Registry-Based Version Detection vs actual File Version - How are you handling the drift?

We are expereincing a recurring pattern in the environment where Rapid7 InsightVM flags vulnerabilities based on registry keys (specifically HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall and WOW6432Node equivalents) while the actual application files on disk are already at a patched/removed version.

How is your organisation handling registry-vs-file-version mismatches at scale? Have you found a way to bulk-submit false positive evidence without investigating every single asset individually?

3 Likes