← All cheat sheets

WMIC

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: LOLBin / GTFOBins Browser

Windows Management Instrumentation Command-line (WMIC).
Powerful interface for querying and managing Windows systems.
NOTE: WMIC is deprecated but still widely used. Consider PowerShell CIM cmdlets.

BASIC SYNTAX#

wmic [alias] [where clause] [verb] [properties]
wmic /node:REMOTE [alias] ...        # Remote system
wmic /user:USER /password:PASS ...   # With credentials

SYSTEM INFORMATION#


    

OS & COMPUTER#

wmic os get caption,version,buildnumber
wmic os get caption,osarchitecture,serialnumber
wmic os get lastbootuptime           # Boot time
wmic os get installdate              # Install date
wmic os get freephysicalmemory       # Free RAM
wmic os get totalvisiblememorysize   # Total RAM

wmic computersystem get name,domain,manufacturer,model
wmic computersystem get username     # Logged user
wmic computersystem get totalphysicalmemory
wmic computersystem get systemtype   # 32/64 bit

BIOS & HARDWARE#

wmic bios get serialnumber,manufacturer,version
wmic baseboard get manufacturer,product,serialnumber
wmic cpu get name,numberofcores,maxclockspeed
wmic memorychip get capacity,manufacturer,speed
wmic diskdrive get model,size,interfacetype
wmic nic get name,macaddress,speed

PROCESSES#

wmic process list brief              # List all processes
wmic process list full               # Full details
wmic process get name,processid,commandline
wmic process get name,processid,parentprocessid
wmic process get name,executablepath
wmic process where name="notepad.exe" get processid
wmic process where processid=1234 get name,commandline
wmic process where name="malware.exe" delete
wmic process where name="calc.exe" call terminate
wmic process call create "cmd.exe"   # Start process

# Find suspicious processes
wmic process get name,parentprocessid,processid | findstr /i cmd
wmic process where "not executablepath like '%Windows%'" get name,executablepath

SERVICES#

wmic service list brief              # List services
wmic service get name,startmode,state
wmic service where name="servicename" get *
wmic service where state="running" get name
wmic service where startmode="auto" get name,state
wmic service where name="servicename" call startservice
wmic service where name="servicename" call stopservice
wmic service where name="servicename" call changestartmode disabled

# Find suspicious services
wmic service where "not pathname like '%Windows%'" get name,pathname

STARTUP PROGRAMS#

wmic startup list brief              # Startup items
wmic startup get caption,command,location
wmic startup get name,location,command,user

USERS & GROUPS#

wmic useraccount list brief          # Local users
wmic useraccount get name,sid,status
wmic useraccount where name="user" get sid
wmic useraccount where "disabled=false" get name
wmic group list brief                # Local groups
wmic group get name,sid

NETWORK#

wmic nicconfig get description,ipaddress,macaddress
wmic nicconfig where ipenabled=true get ipaddress,defaultipgateway,dnsserversearchorder
wmic nicconfig get description,dhcpenabled
wmic netlogin get name,lastlogon,badpasswordcount
wmic rdtoggle list brief             # RDP status

SHARES & MAPPED DRIVES#

wmic share get name,path,type
wmic share where "type=0" get name,path
wmic logicaldisk get caption,description,drivetype,filesystem,size,freespace
wmic logicaldisk where drivetype=3 get caption,filesystem,size,freespace

# Drive types: 2=Removable, 3=Local, 4=Network, 5=CD-ROM

INSTALLED SOFTWARE#

wmic product list brief              # Installed software
wmic product get name,version,vendor
wmic product where name="Program Name" get installdate
wmic product where name="Program Name" call uninstall /nointeractive

# QFE (Quick Fix Engineering) - Patches
wmic qfe list brief                  # Installed patches
wmic qfe get hotfixid,installedon,description
wmic qfe where hotfixid="KB5000802" get *

SCHEDULED TASKS#

wmic job list brief                  # AT jobs (legacy)

