From 3dfc397f6a6c079462c844b963ebdff7794b7e74 Mon Sep 17 00:00:00 2001 From: apriestman Date: Tue, 7 Sep 2021 13:54:51 -0400 Subject: [PATCH 01/10] Add custom MIME type to look for VHD signature in footer --- .../modules/filetypeid/CustomFileTypesManager.java | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/Core/src/org/sleuthkit/autopsy/modules/filetypeid/CustomFileTypesManager.java b/Core/src/org/sleuthkit/autopsy/modules/filetypeid/CustomFileTypesManager.java index 7175b3f023..57ce4c51b3 100644 --- a/Core/src/org/sleuthkit/autopsy/modules/filetypeid/CustomFileTypesManager.java +++ b/Core/src/org/sleuthkit/autopsy/modules/filetypeid/CustomFileTypesManager.java @@ -336,6 +336,14 @@ final class CustomFileTypesManager { signatureList.add(new Signature(byteArray, 8L)); fileType = new FileType("application/x.android-hdb", signatureList); autopsyDefinedFileTypes.add(fileType); + + /** + * Add custom type for fixed-size VHDs. + */ + signatureList.clear(); + signatureList.add(new Signature("conectix", 511L, false)); //NON-NLS + fileType = new FileType("application/x-vhd", signatureList); //NON-NLS + autopsyDefinedFileTypes.add(fileType); } catch (IllegalArgumentException ex) { /* From 8117d5482c4415e05811213db218a2d0c45de0d7 Mon Sep 17 00:00:00 2001 From: Eugene Livis Date: Wed, 8 Sep 2021 11:16:08 -0400 Subject: [PATCH 02/10] Bug fix for previously seen --- .../centralrepository/eventlisteners/IngestEventsListener.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Core/src/org/sleuthkit/autopsy/centralrepository/eventlisteners/IngestEventsListener.java b/Core/src/org/sleuthkit/autopsy/centralrepository/eventlisteners/IngestEventsListener.java index 09c02d52fe..1dad86dd90 100644 --- a/Core/src/org/sleuthkit/autopsy/centralrepository/eventlisteners/IngestEventsListener.java +++ b/Core/src/org/sleuthkit/autopsy/centralrepository/eventlisteners/IngestEventsListener.java @@ -656,7 +656,7 @@ public class IngestEventsListener { } // flag previously seen devices and communication accounts (emails, phones, etc) - if (flagPreviousItemsEnabled + if (flagPreviousItemsEnabled && !previousOccurrences.isEmpty() && (eamArtifact.getCorrelationType().getId() == CorrelationAttributeInstance.USBID_TYPE_ID || eamArtifact.getCorrelationType().getId() == CorrelationAttributeInstance.ICCID_TYPE_ID || eamArtifact.getCorrelationType().getId() == CorrelationAttributeInstance.IMEI_TYPE_ID From 99d8b420f52b92d7d6c8c2b6c5803c55cbd00744 Mon Sep 17 00:00:00 2001 From: apriestman Date: Wed, 8 Sep 2021 12:13:02 -0400 Subject: [PATCH 03/10] New artifact icons --- .../autopsy/datamodel/utils/IconsUtil.java | 7 +++++++ .../sleuthkit/autopsy/images/previously-seen.png | Bin 0 -> 1107 bytes .../autopsy/images/previously-unseen.png | Bin 0 -> 1168 bytes .../autopsy/report/modules/html/HTMLReport.java | 10 ++++++++++ 4 files changed, 17 insertions(+) create mode 100644 Core/src/org/sleuthkit/autopsy/images/previously-seen.png create mode 100644 Core/src/org/sleuthkit/autopsy/images/previously-unseen.png diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/utils/IconsUtil.java b/Core/src/org/sleuthkit/autopsy/datamodel/utils/IconsUtil.java index de88e41e04..69190cd175 100755 --- a/Core/src/org/sleuthkit/autopsy/datamodel/utils/IconsUtil.java +++ b/Core/src/org/sleuthkit/autopsy/datamodel/utils/IconsUtil.java @@ -127,6 +127,13 @@ public final class IconsUtil { imageFile = "gps-area.png"; //NON-NLS } else if (typeID == ARTIFACT_TYPE.TSK_YARA_HIT.getTypeID()) { imageFile = "yara_16.png"; //NON-NLS + } else if (typeID == ARTIFACT_TYPE.TSK_PREVIOUSLY_SEEN.getTypeID()) { + imageFile = "previously-seen.png"; //NON-NLS + } else if (typeID == ARTIFACT_TYPE.TSK_PREVIOUSLY_UNSEEN.getTypeID()) { + imageFile = "previously-unseen.png"; //NON-NLS + } else if (typeID == ARTIFACT_TYPE.TSK_PREVIOUSLY_NOTABLE.getTypeID()) { + imageFile = "previously-notable.png"; //NON-NLS + //imageFile = "red-circle-exclamation.png"; //NON-NLS } else { imageFile = "artifact-icon.png"; //NON-NLS } diff --git a/Core/src/org/sleuthkit/autopsy/images/previously-seen.png b/Core/src/org/sleuthkit/autopsy/images/previously-seen.png new file mode 100644 index 0000000000000000000000000000000000000000..ed78158beb6f740de378cdeda36d1fcbc212f6ac GIT binary patch literal 1107 zcmV-Z1g!gsP)EX>4Tx04R}tkv&MmKpe$iQ>7vmp%xKw$WR5rf~bh2RIvyaN?V~-2a`)bgeDD1 zii@M*T5#}VvFhOBtgC~oAP9bdxVbqgx=4xtOA0MwJUH&hyL*qjcYshYGu7-E2UN{6 zQt_CW&8>)mR|L?H5JnM_n5iey3mJHhuY36TdKcwc-sk=tJxbnWfKMczWx8PzuMo3h_Ddm_ZjLe&o9B@*C%(!vfC?8=2G`ahO;vwz1sCtYoOfQ^XNP)hJ)c zx~y>C;;fddta(rV!eCxoPIH~+5aL)w0!fIFQN;$zun?tHBgI6D_G2FYLC2pYmrSk= zFmlYJ0u_?u2mgcL-I|5T2{$Pi13F)9`(qdg>;jFNZGRuzcH;!_KLb}<%U`JjGoPf_ zT3X}?=-mb`u3MVC2VCv|15dhSNRH&EDHIC8`x$*x4(PiDx>w!an)^6?05a6o(hYEM z2#gddd(GqBUG2U7d#2gn50%eywf8XBF#rGn32;bRa{vGf6951U69E94oEQKA00(qQ zO+^Rg2OJL-7V3`x-T(jq8FWQhbVF}#ZDnqB07G(RVRU6=Aa`kWXdp*PO;A^X4i^9b z0z64XK~y-)V_={VFp{fLs#rEfmtDJ=ECb9-EK6Sgd)fWq!