Insider Threat Matrix™Insider Threat Matrix™
HumanSynthetic
  • Sponsors
  • About Us
  • Contributors
  • Sponsors
  • About Us
  • Contributors

Pyae Heinn Kyaw

Cyber Incident Response Specialist

  • AR5
  • -AF016
human

Uninstalling Software - AR5

The subject uninstalls software, which may also remove relevant artifacts from the system's disk, such as regsitry keys or files necessary for the software to run, preventing them from being used by investigators to track activity.
  • Detections
  • -DT095
human

Windows Event Log, Software Uninstallation - DT095

In some cases it is possible to identify software that has been uninstalled by reviewing two specific Event IDs within the Windows Logs > Application log relating to the Windows installer service. Event ID 11724: This event is logged when a software product is uninstalled. The event provides information about the product name, the version, and the user who initiated the uninstallation. Event ID 1034: This event is generated by the Windows Installer service and indicates that an application has been uninstalled. It provides details about the product name and the success or failure of the uninstallation process.
  • About us
  • Contributors
  • Sponsors
  • Privacy Policy
  • Terms of use
  • Manage Cookies

The Insider Threat Matrix™ is an open framework for computer-enabled insider threat investigations.


© 2026 Forscie Limited. All rights reserved. Insider Threat Matrix™ is a trademark of Forscie Limited.

  • GitHub
  • X
  • Reddit
  • LinkedIn