ENVIRONMENT#

wmic environment list brief          # Environment variables
wmic environment where name="PATH" get variablevalue
wmic environment where "username='<SYSTEM>'" get name,variablevalue

EVENT LOGS#

wmic ntevent where "logfile='Security'" get * /format:list
wmic ntevent where "logfile='System' and eventtype=1" get timegenerated,message
wmic nteventlog get logfilename,numberofrecords
wmic nteventlog where "logfilename='Security'" call cleareventlog

REMOTE EXECUTION#

wmic /node:COMPUTER process list brief
wmic /node:COMPUTER /user:DOMAIN\USER /password:PASS process list
wmic /node:@computers.txt process list brief
wmic /node:COMPUTER process call create "cmd.exe /c command"
wmic /node:COMPUTER service where name="service" call startservice

OUTPUT FORMATS#

wmic process list /format:csv        # CSV output
wmic process list /format:list       # List format
wmic process list /format:table      # Table format
wmic process list /format:htable     # HTML table
wmic process list /format:hform      # HTML form
wmic process list /format:xml        # XML output

# Save to file
wmic process list /format:csv > processes.csv

ALIASES#

# Common WMIC aliases
alias                                # List all aliases
baseboard                            # Motherboard
bios                                 # BIOS info
bootconfig                           # Boot configuration
computersystem                       # Computer info
cpu                                  # Processor
datafile                             # File info
diskdrive                            # Disk drives
environment                          # Environment vars
group                                # Local groups
logicaldisk                          # Logical drives
memorychip                           # RAM modules
netlogin                             # Network logins
netuse                               # Network connections
nic                                  # Network adapters
nicconfig                            # NIC configuration
ntevent                              # Event log entries
nteventlog                           # Event logs
os                                   # Operating system
partition                            # Disk partitions
process                              # Processes
product                              # Installed software
qfe                                  # Patches/hotfixes
service                              # Services
share                                # Shared folders
startup                              # Startup programs
sysaccount                           # System accounts
sysdriver                            # System drivers
useraccount                          # User accounts
volume                               # Volumes

SECURITY ANALYSIS#

# Find processes running from temp directories
wmic process where "executablepath like '%Temp%'" get name,executablepath,processid

# Find processes running from user directories
wmic process where "executablepath like '%Users%'" get name,executablepath

# List all running services and paths
wmic service where state="running" get name,pathname

# Find auto-start services not in System32
wmic service where "startmode='Auto' and not pathname like '%System32%'" get name,pathname

# Check for hidden shares
wmic share where "type=2147483651" get name,path

# Find accounts that never expire
wmic useraccount where passwordexpires=false get name

# Check RDP settings
wmic rdtoggle get allowtsconnections

USEFUL ONE-LINERS#

# Get computer serial number
wmic bios get serialnumber

# Get Windows product key
wmic path softwarelicensingservice get OA3xOriginalProductKey

# List installed hotfixes
wmic qfe list brief | more

# Find process by port (combine with netstat)
# netstat -ano | findstr :80
# wmic process where processid=PID get name,commandline

# Kill multiple processes
wmic process where "name like 'chrome%'" call terminate

# Remote system info
wmic /node:COMPUTER os get caption,version

# Export process list to CSV
wmic process get name,processid,commandline /format:csv > processes.csv

# Find suspicious scheduled tasks
wmic job list full

POWERSHELL EQUIVALENTS#

# WMIC is deprecated, use PowerShell CIM cmdlets:
wmic os get caption              -> Get-CimInstance Win32_OperatingSystem
wmic process list                -> Get-CimInstance Win32_Process
wmic service list                -> Get-CimInstance Win32_Service
wmic bios get serialnumber       -> Get-CimInstance Win32_BIOS

# Or legacy WMI cmdlets:
Get-WmiObject Win32_OperatingSystem
Get-WmiObject Win32_Process
Get-WmiObject Win32_Service