Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

NirCmd is a portable Windows command-line utility for carrying out focused tasks—such as muting audio, turning off a monitor, creating shortcuts, or controlling windows—from a command prompt or script. It is freeware and does not need an installer or background service. Another tool, such as a batch file or Task Scheduler, must invoke it when needed. NirCmd is handy for compact jobs, but it is not a substitute for PowerShell or a full automation system when you need complex logic, logging, or reliable application-specific automation.

The latest version identified on NirSoft’s official NirCmd page is 2.87, released April 23, 2024. Its published compatibility text is dated and lists Windows versions through Windows 10, so it does not amount to a current formal Windows 11 support statement.

What NirCmd can do

NirCmd is a standalone executable that asks Windows to perform an action without opening a conventional interface. You can call it from Command Prompt, PowerShell, a batch file, a shortcut, Task Scheduler, or another program that can launch a process. It normally runs to perform the requested action and exits; it is not inherently a program that stays resident and monitors your PC.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The official command reference covers a broad range of actions. Representative examples include:

Task Command families
Display, lock, and power monitor, screensaver, lockws, and power commands
System audio changesysvolume, setsysvolume, mutesysvolume
Windows, dialogs, and keystrokes win, dlg, sendkey, sendkeypress
Launch and wait for programs exec, exec2, cmdwait
Files and folders clonefiletime, emptybin, filldelete, setfiletime
Shortcuts shortcut, cmdshortcut
Services and remote computers service, remote, multiremote
Administrative execution elevate, elevatecmd

It can also work with clipboard contents, show tray notifications, play media or speech, and read or change Registry and INI data. Those capabilities are useful, but actions that alter files, services, or the Registry deserve testing and a rollback plan.

Version, downloads, and executable choices

Download NirCmd from the official product page. The page identifies version 2.87, dated April 23, 2024, and offers 32-bit and x64 builds. For ordinary use on 64-bit Windows, choose the x64 build; use 32-bit when a specific compatibility need calls for it. The architectures are not guaranteed to be interchangeable in every process-, Registry-, or DLL-related scenario.

The package includes distinct executable variants:

  • nircmd.exe is the normal executable.
  • nircmdc.exe is the console version, intended to send error messages to the console rather than display message boxes. It can be more convenient for scripts and console troubleshooting.

Extract the complete ZIP into a controlled folder if you need the accompanying package files. NirSoft describes the utility as a standalone executable that needs no installation process or additional DLLs. NirSoft utilities are generally distributed as ZIP archives and can be manually removed by deleting the extracted files; see its installation guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Install it and run a first test

  1. Open the official NirCmd page and select the appropriate build.
  2. Extract the ZIP to a folder you control, for example C:ToolsNirCmd or %LOCALAPPDATA%ProgramsNirCmd.
  3. Open Command Prompt or PowerShell in that folder and check that the executable runs:
    nircmd.exe help
    nircmd.exe help monitor
  4. Optionally add the folder to your user or system PATH to call NirCmd without typing its full location. For scheduled and administrative scripts, using an absolute executable path is generally more predictable.

NirCmd documents this general syntax:

nircmd.exe {showerror} [command] [command parameters]

showerror is an optional diagnostic switch. It asks NirCmd to display an error when a command fails; without it, some errors may be suppressed. Use it while developing and troubleshooting. For example, NirSoft documents this pattern:

nircmd.exe showerror rasdial "dial1"

Some commands or failure conditions may not provide the process exit code a script author expects. Check the command’s documentation and test its behavior in the actual environment rather than treating an exit code as a complete account of success.

Useful commands by outcome

Turn off the display, start the screensaver, or lock Windows

NirSoft documents these examples:

nircmd.exe monitor off
nircmd.exe screensaver
nircmd.exe lockws

They can be useful in a desktop shortcut or a routine you invoke yourself. A monitor-off command is not the same as shutting down the PC. Test display-related behavior on the machine and display setup where you intend to use it.

Adjust or mute system volume

NirCmd’s system-volume examples use a scale up to 65,535; treat that as the command’s scale, not as a percentage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
nircmd.exe setsysvolume 65535
nircmd.exe changesysvolume 2000
nircmd.exe changesysvolume -5000
nircmd.exe mutesysvolume 1
nircmd.exe mutesysvolume 0
nircmd.exe mutesysvolume 2

The mute command’s documented modes include mute, unmute, and toggle. If you need to select particular audio endpoints or manage application-specific sound in more detail, NirSoft’s separate SoundVolumeView may be a better fit.

Create a desktop shortcut

The shortcut command can create a shortcut using a target, destination folder, and title. For example, NirSoft documents:

nircmd.exe shortcut "C:WindowsSystem32calc.exe" "~$folder.desktop$" "Windows Calculator"

The special folder token ~$folder.desktop$ resolves to the desktop location; ~$folder.programs$ is another documented token. The command also supports optional arguments such as shortcut arguments, icon, show state, start-in folder, and hotkey. See the shortcut reference for the full syntax. For complex deployment rules, a PowerShell script may make the intended shortcut settings easier to review.

Launch a program and control a window

NirCmd offers program-launching commands such as exec and exec2, as well as commands for waiting, closing or killing processes, and manipulating windows. Quote paths containing spaces, and consult the relevant command page for the exact parameter order. A basic quoted launch pattern is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
nircmd.exe exec show "C:Program FilesAppApp.exe"

The win reference documents actions including close, hide, show, maximize, minimize, activate, and flash. Matching a window by its title can be fragile: titles may change with the open document, application version, language, or current state. The dlg command can interact with standard dialog controls, such as clicking a button or setting text, but custom controls and changing interfaces may not behave as expected.

