Query live system information on Windows using CIM cmdlets (Get-CimInstance) and WQL filters

domain: learn.microsoft.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. List all running processes with memory usage: Get-CimInstance -ClassName Win32_Process | Select-Object Name, ProcessId, WorkingSetSize
  2. Filter using the -Filter parameter (WQL WHERE syntax, not PowerShell): Get-CimInstance -ClassName Win32_Service -Filter "State = 'Running' AND StartMode = 'Auto'"
  3. Use a full WQL query string: Get-CimInstance -Query "SELECT * FROM Win32_Process WHERE WorkingSetSize > 104857600"
  4. Query a remote machine: Get-CimInstance -ClassName Win32_OperatingSystem -ComputerName <HOSTNAME>
  5. Discover available WMI classes: Get-CimClass -Namespace root/cimv2 | Where-Object CimClassName -Like 'Win32_*' | Select-Object CimClassName

Known gotchas

Related routes

discover and query WMI classes on the local machine with Get-CimClass and Get-CimInstance instead of the deprecated WMI cmdlets
learn.microsoft.com · 5 steps · unrated
Query live system state across macOS, Linux, and Windows using osquery's interactive shell and SQL tables
osquery.io · 5 steps · unrated
Use PowerShell's CIM remoting to query hardware and OS inventory across multiple remote Windows machines in bulk
learn.microsoft.com · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans