Skip to content

Advanced WMI/CIM

Advanced WMI/CIM Automation

WMI (Windows Management Instrumentation) and CIM (Common Information Model) provide powerful capabilities for system monitoring, inventory collection, and configuration management. While WMI is the legacy framework, CIM is the modern, standardized replacement. This section demonstrates advanced techniques for leveraging these technologies in PowerShell scripts, including performance monitoring, hardware/software inventory, and configuration automation.


Monitoring System Performance with WMI/CIM

WMI and CIM can retrieve real-time performance metrics from local or remote systems. Use Get-CimInstance (preferred) or Get-WmiObject for querying.

Example: Monitor Disk Usage

Get-CimInstance -ClassName Win32_LogicalDisk | Where-Object { $_.DriveType -eq 3 } | Select-Object DeviceID, FreeSpace, Size
This retrieves free space and total size for all local drives (excluding removable drives).

Example: Track CPU Load

Get-CimInstance -ClassName Win30_PerfFormattedData_PerfOS_Processor | Where-Object { $_.Name -like "*_Total*" } | Select-Object Name, PercentProcessorTime
Queries CPU usage across all cores.

Example: Monitor Service Status

Get-CimInstance -ClassName Win32_Service | Where-Object { $_.State -eq "Running" -and $_.StartMode -eq "Automatic" } | Select-Object Name, DisplayName
Lists all automatically started services that are currently running.


Inventory Collection: Hardware and Software

WMI/CIM can gather detailed system inventory, including hardware, OS, and installed software.

Example: System Hardware Inventory

Get-CimInstance -ClassName Win32_ComputerSystem | Select-Object Manufacturer, Model, TotalPhysicalMemory, SystemType
Provides system model, memory, and architecture details.

Example: Installed Software Inventory

Get-CimInstance -ClassName Win32_Product | Select-Object Name, Version, Publisher
Lists installed software (note: Win32_Product may not capture all applications, especially those installed via MSI).

Example: Network Adapter Information

Get-CimInstance -ClassName Win32_NetworkAdapterConfiguration | Where-Object { $_.IPEnabled -eq $true } | Select-Object IPAddress, DNSDomain
Retrieves IP addresses and DNS settings for active network adapters.


Configuration Management with CIM

CIM enables programmatic control of system settings, such as services, registry keys, and user accounts.

Example: Start a Stopped Service

$service = Get-CimInstance -ClassName Win32_Service -Filter "Name='wuauserv'"
if ($service.State -eq "Stopped") {
    $service.StartService()
    Write-Output "Service 'Windows Update' started."
}
Starts the Windows Update service if it’s stopped.

Example: Modify Registry Settings

$registry = Get-CimInstance -ClassName Win32.Registry -Filter "Key='HKLM:\Software\MyApp'"
if ($registry) {
    $registry.SetValue("Enabled", 1, "DWORD")
    Write-Output "Registry key updated."
}
Sets a registry value (requires admin privileges).

Example: Create a User Account

$account = Get-CimInstance -ClassName Win32_UserAccount -Filter "Name='NewUser'"
if (-not $account) {
    $newAccount = New-CimInstance -ClassName Win32_UserAccount -Property @{
        Name = "NewUser"
        Password = "P@ssw0rd!"
        FullName = "New User"
        Description = "Automatically created user"
        PasswordChangeable = $true
        PasswordExpires = $false
    }
    Write-Output "User account 'NewUser' created."
}
Creates a new user account with specified properties.


Best Practices for WMI/CIM Automation

  1. Prefer CIM over WMI: CIM is more efficient, supports remote management, and aligns with modern standards.
  2. Use -ErrorAction for robustness: Handle errors gracefully in production scripts.
  3. Optimize queries: Filter results with -Filter to reduce data transfer and processing overhead.
  4. Secure remote access: Use Invoke-CimMethod with proper authentication for cross-system management.
  5. Test permissions: Many CIM operations require elevated privileges (e.g., registry edits, user account creation).

Key takeaways

  • Use Get-CimInstance and Invoke-CimMethod for modern, efficient system management.
  • Combine WMI/CIM with filtering and error handling to build robust monitoring and configuration scripts.
  • Prioritize CIM for remote management and complex inventory tasks.
  • Always validate permissions and test scripts in controlled environments before deploying.
  • Leverage CIM’s structured data model for consistent, scalable automation workflows.