WMIC
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: LOLBin / GTFOBins Browser
Windows Management Instrumentation Command-line (WMIC). Powerful interface for querying and managing Windows systems. NOTE: WMIC is deprecated but still widely used. Consider PowerShell CIM cmdlets.
BASIC SYNTAX#
wmic [alias] [where clause] [verb] [properties] wmic /node:REMOTE [alias] ... # Remote system wmic /user:USER /password:PASS ... # With credentials
SYSTEM INFORMATION#
OS & COMPUTER#
wmic os get caption,version,buildnumber wmic os get caption,osarchitecture,serialnumber wmic os get lastbootuptime # Boot time wmic os get installdate # Install date wmic os get freephysicalmemory # Free RAM wmic os get totalvisiblememorysize # Total RAM wmic computersystem get name,domain,manufacturer,model wmic computersystem get username # Logged user wmic computersystem get totalphysicalmemory wmic computersystem get systemtype # 32/64 bit
BIOS & HARDWARE#
wmic bios get serialnumber,manufacturer,version wmic baseboard get manufacturer,product,serialnumber wmic cpu get name,numberofcores,maxclockspeed wmic memorychip get capacity,manufacturer,speed wmic diskdrive get model,size,interfacetype wmic nic get name,macaddress,speed
PROCESSES#
wmic process list brief # List all processes wmic process list full # Full details wmic process get name,processid,commandline wmic process get name,processid,parentprocessid wmic process get name,executablepath wmic process where name="notepad.exe" get processid wmic process where processid=1234 get name,commandline wmic process where name="malware.exe" delete wmic process where name="calc.exe" call terminate wmic process call create "cmd.exe" # Start process # Find suspicious processes wmic process get name,parentprocessid,processid | findstr /i cmd wmic process where "not executablepath like '%Windows%'" get name,executablepath
SERVICES#
wmic service list brief # List services wmic service get name,startmode,state wmic service where name="servicename" get * wmic service where state="running" get name wmic service where startmode="auto" get name,state wmic service where name="servicename" call startservice wmic service where name="servicename" call stopservice wmic service where name="servicename" call changestartmode disabled # Find suspicious services wmic service where "not pathname like '%Windows%'" get name,pathname
STARTUP PROGRAMS#
wmic startup list brief # Startup items wmic startup get caption,command,location wmic startup get name,location,command,user
USERS & GROUPS#
wmic useraccount list brief # Local users wmic useraccount get name,sid,status wmic useraccount where name="user" get sid wmic useraccount where "disabled=false" get name wmic group list brief # Local groups wmic group get name,sid
NETWORK#
wmic nicconfig get description,ipaddress,macaddress wmic nicconfig where ipenabled=true get ipaddress,defaultipgateway,dnsserversearchorder wmic nicconfig get description,dhcpenabled wmic netlogin get name,lastlogon,badpasswordcount wmic rdtoggle list brief # RDP status
SHARES & MAPPED DRIVES#
wmic share get name,path,type wmic share where "type=0" get name,path wmic logicaldisk get caption,description,drivetype,filesystem,size,freespace wmic logicaldisk where drivetype=3 get caption,filesystem,size,freespace # Drive types: 2=Removable, 3=Local, 4=Network, 5=CD-ROM
INSTALLED SOFTWARE#
wmic product list brief # Installed software wmic product get name,version,vendor wmic product where name="Program Name" get installdate wmic product where name="Program Name" call uninstall /nointeractive # QFE (Quick Fix Engineering) - Patches wmic qfe list brief # Installed patches wmic qfe get hotfixid,installedon,description wmic qfe where hotfixid="KB5000802" get *
SCHEDULED TASKS#
wmic job list brief # AT jobs (legacy)
ENVIRONMENT#
wmic environment list brief # Environment variables wmic environment where name="PATH" get variablevalue wmic environment where "username='<SYSTEM>'" get name,variablevalue
EVENT LOGS#
wmic ntevent where "logfile='Security'" get * /format:list wmic ntevent where "logfile='System' and eventtype=1" get timegenerated,message wmic nteventlog get logfilename,numberofrecords wmic nteventlog where "logfilename='Security'" call cleareventlog
REMOTE EXECUTION#
wmic /node:COMPUTER process list brief wmic /node:COMPUTER /user:DOMAIN\USER /password:PASS process list wmic /node:@computers.txt process list brief wmic /node:COMPUTER process call create "cmd.exe /c command" wmic /node:COMPUTER service where name="service" call startservice
OUTPUT FORMATS#
wmic process list /format:csv # CSV output wmic process list /format:list # List format wmic process list /format:table # Table format wmic process list /format:htable # HTML table wmic process list /format:hform # HTML form wmic process list /format:xml # XML output # Save to file wmic process list /format:csv > processes.csv
ALIASES#
# Common WMIC aliases alias # List all aliases baseboard # Motherboard bios # BIOS info bootconfig # Boot configuration computersystem # Computer info cpu # Processor datafile # File info diskdrive # Disk drives environment # Environment vars group # Local groups logicaldisk # Logical drives memorychip # RAM modules netlogin # Network logins netuse # Network connections nic # Network adapters nicconfig # NIC configuration ntevent # Event log entries nteventlog # Event logs os # Operating system partition # Disk partitions process # Processes product # Installed software qfe # Patches/hotfixes service # Services share # Shared folders startup # Startup programs sysaccount # System accounts sysdriver # System drivers useraccount # User accounts volume # Volumes
SECURITY ANALYSIS#
# Find processes running from temp directories wmic process where "executablepath like '%Temp%'" get name,executablepath,processid # Find processes running from user directories wmic process where "executablepath like '%Users%'" get name,executablepath # List all running services and paths wmic service where state="running" get name,pathname # Find auto-start services not in System32 wmic service where "startmode='Auto' and not pathname like '%System32%'" get name,pathname # Check for hidden shares wmic share where "type=2147483651" get name,path # Find accounts that never expire wmic useraccount where passwordexpires=false get name # Check RDP settings wmic rdtoggle get allowtsconnections
USEFUL ONE-LINERS#
# Get computer serial number wmic bios get serialnumber # Get Windows product key wmic path softwarelicensingservice get OA3xOriginalProductKey # List installed hotfixes wmic qfe list brief | more # Find process by port (combine with netstat) # netstat -ano | findstr :80 # wmic process where processid=PID get name,commandline # Kill multiple processes wmic process where "name like 'chrome%'" call terminate # Remote system info wmic /node:COMPUTER os get caption,version # Export process list to CSV wmic process get name,processid,commandline /format:csv > processes.csv # Find suspicious scheduled tasks wmic job list full
POWERSHELL EQUIVALENTS#
# WMIC is deprecated, use PowerShell CIM cmdlets: wmic os get caption -> Get-CimInstance Win32_OperatingSystem wmic process list -> Get-CimInstance Win32_Process wmic service list -> Get-CimInstance Win32_Service wmic bios get serialnumber -> Get-CimInstance Win32_BIOS # Or legacy WMI cmdlets: Get-WmiObject Win32_OperatingSystem Get-WmiObject Win32_Process Get-WmiObject Win32_Service