[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxpDOvpMI9Adwxo4hrSA8hz8uEUQgkuc_OV8I5J5MG1s":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},659,"How can I obtain a complete list of installed programs on a Windows system using PowerShell?","You can enumerate the registry keys under `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall` (and its 32-bit counterpart `Wow6432Node` on 64-bit systems) using `Get-ItemProperty`. The article provides a PowerShell script that loops through subkeys and retrieves the `DisplayName`. This method covers all programs shown in Programs and Features, regardless of their installer type.","\u003Cp>You can enumerate the registry keys under `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall` (and its 32-bit counterpart `Wow6432Node` on 64-bit systems) using `Get-ItemProperty`. The article provides a PowerShell script that loops through subkeys and retrieves the `DisplayName`. This method covers all programs shown in Programs and Features, regardless of their installer type.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-obtaining-the-list-of-installed-programs-on-the-current-system\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-obtain-a-complete-list-of-installed-programs-on-a-windows-system-using-1777482708634","PowerShell, registry enumeration, Uninstall key, DisplayName, 32-bit redirection",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},164,"Penetration Basics - Obtaining the List of Installed Programs on the Current System","penetration-basics-obtaining-the-list-of-installed-programs-on-the-current-system","Learn how to get a complete list of installed programs using WMI and registry enumeration for penetration testing and system analysis.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I encountered an interesting issue: when trying to use WMI to obtain the list of installed programs on the current system, I couldn't get a complete list. So, I conducted further research, identified the cause of the error, changed my approach, and achieved the goal.\u003C\u002Fp>\u003Cp>This article is an introductory piece on basic knowledge, aimed at solving fundamental problems.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Obtaining the list of installed programs on the current system via WMI\u003C\u002Fli>\u003Cli>Reasons for incomplete WMI query results\u003C\u002Fli>\u003Cli>Implementation ideas for obtaining a complete program list\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtaining the List of Installed Programs on the Current System\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using PowerShell to call WMI\u003C\u002Fh3>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WmiObject -class Win32_Product\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Filter the output results to display only program names, the code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WmiObject -class Win32_Product | Select-Object -Property name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The obtained result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017321882_0_5a151b30ca.jpeg\">\u003C\u002Fp>\u003Ch3>2. Using wmic to call WMI\u003C\u002Fh3>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_Product\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Filter the output results to display only program names, the code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_Product get name \u002FFORMAT:table\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The obtained result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017372873_1_bb27331a72.jpeg\">\u003C\u002Fp>\u003Ch3>3. Using WMI Explorer to call WMI\u003C\u002Fh3>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwmie.codeplex.com\u002Freleases\u002Fview\u002F135794\u003C\u002Fp>\u003Cp>A GUI-based WMI query tool that can be used to query WMI-supported classes, making it a great tool for studying WMI.\u003C\u002Fp>\u003Cp>First, click Connect to connect to the local machine.\u003C\u002Fp>\u003Cp>Select ROOT\\CIMV2 -&gt; Query.\u003C\u002Fp>\u003Cp>Enter the query command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SELECT * FROM Win32_Product\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017394594_2_5b71d58466.jpeg\">\u003C\u002Fp>\u003Ch3>4. Query installed programs via Control Panel\u003C\u002Fh3>\u003Cp>Control Panel -&gt; Programs -&gt; Programs and Features\u003C\u002Fp>\u003Cp>It is found that some programs cannot be obtained through WMI queries, such as Google Chrome. The comparison result is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017440161_3_30728576ff.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Reasons for incomplete WMI query results\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Querying Win32_Product via WMI can only retrieve a specific list of programs.\u003C\u002Fp>\u003Cp>These programs share a common characteristic: their installation packages are created by Windows Installer, and the installation process invokes the Windows Installer service for installation.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Microsoft Windows Installer: A component of the Windows operating system, serving as the standard foundation for installing and uninstalling software.\u003C\u002Fp>\u003Cp>Windows Installer Service: Adds, modifies, and removes applications provided as Windows Installer packages.\u003C\u002Fp>\u003Cp>In addition to Microsoft Windows Installer, tools like EasySetup, Setup2Go, Advanced Installer, Qt installer framework, and WinRAR can also be used to create installation packages.