Ross ROSS = Recommend OSS · open-source software intelligence for agents

microsoft/AttackSurfaceAnalyzer

Attack Surface Analyzer can help you analyze your operating system's security configuration for changes during software installation. observed · 2026-08-28

github.com/microsoft/AttackSurfaceAnalyzer · C# · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

82/100

  • Activity 95
  • Release rhythm 55
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 88
  • age_days: 2757
  • days_rel: 222
  • days_push: 32
  • n_releases_24m: 6

Full methodology

Adoption not part of the score

2950 stars · 294 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Attack Surface Analyzer is a Microsoft open-source security tool that scans an operating system's security configuration before and after software installation and diffs the results. It surfaces potential vulnerabilities and misconfigurations introduced by installers or system changes, with a CLI and a Blazor GUI.

Use cases

  • analyze attack surface changes after installing software
  • audit security configuration changes on windows
  • diff system state before and after an installer runs
  • evaluate risk of third-party software installation
  • find security misconfigurations introduced by elevated installs
  • scan os security posture for it audit

When to choose

  • you need to compare system security configuration before and after software installation
  • you are a DevOps engineer validating what your installer changes
  • you are a security auditor assessing third-party software risk

When to avoid

  • you need continuous runtime intrusion detection rather than before/after diffing
  • you need network-wide scanning rather than single-host analysis
  • you need a lightweight agentless scanner on systems without .NET

Facets

cli-tool · maturity active

security vulnerability-scanning monitoring security operating-systems windows cross-platform cli dotnet attack-surface security-audit diff-analysis system-hardening microsoft devops linux macos

1 source

Member repositories

RepositoryRoleHealth v2
microsoft/AttackSurfaceAnalyzermain82

For agents

markdown · JSON · MCP: product_card(name="microsoft/AttackSurfaceAnalyzer")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem