Files

7.7 KiB
Executable File

Setup Analyzer

The Setup Analyzer prepares Windows installation files for silent deployment without executing the uploaded installer on the AssetManager server.

Supported package types

  • MSI and MSP
  • MSIX and AppX
  • MSU
  • Inno Setup
  • NSIS
  • WiX Burn
  • InstallShield
  • Advanced Installer
  • Squirrel
  • ZIP-compatible, 7-Zip and WinRAR/RAR SFX wrappers
  • vendor profiles for Total Commander SFX and the PDF24 Creator online bootstrapper
  • unknown EXE fallback

Analysis output

  • SHA256
  • installer technology and confidence
  • PE product/version/manufacturer/architecture metadata when available
  • presence of Authenticode signature data for PE files
  • detected installer marker strings
  • detected switch-like strings
  • recommended silent arguments and command
  • success and reboot exit-code suggestions
  • detection and uninstall suggestions

Exports and AssetManager packages

The PowerShell export creates an install.ps1 wrapper. The deployment-package export contains the original installer plus install.ps1, uninstall.ps1, detect.ps1, package.json, and analysis.json.

Version 0.5.5.77 can also create a persistent AssetManager software package directly from the analyzer result. Package files are stored in data/software-packages/ and the package appears under Software and Jobs → Software packages. From there administrators can create install, uninstall, and reinstall jobs for one or more compatible Windows assets.

Software-package jobs transfer only the files required for the selected action through MeshCentral, run the generated PowerShell wrapper, and use the normal AssetManager callback/status/retry infrastructure.

Post-install application start

A package can optionally start an application after a successful install or reinstall. The launch happens only after the package detection rule confirms that the software is installed. Because deployment jobs execute as SYSTEM, AssetManager uses the active interactive Windows session and the logged-on user's session token to create the configured application there.

If no interactive user session is active and Start only when an interactive user is logged on is enabled, the application start is skipped without failing the installation job. Application launch is also skipped when the installer reports that a reboot is required.

For known packages, Setup Analyzer can prefill the application path. Greenshot uses C:\Program Files\Greenshot\Greenshot.exe.

Installer process handling

Generated installation scripts no longer use Start-Process -Wait for the installer. They start the installer process, wait only for that specific PID with a configurable timeout, and then evaluate its exit code. This prevents a browser or another long-running child process launched by the installer from keeping the PowerShell script open indefinitely.

The optional Suppress post-install browser launch setting terminates only browser processes that were newly created inside the installer process tree. Existing browser sessions are not touched. The option is preselected for Greenshot detections because Greenshot installers can open a completion web page after setup.

SFX and embedded installers

Version 0.5.5.89 adds recursive static analysis of supported self-extracting installer containers. AssetManager never executes the uploaded SFX on the server. It first identifies the outer wrapper and then attempts to list and extract the payload with safe path, file-count, expanded-size and recursion limits.

Supported extraction paths include ZIP-compatible self-extracting files, 7-Zip SFX containers through the 7-Zip command-line tool, and WinRAR/RAR SFX containers through unar / lsar with 7-Zip as an additional fallback where supported by the installed build.

After extraction, embedded MSI/MSP/MSIX/AppX/MSU and EXE installer candidates are analyzed with the same static technology detector. Nested SFX candidates can be opened recursively up to the configured depth. Candidate selection is heuristic: known installer technologies, setup-like filenames and usable product metadata increase the score, while uninstallers and common prerequisite redistributables are strongly penalized. The selected candidate and alternatives are shown in the UI.

When an embedded installer is selected, package creation preserves the complete extracted payload rather than copying only the selected installer. AssetManager stores that payload in an internal ZIP, transfers it as one package file, expands it on the Windows target, and runs the selected embedded installer from its original relative directory. This preserves adjacent CAB files and subdirectories needed by many vendor packages.

The SFX feature still cannot guarantee that the heuristically selected inner installer is the vendor-supported deployment entry point. Always test the generated package on a designated test asset.

Security

The uploaded installer is stored in a temporary directory and is not executed. Access is restricted to administrators. Old temporary analyses are removed after the configured retention period.

Environment variables:

SETUP_ANALYZER_TMP_DIR=/tmp/assetmanager-setup-analyzer
SETUP_ANALYZER_MAX_UPLOAD_MB=4096
SETUP_ANALYZER_RETENTION_HOURS=24
SETUP_ANALYZER_MAX_EXTRACTED_MB=8192
SETUP_ANALYZER_MAX_EXTRACTED_FILES=20000
SETUP_ANALYZER_MAX_SFX_DEPTH=2
SOFTWARE_PACKAGE_DIR=/assetmanager-data/software-packages

MSI metadata

Standard MSI silent-command generation works without additional system packages. Detailed MSI properties such as ProductCode and UpgradeCode are additionally read when the optional msiinfo utility is present in the container.

Important

Installer technology detection and a suggested command do not guarantee vendor-specific compatibility. Test generated commands on a designated test asset before broad deployment.

Vendor bootstrapper notes

Total Commander SFX installers are detected through their embedded INSTALL.INF. AssetManager uses /AH1 for unattended hidden installation and shows /A1 as the visible automatic alternative.

The small pdf24-creator-installer.exe is treated as an online bootstrapper rather than as the full PDF24 Creator Inno Setup package. It selects an architecture-specific current installer at runtime, so its package version is intentionally left unpinned. The analyzer surfaces /SILENT with medium confidence and recommends using the offline EXE or MSI when deterministic deployment is required.

Analyzer profiles (0.5.5.90)

Vendor- and installer-specific detection knowledge is no longer added to the Python analyzer as product-specific branches. The generic analyzer engine loads declarative profiles from:

  • app/analyzer_profiles/system/ for profiles shipped with AssetManager,
  • /assetmanager-data/analyzer-profiles/community/ for imported/community profiles,
  • /assetmanager-data/analyzer-profiles/local/ for locally maintained overrides.

Profiles can contribute static markers, match rules, installer metadata extraction, architecture rules, silent parameters, process-control defaults and post-install defaults. Community and local profiles can override a system profile by using the same stable profile ID. The profile manager is available under Software -> Setup Analyzer -> Analyzer profiles.

Profiles are exchanged as .amprofile bundles and contain declarative JSON only. They cannot execute Python code. A separately hosted HTTPS repository can provide a catalog of .amprofile bundles through ANALYZER_PROFILE_REPOSITORY_URL; administrators explicitly choose profiles to install.

Software packages can be exported as .ampkg and re-imported. If the package was created from an analyzer profile, the export can embed that .amprofile; the importing administrator may explicitly choose whether to install the embedded profile as a Community profile.