ITM is an open framework - Submit your contributions now.

Insider Threat Matrix™Insider Threat Matrix™
  • ID: DT148
  • Created: 23rd October 2025
  • Updated: 23rd October 2025
  • Platform: Windows
  • MITRE ATT&CK®: DS0024
  • Contributor: The ITM Team

Installed Software via Registry

Three key registry paths can be used to enumerate installed software:

  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
  • HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\

 

Registry values of interest include:

  • DisplayName - the name of the application
  • DisplayVersion - the version of the application
  • InstallLocation - the location on disk where files related to the application are stored
  • Publisher - the publisher of the application