diff --git a/BUILDING.txt b/BUILDING.txt
index 68a7e43249..69a3dfd988 100644
--- a/BUILDING.txt
+++ b/BUILDING.txt
@@ -1,3 +1,5 @@
+ Last Updated: June 12, 2012
+
This file outlines what it takes to build Autopsy from source.
Note that it currently only works out of the box on Windows. We
@@ -5,33 +7,49 @@ are working on getting the process working under non-WIndows systems.
It generally works, but needs some custom mangling to find the
correct C libraries.
+
STEPS:
-1) Download and install 32-bit version of JDK (32-bit is currently
+1) Get Java Setup
+1a) Download and install 32-bit version of JDK (32-bit is currently
needed even if you have a 64-bit system).
-2) Ensure that JDK_HOME is set to the root JDK directory.
+1b) Ensure that JDK_HOME is set to the root JDK directory.
-3) Download and install Netbeans IDE 7.0.1 (http://netbeans.org/)
+1c) Download and install Netbeans IDE 7.0.1 (http://netbeans.org/)
-4) Download and build the release version of Libewf2 (20120304 or later). All you need is the dll file. Note that you will get a launching error if you use libewf 1.
+
+2) Get Sleuth Kit Setup
+2a) Download and build the release version of Libewf2 (20120304 or later). All you need is the dll file. Note that you will get a launching error if you use libewf 1.
- http://sourceforge.net/projects/libewf/
-5) Set LIBEWF_HOME environment variable to root directory of LIBEWF
+2b) Set LIBEWF_HOME environment variable to root directory of LIBEWF
-6) Download and build release version of Sleuth Kit (TSK) 3.3. You
+2c) Download and build release version of Sleuth Kit (TSK) 4.0. You
need to build the tsk_jni project.
-- At the time of this writing, 3.3 is not released. You can get it from either
+- At the time of this writing, 4.0 is not released. You can get it from either
-- GIT: git://github.com/sleuthkit/sleuthkit.git
-- SVN: http://svn.github.com/sleuthkit/sleuthkit.git
-7) Build the TSK JAR file by typing 'ant' in bindings/java from a
+2d) Build the TSK JAR file by typing 'ant' in bindings/java from a
command line or by opening the project in NetBeans.
-8) Set TSK_HOME environment variable to the root directory of TSK
+2e) Set TSK_HOME environment variable to the root directory of TSK
-9) Start NetBean IDE and open the Autopsy project.
-10) Choose to build the Autopsy project / module. It is the highest
+3) Get gstreamer Setup
+
+If Autopsy installer is not used, add the following entries to Windows PATH environment variable
+(replace GSTREAMER_INSTALL_DIR with the location of the gstreamer root directory):
+ GSTREAMER_INSTALL_DIR\bin\;
+ GSTREAMER_INSTALL_DIR\lib\gstreamer-0.10\;
+If you don't have gstreamer already, you can find a zipped gstreamer distribution in
+ AUTOPSYROOT/thirdparty/gstreamer
+
+
+4) Compile Autopsy
+4a) Start NetBean IDE and open the Autopsy project.
+
+4b) Choose to build the Autopsy project / module. It is the highest
level project that will then cause the other modules to be compiled.
@@ -55,5 +73,4 @@ rebuild both the dll and the JAR file.
---------------
Brian Carrier
-4/6/2012
carrier Note that Autopsy will store the path to the image in its configuration file. If the image moves, then Autopsy will give an error because it can't find the image file.
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashDbMgmt.html b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashDbMgmt.html
index 1a98b75d10..a2a81abef9 100644
--- a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashDbMgmt.html
+++ b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashDbMgmt.html
@@ -16,16 +16,16 @@
Autopsy allows for a single known bad hash database to be set. Future versions will support multiple hash sets. Autopsy supports three formats:
+ Autopsy allows for multiple known bad hash databases to be set. Autopsy supports three formats:
Autopsy can use the NIST NSRL to detect 'known files'. Note that the NSRL contains hashes of 'known files' that may be good or bad depending on your perspective and investigation type. For example, the existence of a piece of financial software
- may be interesting to your investigation and that software could be in the NSRL. Therefore, Autopsy treats files that are found in the NSRL as simplyi 'known' and does not specify good or bad. Ingest modules have the option of ignoring files that were found in the NSRL.
Notable / Known Bad Hashsets
-
NIST NSRL
To use the NSRL, you must concatenate all of the NSRLFile.txt files together. You can use 'cat' on a Unix system or from within Cygwin to do this.
@@ -43,5 +43,6 @@You can also see the results in the File Search window. There is an option to choose the 'known status'. From here, you can do a search to see all 'known bad' files. From here, you can also choose to ignore all 'known' files that were found in the NSRL. You can also see the status of the file in a column when the file is listed.
+