details in the dialog above it are still valid.
Technical detail
Implemented by app/server/modules/60-processes.js.
Actions it exposes: bootPerf, events, hash, kill, list, software, uninstall, verifySignature
Ultimate Uninstall
Deep uninstall with leftover cleanup

What it is
Ultimate Uninstall, in three tabs: Programs, Office removal and Adobe removal. Programs merges registry-registered software with Microsoft Store and Xbox packages, which have no uninstall registry key and therefore never appear in a registry-based Add or Remove Programs list. Analysing one finds everything it owns — install folder, AppData and ProgramData folders, registry keys, services, scheduled tasks, startup entries and shortcuts — then runs the vendor uninstaller and sweeps what it left behind.
When you would use it
When a vendor uninstaller has been run and the machine still misbehaves, when a program was deleted by hand and only its registry entry remains, when Store or Xbox titles are taking up the disk, and for Office or Adobe installs that need Microsoft's or Adobe's own supported removal path.
How to use it
- Open
Programs, filter if needed, and pressAnalyseon a row. The detail panel appears above the table, not below it. - Read what it found: install folder, the uninstall command, whether a silent uninstall is supported, any launcher handoff, and the full component list with sizes. Nothing has been touched at this point — analysis is read-only.
- Tick what should be removed. Items judged safe are pre-ticked;
Safe only,Select allandClearset them in bulk. Uninstall and sweepdoes the whole job in one press: the vendor uninstaller runs, TechDeck looks again at what is left, and only the ticked items that are still there are removed.Uninstaller onlystops after the vendor uninstaller.Sweep selected leftoversremoves the ticked items without running an uninstaller — this is the route for a program whose uninstaller is already missing.- After a removal the program list is re-read and the panel says either that it is gone or that it is still listed, in the same place you are already looking.
Office removaldetects Click-to-Run and MSI installs and removes Click-to-Run products with Microsoft's own engine.Adobe removallists Adobe products, services and folders, andAnalyseon a product routes it back through the Programs flow.
Worth knowing
- Before the uninstaller runs, TechDeck closes anything running from that program's own install folder — asked politely first with CloseMainWindow, forced only if still there. Matching is by executable path, never by process name, and shared parents such as Windows or Program Files are refused outright.
- Folders removed by the sweep go to the Recycle Bin, and registry keys are exported to a
.regfile under TechDeck's data folder before deletion. The backup path is printed in the result, and double-clicking that file restores the key. - Components marked
sharedbelong to another installed program as well and are never pre-ticked. The detail text names which other products claim them. - Store and Xbox titles are removed as a package with no vendor window. An Xbox game's content folder under
C:\XboxGamesis separate from the package and stays on disk until swept — the result message names the folder and tells you to sweep it, but does not say how big it is. Re-analyse to see the size. - "Still in the list" after a successful uninstall is a real outcome, not a failure to report. Some uninstallers only drop their registration on the next restart.
Traps
- Uninstalling and sweeping both require Administrator. Unelevated the buttons are disabled and the tab shows a warning at the top.
Select allreaches thesharedandreviewitems too. Deleting a shared folder or a vendor registry key takes another installed product's data with it —C:\ProgramData\Adobeand%LOCALAPPDATA%\AMDare not one product's folder. Read the "SHARED with" text before removing them.- Running the uninstaller force-closes programs running from that folder without asking again. Unsaved work in that application is lost. TechDeck prints what it closed into the live log.
- A Steam, Epic, GOG, EA or Ubisoft entry does not uninstall directly — it hands off to that launcher, which opens its own window. Nothing is removed until you confirm it there.
- Office removal runs Microsoft's engine for 5 to 15 minutes behind its own progress window and wants a restart afterwards. Outlook profiles and local
.pstfiles are not deleted, but confirm the customer's documents are backed up and that they know their Microsoft account sign-in before you start.
Technical detail
Implemented by app/server/modules/62-uninstall.js.
Actions it exposes: adobeDetect, analyze, closeRunning, identify, identifyMany, list, officeDetect, officeRemove, removeAppx, removeSteam, run, sweep
Drivers
Every device, its driver, and what can be updated now

What it is
A device and driver inventory with Windows' own plumbing filtered out, plus the two things Device Manager will not tell you: which hardware is limping on Windows' generic fallback driver, and which drivers Windows Update has for this machine right now. It also exports every third-party driver on the machine into one folder, and links to the chip maker and the machine maker built from this machine's real hardware IDs. It sits under Maintenance.
When you would use it
On any bench machine where something is not working properly, and before a rebuild — the export captures the card reader, fingerprint sensor and dock drivers that are hardest to find again afterwards.
