The Windows System State Analyzer!

系统状态分析器是一款由微软推出的实用工具,它可以帮助用户通过对比不同时间点的系统快照来发现系统的变化。此工具适用于应用安装前后的系统状态比较,也可用于虚拟机中的恶意软件分析或逆向工程。

It has been a long time since Microsoft came out with this nifty little tool that could help you find what has changed on a system. It allows you to take snapshots and compare them before and after taking the snapshot. The basic functionality of the System State Analyzer tool is to allow you to compare two snapshots taken at different points in time. This allows you to compare the state of a machine both before and after an application install or probably you could use it in your VM as a first step in malware analysis or reverse engineering.

A typical screen of the Windows System State Analyzer:

System State AnalyzerAs you can see, the interface is divided into two panes, each of which is for a separate snapshot that you wish to compare. An amazing feature about this tool is that you can choose what you wish to include in the snapshot for comparison. You can compare drives, registry keys, services or drivers. This is how it looks:

System State analyzerIt allows you store detailed reports in simple .html files too! The Detailed Report displays the change summary and details filtered based on file extension and various other file properties. This is how a sample report looks like:

System State Analyzer-2
This tool is a part of the Windows 2008 R2 Logo Software Certification and Windows 2008 R2 Logo Program Software Certification toolkits. Hence you will need to download the toolkits to get the System State Analyzer tool.

Download the Server Logo Program Software Certification Tool (x86): here and (x64): here

You must have the .NET Framework 2.0 installed for Windows System State Analyzer to work correctly.

Searches leading to this post:
WINDOWS SYSTEM STATE ANALYZER

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值