2.6 KiB
Executable File
AssetManager Analyzer Profiles
AssetManager 0.5.5.90 separates installer-specific knowledge from the analyzer engine. The Python engine performs generic operations such as PE inspection, MSI metadata parsing, marker scanning, safe SFX extraction, embedded-installer selection and profile evaluation. Product/vendor knowledge is stored in declarative JSON profiles.
Profile types
Profiles use schema assetmanager-analyzer-profile-v1 and profile API 1.
They can be installed from three sources:
system: shipped with AssetManager underapp/analyzer_profiles/system/.community: imported manually or installed from a configured community repository.local: locally maintained profiles. Local profiles override profiles with the same ID.
Imported profiles are stored in /assetmanager-data/analyzer-profiles and are included in AssetManager backups.
Profiles are declarative data only and cannot contain executable Python code.
Exchange format
Profiles are exported as .amprofile files. The file is a ZIP container with:
manifest.json: bundle schema, profile ID/version/API and SHA-256 ofprofile.json.profile.json: the validated declarative profile definition.
The import validates paths, size, profile schema/API and SHA-256 before installing the profile.
Community repository index
A repository is an HTTPS-hosted JSON index. Configure it with:
ANALYZER_PROFILE_REPOSITORY_URL=https://example.org/assetmanager-profiles/index.json
Index format:
{
"schema": "assetmanager-analyzer-profile-repository-v1",
"name": "AssetManager Community Profiles",
"profiles": [
{
"id": "vendor.example-app",
"name": "Example App",
"version": "1.0.0",
"url": "https://example.org/profiles/vendor.example-app.amprofile",
"sha256": "<sha256 of the amprofile file>"
}
]
}
The AssetManager administrator explicitly loads the catalog and chooses which profile to install. The bundle SHA-256 is verified when the repository provides one.
Contributing profiles
A public profile repository can be maintained independently from the AssetManager application
repository. Contributors only need to submit declarative .amprofile bundles and index metadata;
no AssetManager source-code change is required for ordinary vendor/installer rules.
Use stable profile IDs. Increase the profile version when rules change. Avoid filename-only matching when stronger static evidence is available. Silent parameters should only be marked high-confidence when they are documented or clearly proven by installer metadata/static analysis.