How to use it
- Open
Drivers. The inventory reads locally and needs no network. Four tiles appear: devices, problems, fallback drivers, and how many key devices are over three years old. - Read the alert boxes. Problem devices are listed with Windows' own error text in plain words; devices on a Microsoft fallback driver are listed with what that costs;
Where the newer drivers actually come fromlinks to the machine maker and each chip maker found on this board. - Press
Check for driver updatesto ask Windows Update. This contacts Microsoft and normally takes up to a minute. - Press
Installon any row you want and confirm. The live output appears underneath. A driver install can blank the screen for a moment and some need a restart to finish. - Press
Back up all driversand confirm to export every third-party driver package into adrivers-YYYY-MM-DDfolder inside TechDeck's owndatafolder.Openreveals it when it is done. - Use
Filter devicesto search by name, vendor or provider, and tickshow Windows' own plumbingwhen you need the entries that are normally hidden.
Worth knowing
- Every in-box Windows driver is stamped 21 June 2006. That is a placeholder, not an age — those rows read
ships with Windowsand are left out of the over-three-years count. - "Fallback driver" is only flagged where the customer would notice: graphics, network, Bluetooth and audio. Microsoft's own driver on an NVMe controller, a SATA controller or a USB hub is the correct driver and is not flagged.
- Nearly all driver updates arrive from Windows Update as
optional, the class Windows will never install on its own. That is how a machine reports itself fully up to date while running a two-year-old graphics driver. Restart as administratorrelaunches TechDeck throughTechDeck.vbsnext to the app. If that file is not there it says so and you have to start it again yourself.- The same physical device can appear once per function on some chipsets; rows are deduplicated by name, version and class, so the count is lower than Device Manager's.
Traps
- Installing a driver writes to the protected driver store and needs administrator rights. Every
Installbutton is disabled until TechDeck is elevated; the rest of the screen works without it. Back up all driversrunspnputil /export-driverand also needs administrator rights. Unelevated it exports nothing and the panel says so rather than failing loudly. It can take a minute or considerably more on a machine with many devices.- "Windows Update has nothing newer for this hardware" is not the same as "your drivers are current". Windows Update ships a conservative build and is routinely months behind NVIDIA, AMD and Intel.
- A device Windows reports as a problem is often disabled on purpose — onboard graphics switched off in favour of a card, or Wi-Fi turned off on a wired desktop. Check before you fix it.
- No tool can honestly tell you a Realtek, MediaTek or chipset driver is out of date: those vendors publish no machine-readable version feed. The screen states this rather than guessing, and any tool that claims otherwise is guessing or selling something.
Technical detail
Implemented by app/server/modules/67-drivers.js.
Actions it exposes: backup, check, elevate, install, inventory, launchTool, tools
Image Tools
HEIC to JPEG conversion

What it is
Image Tools converts HEIC and HEIF photos — and PNG, TIFF, BMP, WebP and AVIF — to JPEG. Decoding goes through Windows' own imaging component, so nothing is bundled: HEIC works only where Microsoft's free HEIF Image Extensions are installed, and the screen says plainly when they are not. EXIF orientation is applied to the pixels, and the useful metadata and file timestamps are carried across.
When you would use it
The routine bench job: a customer's iPhone photos that nothing on their Windows machine will open, or a folder of images that needs to be in a format everything can read.
How to use it
- Open Image Tools. The line at the top says whether HEIC support is present on this machine. If it is missing, an amber panel explains why and offers
Open in Microsoft Store(which opens the Store listing in the default browser) andRe-checkonce it is installed. - Set
Quality. The choices are 95, 90 (the default), 80 and 65. - Either drag photos onto
Drag photos here, or click it to browse. The files are copied into TechDeck'sdata\stagedfolder and conversion starts on its own. - Or type a folder path into
Or convert an entire folder, tickinclude subfoldersif the photos are nested, and pressConvert folder. - Set
Save converted images toif you want a specific destination. Left blank, dropped files go to<your profile>\Pictures\Convertedand a folder conversion goes to aConvertedfolder inside the folder you pointed at. - Read the results table.
Was → becameshows what each file actually was, so a JPEG going in and a JPEG coming out is visible rather than hidden; anything not converted appears as askippedrow with the reason.Open output foldershows the results in Explorer. - Press
Clearwhen finished with a batch. It removes the staged copies from the machine.
Worth knowing
- Nothing is overwritten. A name that already exists in the output folder gets " (1)" appended, so two files called
IMG_0001.HEICfrom different folders both survive. - Date taken, camera make and model, title, subject, comment, copyright and keywords are copied into the JPEG, and the output file's created and modified times are set to match the original — without that, every converted photo would look like it was taken today in Explorer.
