Advanced WMI/CIM
Advanced WMI/CIM Automation¶
WMI (Windows Management Instrumentation) and CIM (Common Information Model) provide powerful capabilities for system monitoring, inventory collection, and configuration management. While WMI is the legacy framework, CIM is the modern, standardized replacement. This section demonstrates advanced techniques for leveraging these technologies in PowerShell scripts, including performance monitoring, hardware/software inventory, and configuration automation.
Monitoring System Performance with WMI/CIM¶
WMI and CIM can retrieve real-time performance metrics from local or remote systems. Use Get-CimInstance (preferred) or Get-WmiObject for querying.
Example: Monitor Disk Usage¶
Get-CimInstance -ClassName Win32_LogicalDisk | Where-Object { $_.DriveType -eq 3 } | Select-Object DeviceID, FreeSpace, Size
Example: Track CPU Load¶
Get-CimInstance -ClassName Win30_PerfFormattedData_PerfOS_Processor | Where-Object { $_.Name -like "*_Total*" } | Select-Object Name, PercentProcessorTime
Example: Monitor Service Status¶
Get-CimInstance -ClassName Win32_Service | Where-Object { $_.State -eq "Running" -and $_.StartMode -eq "Automatic" } | Select-Object Name, DisplayName
Inventory Collection: Hardware and Software¶
WMI/CIM can gather detailed system inventory, including hardware, OS, and installed software.
Example: System Hardware Inventory¶
Get-CimInstance -ClassName Win32_ComputerSystem | Select-Object Manufacturer, Model, TotalPhysicalMemory, SystemType
Example: Installed Software Inventory¶
Lists installed software (note:Win32_Product may not capture all applications, especially those installed via MSI).
Example: Network Adapter Information¶
Get-CimInstance -ClassName Win32_NetworkAdapterConfiguration | Where-Object { $_.IPEnabled -eq $true } | Select-Object IPAddress, DNSDomain
Configuration Management with CIM¶
CIM enables programmatic control of system settings, such as services, registry keys, and user accounts.
Example: Start a Stopped Service¶
$service = Get-CimInstance -ClassName Win32_Service -Filter "Name='wuauserv'"
if ($service.State -eq "Stopped") {
$service.StartService()
Write-Output "Service 'Windows Update' started."
}
Example: Modify Registry Settings¶
$registry = Get-CimInstance -ClassName Win32.Registry -Filter "Key='HKLM:\Software\MyApp'"
if ($registry) {
$registry.SetValue("Enabled", 1, "DWORD")
Write-Output "Registry key updated."
}
Example: Create a User Account¶
$account = Get-CimInstance -ClassName Win32_UserAccount -Filter "Name='NewUser'"
if (-not $account) {
$newAccount = New-CimInstance -ClassName Win32_UserAccount -Property @{
Name = "NewUser"
Password = "P@ssw0rd!"
FullName = "New User"
Description = "Automatically created user"
PasswordChangeable = $true
PasswordExpires = $false
}
Write-Output "User account 'NewUser' created."
}
Best Practices for WMI/CIM Automation¶
- Prefer CIM over WMI: CIM is more efficient, supports remote management, and aligns with modern standards.
- Use
-ErrorActionfor robustness: Handle errors gracefully in production scripts. - Optimize queries: Filter results with
-Filterto reduce data transfer and processing overhead. - Secure remote access: Use
Invoke-CimMethodwith proper authentication for cross-system management. - Test permissions: Many CIM operations require elevated privileges (e.g., registry edits, user account creation).
Key takeaways¶
- Use
Get-CimInstanceandInvoke-CimMethodfor modern, efficient system management. - Combine WMI/CIM with filtering and error handling to build robust monitoring and configuration scripts.
- Prioritize CIM for remote management and complex inventory tasks.
- Always validate permissions and test scripts in controlled environments before deploying.
- Leverage CIM’s structured data model for consistent, scalable automation workflows.