3.8 KiB
Executable File
Setup Analyzer
The Setup Analyzer prepares Windows installation files for silent deployment without executing the uploaded installer on the AssetManager server.
Supported package types
- MSI and MSP
- MSIX and AppX
- MSU
- Inno Setup
- NSIS
- WiX Burn
- InstallShield
- Advanced Installer
- Squirrel
- common 7-Zip and WinRAR SFX wrappers
- unknown EXE fallback
Analysis output
- SHA256
- installer technology and confidence
- PE product/version/manufacturer/architecture metadata when available
- presence of Authenticode signature data for PE files
- detected installer marker strings
- detected switch-like strings
- recommended silent arguments and command
- success and reboot exit-code suggestions
- detection and uninstall suggestions
Exports and AssetManager packages
The PowerShell export creates an install.ps1 wrapper. The deployment-package export contains the original installer plus install.ps1, uninstall.ps1, detect.ps1, package.json, and analysis.json.
Version 0.5.5.77 can also create a persistent AssetManager software package directly from the analyzer result. Package files are stored in data/software-packages/ and the package appears under Software and Jobs → Software packages. From there administrators can create install, uninstall, and reinstall jobs for one or more compatible Windows assets.
Software-package jobs transfer only the files required for the selected action through MeshCentral, run the generated PowerShell wrapper, and use the normal AssetManager callback/status/retry infrastructure.
Post-install application start
A package can optionally start an application after a successful install or reinstall. The launch happens only after the package detection rule confirms that the software is installed. Because deployment jobs execute as SYSTEM, AssetManager uses the active interactive Windows session and the logged-on user's session token to create the configured application there.
If no interactive user session is active and Start only when an interactive user is logged on is enabled, the application start is skipped without failing the installation job. Application launch is also skipped when the installer reports that a reboot is required.
For known packages, Setup Analyzer can prefill the application path. Greenshot uses C:\Program Files\Greenshot\Greenshot.exe.
Installer process handling
Generated installation scripts no longer use Start-Process -Wait for the installer. They start the installer process, wait only for that specific PID with a configurable timeout, and then evaluate its exit code. This prevents a browser or another long-running child process launched by the installer from keeping the PowerShell script open indefinitely.
The optional Suppress post-install browser launch setting terminates only browser processes that were newly created inside the installer process tree. Existing browser sessions are not touched. The option is preselected for Greenshot detections because Greenshot installers can open a completion web page after setup.
Security
The uploaded installer is stored in a temporary directory and is not executed. Access is restricted to administrators. Old temporary analyses are removed after the configured retention period.
Environment variables:
SETUP_ANALYZER_TMP_DIR=/tmp/assetmanager-setup-analyzer
SETUP_ANALYZER_MAX_UPLOAD_MB=4096
SETUP_ANALYZER_RETENTION_HOURS=24
SOFTWARE_PACKAGE_DIR=/app/data/software-packages
MSI metadata
Standard MSI silent-command generation works without additional system packages. Detailed MSI properties such as ProductCode and UpgradeCode are additionally read when the optional msiinfo utility is present in the container.
Important
Installer technology detection and a suggested command do not guarantee vendor-specific compatibility. Test generated commands on a designated test asset before broad deployment.