- Photos taken in portrait are rotated as the pixels are written, and the orientation tag is deliberately not re-stated in the JPEG, so the image is the right way up in every viewer.
- JPEGs are left alone and listed as skipped unless
re-compress JPEGsis ticked. Even then, if the re-encode comes out larger than the original the new file is deleted and the original kept, and the row says so. - The JPEGs usually add up to more than the HEIC originals. That is expected — HEIC compresses far more efficiently — and the screen states it rather than flagging it as a fault. Lower the quality if size matters more than fidelity.
Traps
Convert folderonly picks up HEIC, HEIF, HIF and AVIF. PNG, TIFF, BMP, WebP and JPEG are converted only when dropped on the drop zone, even though the drop zone lists them as accepted.- Dropping a second batch re-converts everything staged so far, so the first batch comes out again as " (1)" duplicates. Press
Clearbetween batches. - Without HEIF Image Extensions no HEIC can be decoded on that machine by anything, this tool included. Installing it happens on the customer's PC and needs their Store access and internet.
- Dropped files are copied onto the machine running TechDeck, into its own
data\stagedfolder, up to 512 MB per file. On a customer's PC that leaves their photos inside your toolkit folder until you pressClear. - Recursion into subfolders stops six levels down, so a deeply nested photo library may not be fully covered by one pass.
Technical detail
Implemented by app/server/modules/70-media.js.
Actions it exposes: capabilities, clearStaged, convert, convertFolder, reveal
PowerShell
Hosts, modules and a console

What it is
The PowerShell workbench — the screen is labelled PowerShell (Under Development). Two cards at the top show which PowerShell hosts are on the machine, and six tabs sit under them: Module Catalog, a curated list of the modules a technician actually reaches for with one-click installs; Installed, everything already on the machine; Gallery Search; Common Tasks, a library of fill-in-the-blanks admin jobs for connected 365 services; Console, backed by a session that stays alive between runs; and History, everything that has been run.
When you would use it
When a job needs SharePoint, Exchange, Teams, Graph, Azure or Active Directory work and half the problem is knowing which module provides it and whether this machine already has it. Also as a plain console when you want the sign-in to survive from one command to the next.
How to use it
- Look at the two cards at the top: whether Windows PowerShell and PowerShell 7 are present, their versions and their paths.
Install PowerShell 7installs via winget, needs administrator, takes a few minutes, and runs side by side with 5.1 rather than replacing it. If winget is not on the machine the button opens the download page instead. - Set
PowerShell versionat the top right before anything else. It decides which modules are listed and which host the console runs in. - On
Module Catalog, modules are grouped by job and filtered to what the selected version can actually load;Show them anywayreveals the rest.Installasks forAll users(administrator) orCurrent user only, and the progress, elapsed time and alogbutton appear on the row you clicked. - Modules tagged
Windows feature— ActiveDirectory, GroupPolicy, DnsServer, DhcpServer — are RSAT capabilities and are not on the gallery at all. UseAdd feature: administrator, downloaded from Windows Update, several minutes. Installedlists what is already on the machine for the selected version.Gallery Searchlooks up anything the catalog does not carry and installs it the same way; it needs internet, and it says so plainly when the gallery cannot be reached.- On
Common Tasksthe pills at the top show what this session is signed in to, and only tasks for connected services are offered. Locked ones are listed with aConnectbutton that drops the correct sign-in command into the console. Pick a task, fill in the labelled boxes, readWhat this will doand the exact command underneath it, then pressRun it. - On
Console, type or paste and pressRunor Ctrl+Enter. If the script needs a module that is not available, that is stated before anything runs, with a button to install it or to switch version. Historylists every task and typed command with whether it worked.Againputs a command back in the console ready to check and run;Cleardeletes the record and cannot be undone.
Worth knowing
- The console keeps one PowerShell process per version alive, which is what makes signing in worth doing:
Connect-ExchangeOnlinein one run andGet-Mailboxin the next reach the same session.Reset sessionon the Common Tasks tab throws it away along with every connection; so does closing TechDeck. - That process is separate from TechDeck's own internal PowerShell, so a script that hangs or calls
exitcannot take the app down. It inherits TechDeck's elevation — an elevated TechDeck means an elevated console, and the banner on the tab says which you have. - The console runs hidden, so the Windows account picker has nowhere to appear and Microsoft sign-in fails with "a window handle must be configured". TechDeck recognises that error and offers
Fix and run again, adding the flag for a device-code or browser sign-in (-DisableWAM,-UseDeviceCode,-DeviceLoginor-UseDeviceAuthentication). - Installed modules are read from both
Get-Module -ListAvailableand PowerShellGet's own record. A module that installed correctly but cannot load in the selected version is reported as exactly that, rather than as missing or as a failed install. - Tasks marked
works on a listaccept up to 100 values pasted one per line; commas and semicolons separate them too. Each row is run and reported separately, so one bad address does not hide the ones that worked.
