65 lines
2.6 KiB
Markdown
Executable File
65 lines
2.6 KiB
Markdown
Executable File
# AssetManager Analyzer Profiles
|
|
|
|
AssetManager 0.5.5.90 separates installer-specific knowledge from the analyzer engine.
|
|
The Python engine performs generic operations such as PE inspection, MSI metadata parsing,
|
|
marker scanning, safe SFX extraction, embedded-installer selection and profile evaluation.
|
|
Product/vendor knowledge is stored in declarative JSON profiles.
|
|
|
|
## Profile types
|
|
|
|
Profiles use schema `assetmanager-analyzer-profile-v1` and profile API `1`.
|
|
They can be installed from three sources:
|
|
|
|
- `system`: shipped with AssetManager under `app/analyzer_profiles/system/`.
|
|
- `community`: imported manually or installed from a configured community repository.
|
|
- `local`: locally maintained profiles. Local profiles override profiles with the same ID.
|
|
|
|
Imported profiles are stored in `/assetmanager-data/analyzer-profiles` and are included in AssetManager backups.
|
|
Profiles are declarative data only and cannot contain executable Python code.
|
|
|
|
## Exchange format
|
|
|
|
Profiles are exported as `.amprofile` files. The file is a ZIP container with:
|
|
|
|
- `manifest.json`: bundle schema, profile ID/version/API and SHA-256 of `profile.json`.
|
|
- `profile.json`: the validated declarative profile definition.
|
|
|
|
The import validates paths, size, profile schema/API and SHA-256 before installing the profile.
|
|
|
|
## Community repository index
|
|
|
|
A repository is an HTTPS-hosted JSON index. Configure it with:
|
|
|
|
`ANALYZER_PROFILE_REPOSITORY_URL=https://example.org/assetmanager-profiles/index.json`
|
|
|
|
Index format:
|
|
|
|
```json
|
|
{
|
|
"schema": "assetmanager-analyzer-profile-repository-v1",
|
|
"name": "AssetManager Community Profiles",
|
|
"profiles": [
|
|
{
|
|
"id": "vendor.example-app",
|
|
"name": "Example App",
|
|
"version": "1.0.0",
|
|
"url": "https://example.org/profiles/vendor.example-app.amprofile",
|
|
"sha256": "<sha256 of the amprofile file>"
|
|
}
|
|
]
|
|
}
|
|
```
|
|
|
|
The AssetManager administrator explicitly loads the catalog and chooses which profile to install.
|
|
The bundle SHA-256 is verified when the repository provides one.
|
|
|
|
## Contributing profiles
|
|
|
|
A public profile repository can be maintained independently from the AssetManager application
|
|
repository. Contributors only need to submit declarative `.amprofile` bundles and index metadata;
|
|
no AssetManager source-code change is required for ordinary vendor/installer rules.
|
|
|
|
Use stable profile IDs. Increase the profile version when rules change. Avoid filename-only matching
|
|
when stronger static evidence is available. Silent parameters should only be marked high-confidence
|
|
when they are documented or clearly proven by installer metadata/static analysis.
|