Attack Surface Analyzer
A Microsoft tool that records how installing software changes an operating system's security configuration.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About Attack Surface Analyzer
Attack Surface Analyzer helps you see what a piece of software changes on a system when it is installed. You take a snapshot of the system's security configuration before installation and another afterwards, and the tool compares the two so new services, settings and other changes stand out.
It is a command-line program published as open source by Microsoft on GitHub. It suits developers checking what their own installers do, and administrators or security reviewers vetting third-party software before rolling it out.
Strengths
- Compares before-and-after snapshots of system security settings
- Useful for reviewing what an installer really changes
- Published openly by Microsoft
Limitations
- Command-line workflow with snapshot steps to manage
- Release activity is not shown in the research
Details
- Pricing
- FreeFree and open source from Microsoft.
- License
- MIT
- Developer
- Microsoft
- Platforms
- Command line
- How it runs
- Downloadable app
- Account
- Not required
- Works offline
- Yes
- Best suited for
- Developers and reviewers checking what software installation changes on a system
- Categories
- Security tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Similar software
Related functionality, not necessarily a direct replacement.
Autoruns
A Sysinternals utility that shows every program and driver configured to start automatically on Windows.
Sandboxie-Plus
Runs a Windows program inside an isolated box, so whatever it writes to disk or the registry disappears afterwards.
Belarc Advisor
A Windows system profiler that lists installed hardware, software, missing updates and security status.
Sysmon
A Sysinternals service that logs detailed process, network and file activity to the Windows event log.