Traps
- Installing a module into the wrong version succeeds and then the module is simply invisible — a genuinely confusing half hour. Set
PowerShell versionfirst; the install dialog warns when the module needs the other host, and the catalog offers to switch for you. Microsoft.GraphandAzpull in many sub-modules and can take several minutes. Gallery installs and RSAT features both need internet on the customer's machine.- Tasks tagged
changes thingsalter live configuration on whatever tenant the session is signed in to. The command preview above the button is built from the values you typed and is shown before anything runs — read it. - The history file lives in TechDeck's
datafolder and travels with the toolkit. Preset commands are recorded with secrets masked, but commands you type in the console are stored as you typed them. Clear it before the stick goes to another site. - This screen installs modules and never removes one — there is no uninstall button anywhere on it. To take a module off a customer's machine, run
Uninstall-Moduleyourself in theConsoletab, and remember that adding-AllVersionsremoves every version rather than the newest.
Technical detail
Implemented by app/server/modules/72-powershell.js.
Actions it exposes: connections, favourite, history, historyClear, hosts, install, installPwsh, installRsat, modules, preflight, presetBulk, presetPreview, presetRun, presets, resetSession, rsat, run, search, uninstallModule
Report
Export a client-ready summary

What it is
One screen with two buttons that produces a client-ready service report: a single self-contained HTML file with no external assets or attachments, which opens in any browser and prints cleanly. It is called Client Report in the sidebar and Service Report on the page and in the file itself.
When you would use it
End of a job, handover, before-and-after evidence, or when quoting an upgrade — the memory configuration table showing populated and free slots is included for exactly that.
How to use it
- Press
Generate report. The screen shows one line — "Sweeping the machine and building the report…" — and nothing else until it finishes: no percentage and no stage names. Behind it, seven checks run in order: system info, volumes, triage sweep, disk health, security posture, hardware inventory and crash history. - When it finishes you get the health score out of 100, the number of findings, the file size and the full path to the file.
- Press
Open reportto open it in the default browser, orCopy pathto put the path on the clipboard for an email. - Press
Open reports folderto open the folder in Explorer. This works before you have generated anything — the folder is created when TechDeck starts. - Print from the browser if the client wants paper. The file carries its own print styling and avoids splitting a section across two pages.
Worth knowing
- The file lands in TechDeck's own
datafolder asreport-<COMPUTERNAME>-<date>-<time>.html. Nothing is uploaded anywhere; the report is written to the machine you are working on and stays there until you move it. - Sections, in order: Summary (health score, issues found, operating system and build, uptime); Findings, each with a recommended action where the check supplies one; System; Storage; Disk Health; Security; Stability over the last 30 days; and Memory Configuration.
- The report reuses the other screens' own checks rather than repeating them, so what it says about disk health or security posture is the same reading you would get on those screens at that moment.
- The footer records the generation time and the TechDeck session id, and states in writing that the findings are automated and should be confirmed by the technician before being acted on.
- The timestamp in the filename is UTC. The times printed inside the report are the machine's local time, so the two can differ by hours.
Traps
- The report contains the machine's serial number, the logged-in user name and the full security posture — which antivirus is active, firewall state per profile, BitLocker and UAC. Treat it as client data: appropriate to hand to the owner, not to leave on their desktop or forward to a third party.
- A section that failed silently disappears from the file. If Storage, Disk Health, Security, Stability or Memory Configuration is not in the report, that check did not run — it does not mean nothing was found there.
- A health score of
—printed next to "No issues found during the automated sweep" means the sweep itself did not run. The report prints that same all-clear line when the triage step returned nothing at all. With no score, do not quote the all-clear to a client. - The Stability section prints zero unexpected shutdowns and zero error events when the event log could not be read. The report does not carry the "could not check" warning that the Events screen shows, so confirm there before describing a machine as stable.
- Generating takes a while and the screen gives no sign of how far along it is — the security stage alone is allowed two minutes for the Windows Update history. Start it while you do something else. Run TechDeck as administrator first, or the Disk Health table comes out with blank wear and power-on columns.
Technical detail
Implemented by app/server/modules/90-report.js.
Actions it exposes: build, folder, open
Nothing in the manual matches that.