# Node Investigator: A PowerShell GUI for Stale Node Cleanup Every sysadmin eventually faces the same chore: a server or workstation gets retired, and its ghost lingers across Active Directory, DNS, and DHCP. Cleaning it up means bouncing between three consoles, double-checking names and IPs, and hoping you didn't miss a record. **Node Investigator** is a single-file PowerShell WinForms tool that does the whole investigation from one window. Type in an FQDN, click **Investigate**, and it checks every system, reports what it finds, and (optionally) purges the records. Every run is logged to SQL Server so you have an audit trail of who looked at what, and what was deleted. --- ## What It Does For any FQDN you enter, the tool runs these checks in order: 1. **Active Directory.** Searches for a matching computer object across a configurable list of OUs and reports the last logon date. 2. **DNS.** Resolves the FQDN (falling back to the short name) against your configured DNS servers. 3. **Ping.** Tests connectivity using the resolved IP, or the FQDN if DNS came up empty. 4. **DHCP.** Walks every scope on your DHCP servers looking for a lease matching the hostname or the resolved IP. 5. **Optional cleanup.** With **Delete Mode** enabled, it prompts for confirmation, then removes the AD object, DNS record, and DHCP lease. 6. **SQL logging.** Writes the results and action taken to a SQL table. Everything is shown in a console-style output pane inside the GUI. ## Features - **Audit by default.** Nothing is deleted unless you tick *Enable Delete Mode* **and** confirm a warning dialog. - **External config.** Servers, OUs, and SQL settings live in a `config.json` next to the script. An **Edit Config** button opens it in Notepad, and the config is re-read on every run, so no restart is needed. - **Auto-generated config.** On first launch, the script creates a `config.json` with sensible defaults. - **Targeted AD search.** Only the OUs you list are searched, which keeps lookups fast and avoids touching objects you don't intend to. - **SQL audit trail.** Every investigation is logged using parameterized queries. - **Keyboard friendly.** Press Enter in the FQDN box to run. ## Requirements - Windows with PowerShell 5.1 or later - [RSAT](https://learn.microsoft.com/en-us/windows-server/remote/remote-server-administration-tools) modules installed: - `ActiveDirectory` - `DnsServer` - `DhcpServer` - Permissions to read (and, for Delete Mode, modify) AD, DNS, and DHCP - Access to a SQL Server database for logging ## Setup ### 1. Create the SQL table ```sql CREATE TABLE dbo.NodeCleanupLogs ( Id INT IDENTITY(1,1) PRIMARY KEY, Timestamp DATETIME NOT NULL, FQDN NVARCHAR(255) NOT NULL, PingStatus NVARCHAR(50) NULL, ADStatus NVARCHAR(255) NULL, DNSStatus NVARCHAR(255) NULL, DHCPStatus NVARCHAR(255) NULL, ActionTaken NVARCHAR(50) NULL ); ``` ### 2. Run the script once to generate `config.json` ```powershell .\NodeInvestigator.ps1 ``` ### 3. Edit the config Click **Edit Config** (or open `config.json` directly) and fill in your environment: ```json { "DnsServers": ["dns1.example.com", "dns2.example.com"], "DhcpServers": ["dhcp1.example.com"], "SearchBaseOUs": [ "OU=Servers,DC=example,DC=com", "OU=Workstations,DC=example,DC=com" ], "SqlConnectionString": "Server=YOUR_SQL_SERVER;Database=YOUR_DB_NAME;Integrated Security=True;", "SqlTableName": "NodeCleanupLogs" } ``` | Setting | Purpose | |---|---| | `DnsServers` | DNS servers to query. The first entry is also used as the target for record deletion. | | `DhcpServers` | DHCP servers whose scopes are searched for leases. | | `SearchBaseOUs` | OUs searched for the computer object. | | `SqlConnectionString` | Connection string for the audit database. | | `SqlTableName` | Table that receives the log rows. | ### 4. Run it Launch the script from an elevated PowerShell session (or an account with the needed rights), enter a FQDN, and click **Investigate**. ## Example Output ``` -------------------------------------------------- Investigating: oldserver01.example.com [+] AD: Record found in OU=Servers,DC=example,DC=com. Last Logon: 03/14/2025 08:22:10 [+] DNS: Resolved to 10.20.30.40 via dns2.example.com [!] Ping: Failed [+] DHCP: Lease found (10.20.30.40) on dhcp1.example.com --- Successfully logged to SQL Database --- ``` ## Using Delete Mode 1. Run an audit first and review what was found. 2. Tick **Enable Delete Mode**. 3. Click **Investigate** again and confirm the warning dialog. Deletion removes the AD computer object, the DNS record from the zone, and the DHCP lease, and the SQL log records the action as `DELETED`. If you cancel the dialog, nothing is removed and the run is logged as an audit. > **Heads up:** Deletions are permanent. Consider enabling the AD Recycle Bin and testing against a non-production node first. ## Notes and Limitations - The DNS deletion step assumes the zone is `domain.com`, so adjust that value in the script for your own domain. - The tool is single-threaded, and the GUI may appear busy while scanning large DHCP scope lists. - Only IPv4 DHCP is supported. ## Future Ideas - Bulk mode: import a CSV of FQDNs - Export results to CSV - Zone name as a config setting - Background runspaces to keep the UI responsive ## License Use it, modify it, and share it. If it saves you an afternoon of console hopping, I'd love to hear about it. ### Github hfjshfjkhfkfhjkls