It has been a long time since Microsoft came out with this nifty little tool that could help you find what has changed on a system. It allows you to take snapshots and compare them before and after taking the snapshot. The basic functionality of the System State Analyzer tool is to allow you to compare two snapshots taken at different points in time. This allows you to compare the state of a machine both before and after an application install or probably you could use it in your VM as a first step in malware analysis or reverse engineering.
A typical screen of the Windows System State Analyzer:
As you can see, the interface is divided into two panes, each of which is for a separate snapshot that you wish to compare. An amazing feature about this tool is that you can choose what you wish to include in the snapshot for comparison. You can compare drives, registry keys, services or drivers. This is how it looks:
It allows you store detailed reports in simple .html files too! The Detailed Report displays the change summary and details filtered based on file extension and various other file properties. This is how a sample report looks like:

This tool is a part of the Windows 2008 R2 Logo Software Certification and Windows 2008 R2 Logo Program Software Certification toolkits. Hence you will need to download the toolkits to get the System State Analyzer tool.
Download the Server Logo Program Software Certification Tool (x86): here and (x64): here
You must have the .NET Framework 2.0 installed for Windows System State Analyzer to work correctly.
Searches leading to this post:
WINDOWS SYSTEM STATE ANALYZER
系统状态分析器是一款由微软推出的实用工具,它可以帮助用户通过对比不同时间点的系统快照来发现系统的变化。此工具适用于应用安装前后的系统状态比较,也可用于虚拟机中的恶意软件分析或逆向工程。

被折叠的 条评论
为什么被折叠?