\u003C\u002Fp>\u003Cp>Chrome does not invoke the Microsoft Windows Installer component during its installation process, so it cannot be found by querying Win32_Product via WMI.\u003C\u002Fp>\u003Ch2>0x04 Implementation Approach for Obtaining a Complete Program List\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>We know that the program list obtained via Control Panel -&gt; Programs -&gt; Programs and Features is relatively complete. This list corresponds to the registry key:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\u003C\u002Fp>\u003Cp>Each subkey represents a program in the list.\u003C\u002Fp>\u003Cp>Therefore, a complete program list can be obtained by enumerating registry keys.\u003C\u002Fp>\u003Cp>It is worth noting that on 64-bit systems, registry redirection issues can also affect the display of the program list.\u003C\u002Fp>\u003Cp>The 32-bit program list corresponds to the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\u003C\u002Fp>\u003Cp>The 64-bit program list corresponds to the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This issue was previously summarized in the article 'Notes on Redirection Issues When Running 32-bit Programs on 64-bit Systems'.\u003C\u002Fp>\u003Cp>Write a PowerShell script to enumerate the registry and obtain a complete list of programs.\u003C\u002Fp>\u003Cp>Key code:\u003C\u002Fp>\u003Ch3>1. Enumerate subkeys under the specified registry key\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir Registry::HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall -Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017466631_4_1023ebc18b.jpeg\">\u003C\u002Fp>\u003Ch3>2. Query the registry key values of the specified registry key\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>(Get-ItemProperty -Path \"Registry::HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{4F3742E0-700E-431D-BF19-5B27ED98E8F1}\").DisplayName\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017480805_5_ebb557392a.jpeg\">\u003C\u002Fp>\u003Ch3>3. Implement enumeration by adding a foreach loop\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RegPath = \"Registry::HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\"\u003Cbr>$QueryPath = dir $RegPath -Name\u003Cbr>foreach($Name in $QueryPath)\u003Cbr>{\u003Cbr>    (Get-ItemProperty -Path $RegPath$Name).DisplayName\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Add system architecture detection to automatically determine registry redirection\u003C\u002Fh3>\u003Cp>Complete code can be referenced at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Typically, installed programs create shortcuts, so attempting to enumerate shortcut files can also yield a complete program list\u003C\u002Fp>\u003Cp>Get all shortcuts via wmic:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic PATH Win32_ShortcutFile get name \u002FFORMAT:table\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article explains why WMI cannot obtain a complete list of installed programs on the current system, and demonstrates writing a PowerShell script to achieve a complete program list by enumerating registry entries. As an introductory article on basic knowledge, it aims to provide inspiration for newcomers.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I encountered an interesting issue: when trying to use WMI to obtain the list of installed programs on the current system, I couldn't get a complete list. So, I conducted further research, identified the cause of the error, changed my approach, and achieved the goal.\u003C\u002Fp>\u003Cp>This article is an introductory piece on basic knowledge, aimed at solving fundamental problems.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Obtaining the list of installed programs on the current system via WMI\u003C\u002Fli>\u003Cli>Reasons for incomplete WMI query results\u003C\u002Fli>\u003Cli>Implementation ideas for obtaining a complete program list\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtaining the List of Installed Programs on the Current System\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using PowerShell to call WMI\u003C\u002Fh3>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WmiObject -class Win32_Product\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Filter the output results to display only program names, the code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WmiObject -class Win32_Product | Select-Object -Property name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The obtained result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017321882_0_5a151b30ca-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Using wmic to call WMI\u003C\u002Fh3>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_Product\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Filter the output results to display only program names, the code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_Product get name \u002FFORMAT:table\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The obtained result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017372873_1_bb27331a72-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Using WMI Explorer to call WMI\u003C\u002Fh3>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwmie.codeplex.com\u002Freleases\u002Fview\u002F135794\u003C\u002Fp>\u003Cp>A GUI-based WMI query tool that can be used to query WMI-supported classes, making it a great tool for studying WMI.\u003C\u002Fp>\u003Cp>First, click Connect to connect to the local machine.\u003C\u002Fp>\u003Cp>Select ROOT\\CIMV2 -&gt; Query.\u003C\u002Fp>\u003Cp>Enter the query command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SELECT * FROM Win32_Product\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017394594_2_5b71d58466-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Query installed programs via Control Panel\u003C\u002Fh3>\u003Cp>Control Panel -&gt; Programs -&gt; Programs and Features\u003C\u002Fp>\u003Cp>It is found that some programs cannot be obtained through WMI queries, such as Google Chrome. The comparison result is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017440161_3_30728576ff-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Reasons for incomplete WMI query results\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Querying Win32_Product via WMI can only retrieve a specific list of programs.\u003C\u002Fp>\u003Cp>These programs share a common characteristic: their installation packages are created by Windows Installer, and the installation process invokes the Windows Installer service for installation.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Microsoft Windows Installer: A component of the Windows operating system, serving as the standard foundation for installing and uninstalling software.\u003C\u002Fp>\u003Cp>Windows Installer Service: Adds, modifies, and removes applications provided as Windows Installer packages.\u003C\u002Fp>\u003Cp>In addition to Microsoft Windows Installer, tools like EasySetup, Setup2Go, Advanced Installer, Qt installer framework, and WinRAR can also be used to create installation packages.\u003C\u002Fp>\u003Cp>Chrome does not invoke the Microsoft Windows Installer component during its installation process, so it cannot be found by querying Win32_Product via WMI.\u003C\u002Fp>\u003Ch2>0x04 Implementation Approach for Obtaining a Complete Program List\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>We know that the program list obtained via Control Panel -&gt; Programs -&gt; Programs and Features is relatively complete. This list corresponds to the registry key:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\u003C\u002Fp>\u003Cp>Each subkey represents a program in the list.\u003C\u002Fp>\u003Cp>Therefore, a complete program list can be obtained by enumerating registry keys.\u003C\u002Fp>\u003Cp>It is worth noting that on 64-bit systems, registry redirection issues can also affect the display of the program list.\u003C\u002Fp>\u003Cp>The 32-bit program list corresponds to the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\u003C\u002Fp>\u003Cp>The 64-bit program list corresponds to the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This issue was previously summarized in the article 'Notes on Redirection Issues When Running 32-bit Programs on 64-bit Systems'.\u003C\u002Fp>\u003Cp>Write a PowerShell script to enumerate the registry and obtain a complete list of programs.\u003C\u002Fp>\u003Cp>Key code:\u003C\u002Fp>\u003Ch3>1. Enumerate subkeys under the specified registry key\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir Registry::HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall -Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017466631_4_1023ebc18b-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Query the registry key values of the specified registry key\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>(Get-ItemProperty -Path \"Registry::HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{4F3742E0-700E-431D-BF19-5B27ED98E8F1}\").DisplayName\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017480805_5_ebb557392a-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Implement enumeration by adding a foreach loop\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RegPath = \"Registry::HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\"\u003Cbr>$QueryPath = dir $RegPath -Name\u003Cbr>foreach($Name in $QueryPath)\u003Cbr>{\u003Cbr>    (Get-ItemProperty -Path $RegPath$Name).DisplayName\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Add system architecture detection to automatically determine registry redirection\u003C\u002Fh3>\u003Cp>Complete code can be referenced at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Typically, installed programs create shortcuts, so attempting to enumerate shortcut files can also yield a complete program list\u003C\u002Fp>\u003Cp>Get all shortcuts via wmic:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic PATH Win32_ShortcutFile get name \u002FFORMAT:table\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article explains why WMI cannot obtain a complete list of installed programs on the current system, and demonstrates writing a PowerShell script to achieve a complete program list by enumerating registry entries. As an introductory article on basic knowledge, it aims to provide inspiration for newcomers.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",834,"Onedaysec",4,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Penetration Basics: Get Installed Programs List via WMI & Registry","WMI, installed programs, penetration testing, PowerShell, registry, Win32_Product, system enumeration",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],661,660,658,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.028Z","2026-07-23T16:01:56.044Z","draft","2026-07-23T16:14:02.571Z"]