Files
Assetmanager/docs/analyzer-profiles

AssetManager Analyzer Profiles

AssetManager 0.5.5.90 separates installer-specific knowledge from the analyzer engine. The Python engine performs generic operations such as PE inspection, MSI metadata parsing, marker scanning, safe SFX extraction, embedded-installer selection and profile evaluation. Product/vendor knowledge is stored in declarative JSON profiles.

Profile types

Profiles use schema assetmanager-analyzer-profile-v1 and profile API 1. They can be installed from three sources:

  • system: shipped with AssetManager under app/analyzer_profiles/system/.
  • community: imported manually or installed from a configured community repository.
  • local: locally maintained profiles. Local profiles override profiles with the same ID.

Imported profiles are stored in /assetmanager-data/analyzer-profiles and are included in AssetManager backups. Profiles are declarative data only and cannot contain executable Python code.

Exchange format

Profiles are exported as .amprofile files. The file is a ZIP container with:

  • manifest.json: bundle schema, profile ID/version/API and SHA-256 of profile.json.
  • profile.json: the validated declarative profile definition.

The import validates paths, size, profile schema/API and SHA-256 before installing the profile.

Community repository index

A repository is an HTTPS-hosted JSON index. Configure it with:

ANALYZER_PROFILE_REPOSITORY_URL=https://example.org/assetmanager-profiles/index.json

Index format:

{
  "schema": "assetmanager-analyzer-profile-repository-v1",
  "name": "AssetManager Community Profiles",
  "profiles": [
    {
      "id": "vendor.example-app",
      "name": "Example App",
      "version": "1.0.0",
      "url": "https://example.org/profiles/vendor.example-app.amprofile",
      "sha256": "<sha256 of the amprofile file>"
    }
  ]
}

The AssetManager administrator explicitly loads the catalog and chooses which profile to install. The bundle SHA-256 is verified when the repository provides one.

Contributing profiles

A public profile repository can be maintained independently from the AssetManager application repository. Contributors only need to submit declarative .amprofile bundles and index metadata; no AssetManager source-code change is required for ordinary vendor/installer rules.

Use stable profile IDs. Increase the profile version when rules change. Avoid filename-only matching when stronger static evidence is available. Silent parameters should only be marked high-confidence when they are documented or clearly proven by installer metadata/static analysis.