Window, dialog, and keystroke commands are best-effort UI automation, not a dependable application API. They can fail if the target is not active, the desktop is locked, the application runs in another session or at a different integrity level, or the dialog title or controls differ. Prefer an application API or a more robust automation method for a workflow where a missed click could cause harm.

Files, notifications, clipboard, and configuration

The command catalog includes file operations such as copying timestamps with clonefiletime, setting timestamps with setfiletime, emptying the Recycle Bin with emptybin, and deletion-related commands such as filldelete. Use sample files and explicit, quoted paths before applying file commands to valuable data. Do not depend on an unspecified current working directory in a scheduled job.

Other commands can show tray balloons or message-style notifications, produce beeps, play media, or use speech components. These can provide a completion cue, but depend on the user session and relevant Windows components. Clipboard commands can expose sensitive text; avoid placing secrets on the clipboard or leaving them there unnecessarily.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NirCmd can also change Registry keys and values or edit INI files. Confirm the exact path and value type, consider 32-bit versus 64-bit Registry views, and determine whether administrative permissions are required. Back up important Registry data before changing it. Do not put credentials, tokens, or other secrets in batch files or command-line arguments.

Use NirCmd from batch files, PowerShell, and Task Scheduler

NirCmd performs an action; the calling tool supplies the logic and execution schedule. For example, a batch file can call the executable by absolute path:

@echo off
set "NIRCMD=C:ToolsNirCmdnircmd.exe"
"%NIRCMD%" showerror monitor off
if errorlevel 1 exit /b %errorlevel%

This example checks the process exit status, but that status should not be assumed to describe every NirCmd failure mode. Test the command, diagnostic behavior, and script flow before relying on it.

PowerShell can invoke the same executable:

$NirCmd = 'C:ToolsNirCmdnircmd.exe'
& $NirCmd showerror monitor off
if ($LASTEXITCODE -ne 0) {
    throw "NirCmd failed with exit code $LASTEXITCODE"
}

When using Task Scheduler:

  • Specify the full path to the executable or script, and set the working directory deliberately if relative paths are involved.
  • Choose whether the task runs only when the user is logged on. UI actions may not work in a noninteractive session, on a locked desktop, or after a Remote Desktop session changes state.
  • Test under the actual task account. Its permissions, mapped drives, environment, and session can differ from your interactive account.
  • Use nircmdc.exe when console-oriented error reporting is useful, and arrange logging in the calling script if you need a durable record.
  • Avoid secrets in command-line arguments, which may be visible to administrators or diagnostic tools.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Elevation, services, and remote computers

NirCmd includes elevation commands, but these do not bypass Windows authorization. A user must have permission to elevate, and User Account Control may present a prompt. A scheduled task without an interactive desktop cannot necessarily respond to that prompt. Elevated and non-elevated processes can also differ in their access to files, Registry views, mapped drives, and windows.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The service command can start, stop, pause, continue, restart, or change the startup type of a service or driver. Examples documented by NirSoft include:

nircmd.exe service start schedule
nircmd.exe service restart w3svc
nircmd.exe service \remote stop schedule

Service changes can interrupt Windows or application functions. Verify the service name, host, permissions, and intended result before running a command—especially from an unattended task.

The remote command can execute a NirCmd command on another computer; its copy option copies NirCmd to the remote computer’s Windows directory first. Remote use requires suitable permissions and working network access, including any necessary firewall and administrative-share configuration. NirSoft says remote commands run under the remote machine’s SYSTEM account, so they may not behave like commands launched by that machine’s interactive user. Confirm the target host and consider account, audit, and security implications before proceeding.

NirSoft also documents runinteractive and runinteractivecmd for launching GUI-accessing work from a Windows service. A service is not the same as an interactive desktop: the version history notes that a service may not be able to access the user interface, and some UI-related operations can fail or produce unusable results in that context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is NirCmd safe to download?

NirCmd is freeware, not open-source software. NirSoft permits redistribution only if it is free of charge and the package files are included without modification. Its official product page describes the utility as portable, but portability does not mean every command runs without permission, nor does a vendor description guarantee that a particular download is safe for every environment.

NirSoft acknowledges recurring antivirus false-positive reports affecting its utilities in its FAQ. Treat an alert as something to investigate, not as proof either that a file is malicious or that it is harmless. A prudent process is to download only from NirSoft’s official domain, confirm that the archive and build are expected, scan it using your organization’s approved security tools, compare a published hash if one is provided, and report a suspected false positive to the security vendor. Do not disable protection broadly or use repacked downloads from unofficial mirrors. An organization may still prohibit the executable because it is proprietary or outside its approved software policy.

Limitations and alternatives

Choose NirCmd when one compact command can perform a clearly defined Windows action and you already have a shortcut, batch file, or scheduled task to invoke it. Its breadth and portability are convenient, particularly for desktop actions that are awkward in traditional batch syntax.

Prefer PowerShell or a built-in Windows tool when the task needs branching, loops, structured output, robust error handling, logging, testing, or maintainable administration code. PowerShell is generally easier to review for complex changes. Use AutoHotkey or a dedicated automation platform when you need persistent hotkeys, reusable application-specific UI workflows, or richer interaction logic. Microsoft Sysinternals and other Microsoft administration tools are more appropriate for many process, security, performance, and diagnostic tasks where official tooling and enterprise familiarity matter.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NirCmd’s trade-offs are its terse, older-style documentation, dated published compatibility list, variable diagnostics, fragile UI automation, and the care required for destructive, elevated, or remote operations. For a simple, tested action, it remains a small tool; for a critical workflow, use an interface and logging model designed for that level of reliability.

Where to find the command syntax

Use the complete NirCmd command reference for command names and parameters, and the product page for downloads, version information, examples, and version history. When a command affects files, services, the Registry, remote machines, or system power, verify its exact syntax and test it in the intended account and environment before automating it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.