@X1{dz{9OFJ3*hHJ7xgV_;)U3RLmW ztVphyMO+xt1P2F;ef|2i@!!9Hao@jx=lb{W9|IE;69XF?+fQCz-c>3p zDz!a5JrB_hU}j)oU@$Z^v|(amI{5SFPf=xM<*uJUf8G`p6nxCh&3){{hYyoDI5@%{ zKYm;-Dk^&L>C>l=kquySadFY$;^Nx*>({Rh`T6;#_wL>E`26{E?yFa?LSDUkmBPcr zleTHoCKEwH!R2ghY`c<@lFU#H`2YX^JOu@X(}xZnO8fBPgV?WMzdVo?eEaszE-Ncb zdCi(Nsek|e-SX_&vxO)IaB^~9eD>^_;*1$HWZBu-Uo$c?{z6f}#KgeE!}EUW(xrmz z?Ckm+92}R>1Ci6o$!Q-yKfl!X@83QD{rl(q?c29WjEs=*RZ&stdjJ0Y{NKNSuVQ9q z=FZN}Hg|V-e*?FGfq~&WJ3G7cj~_oS|M>CaDjy%8r>v~(99CA=BfPx4b3T6jsPXaR z$IA>13@_ileQSiQ86zP@L_|1${rWZQ@87@rU%!4;784VD`s>%P^9l+I^CwQ6xQ>Aq Z006lG-IivAq3Zwu002ovPDHLkV1k^B4@Cd~ literal 0 HcmV?d00001 diff --git a/Core/src/org/sleuthkit/autopsy/images/previously-unseen.png b/Core/src/org/sleuthkit/autopsy/images/previously-unseen.png new file mode 100644 index 0000000000000000000000000000000000000000..c08a1e6f3f36cdcafdd06dbe205aba58afed1a8a GIT binary patch literal 1168 zcmV;B1aJF^P)EX>4Tx04R}tkv&MmKpe$iQ>7vmp%xKw$WR5rf~bh2RIvyaN?V~-2a`)bgeDD1 zii@M*T5#}VvFhOBtgC~oAP9bdxVbqgx=4xtOA0MwJUH&hyL*qjcYshYGu7-E2UN{6 zQt_CW&8>)mR|L?H5JnM_n5iey3mJHhuY36TdKcwc-sk=tJxbnWfKMczWx8PzuMo3h_Ddm_ZjLe&o9B@*C%(!vfC?8=2G`ahO;vwz1sCtYoOfQ^XNP)hJ)c zx~y>C;;fddta(rV!eCxoPIH~+5aL)w0!fIFQN;$zun?tHBgI6D_G2FYLC2pYmrSk= zFmlYJ0u_?u2mgcL-I|5T2{$Pi13F)9`(qdg>;jFNZGRuzcH;!_KLb}<%U`JjGoPf_ zT3X}?=-mb`u3MVC2VCv|15dhSNRH&EDHIC8`x$*x4(PiDx>w!an)^6?05a6o(hYEM z2#gddd(GqBUG2U7d#2gn50%eywf8XBF#rGn32;bRa{vGf6951U69E94oEQKA00(qQ zO+^Rg2OJL<1zZOsf&c&j8FWQhbVF}#ZDnqB07G(RVRU6=Aa`kWXdp*PO;A^X4i^9b z0(nV9K~y-)wb5@#6JZ<&@ZWB`oq0TY?N-{-ExQ^uAqkwyk0rf-t0}^cRzT3 zpXbZ-0OXiQ<$I5W9(Xn^&krwNHux)R-Kt!Hp{j#iUg1Wu=zMFPzpr1redcpu@dvNX z85n_eC7D9wn6`RPN{VpAQbJOPf5&Tb1^@t_RMqZB(b);WRUq)vfz!!oFlS((nk~tj zlg5?+FhuKS7vF!;Yknnauv~%scVAy9xJLc0d{@mT+le}j**LqnZS(l525z@I-{bKd zE+{BCWHOlyJkRqC!+b0*F77RxdP{tI6Pj~;n2rMg%=GqA+{kEs7HDW_IF(E$?_(II zCkP@)5JUt3w#?7ZTNf4<)FesX@p`>CDT-27UWx$#I2?`}iA16wAv9pISgbgXujhIG zj3h}GolbWWA=D-a!WEm%_H1%;l2{3-nwpx9N2AfF2%!r;pRbc;+39pTy?ezO*=n_J z)o3(j!C>$uK@j(bhlks;4dU_mZIj9L+~@Ok_Vn~<*DM17kl}E6r_1FU1%PWRmFl|F z=`6|u2%*Ou$JMvDx9@9iZcZbFgtb3lHk)~tW%EgryozC%-|2Mz%mR&#jkjo;eiaA= z{4Fgl$MkxAD**ff08kVK7>030A`y(DsE{N{YJN7M9_ zD2fwCqp>U&i-i?MVN$8oQ5?s|OG``bU0q$=KfrSAc6+5P%a<~lOr Date: Wed, 8 Sep 2021 14:07:41 -0400 Subject: [PATCH 04/10] Switch icons --- .../autopsy/datamodel/utils/IconsUtil.java | 3 +-- .../autopsy/images/previously-seen.png | Bin 1107 -> 6455 bytes .../autopsy/images/previously-unseen.png | Bin 1168 -> 6633 bytes .../report/modules/html/HTMLReport.java | 3 +-- 4 files changed, 2 insertions(+), 4 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/utils/IconsUtil.java b/Core/src/org/sleuthkit/autopsy/datamodel/utils/IconsUtil.java index 69190cd175..58bf8b26d2 100755 --- a/Core/src/org/sleuthkit/autopsy/datamodel/utils/IconsUtil.java +++ b/Core/src/org/sleuthkit/autopsy/datamodel/utils/IconsUtil.java @@ -132,8 +132,7 @@ public final class IconsUtil { } else if (typeID == ARTIFACT_TYPE.TSK_PREVIOUSLY_UNSEEN.getTypeID()) { imageFile = "previously-unseen.png"; //NON-NLS } else if (typeID == ARTIFACT_TYPE.TSK_PREVIOUSLY_NOTABLE.getTypeID()) { - imageFile = "previously-notable.png"; //NON-NLS - //imageFile = "red-circle-exclamation.png"; //NON-NLS + imageFile = "red-circle-exclamation.png"; //NON-NLS } else { imageFile = "artifact-icon.png"; //NON-NLS } diff --git a/Core/src/org/sleuthkit/autopsy/images/previously-seen.png b/Core/src/org/sleuthkit/autopsy/images/previously-seen.png index ed78158beb6f740de378cdeda36d1fcbc212f6ac..1bd707232e0e7824adb9b6e66fe112a683652e70 100644 GIT binary patch literal 6455 zcmeHKc{r478y`_LStCnS(?sbot6`Q*lCccNo=Q%7XXZ5~vo$leq!O}4i&LSJrIaXI zq%19@93>q~bfhdtqHyXIIZpcCL8b5OJKxuJecyl0b-gq5JkRg`-S_i*@B4n&p9|Ih*<;LqP&*|1|?#SW9S+M@Wf#W^i)0+YIJHS9NXLJRd|;je@zML_jhlU1`c z5#(d7!4Wy5bB`p}wphJgP~t)N|XA`K#!rxp<#6deNbWXFtAB^bIpNawn11!Bw2m&J`EVy zus^A1hC&TlfIV;)x3D!+DbojFWSSpdAY2(tM|AG7&$2`OBzLG-bySl_Qw2FkgYJjv z_)32Ug+{+(i7R*OvJ%K!@U2Ndt|sTEderJs%nUh& z_-7muT*s5QrTVZNlWw&3gllp08b6yP^XA7_(sok>*J89cY`*Gg|3gsQvHokZ3&Z=v z5G}j)g0FPi>ux!*AG2ApdGGL?)4y0J>3B#sUO649Upd%ZtD}^bDu=tQaI1<2n_Z`A zw%})jQKd64a?E~idn~G<)Mwh94|7D)~FN~DR_Rw!w zU`m^Sz*803%^7dIy1o9i7CPFW((bbb`FO|53zgPg5k`Rfypbj6xBjuIc+fvZFSbE# zo53Ro)u0Mv^E#0|Hm4OeF4DwZyfd@1q^hAuRB3wAc0DE9#;fVbBLiFSkr0Q8pnU@$%fm~Nap#WVeFb}V(J&8Y+QuJKmw4Zfe1dM8Bsll zEB+~Aaq(kcCt}M>^Ts~|bAL~u(MPv+uaBuj8+S^X;WaL)^tpZKEmj1Dnid$w_YSQN zNqGkxttZaa51RQ}b!2va~g})VR&Ox$AUXj@Nl5ZO08+YZOzQtfH5y&=V4K zI($UGv(EQ-bQR=B5b^Zn$Y2|$gfhZbqu%vR{HX_es6ZwjCy7Lv?hZssq0KHpMQM2fPMOw=PeD}W@Epa z(gM+wu7X4P1!1n^m76whaFHB)rrx!VHiI6w&%Jt9ZISxPHA|{#3B#;~VAx=Jr+B&G9rENTnxR`}gYeyz`4zdU)f z<0o2te121U-aZR`ZbN#xqVFI~-nEqNko?=J~( z8&pIhr9E29!|S@+e;lZIAD;W@soKGMaq)-l1;a3y+8Qo&-mPOeQ&>Vi8ej{VAUc#U zf^q`}v$P5o0jxk!ieQ2qu7HXhD!YzEaM@JkT5|@LA+iAjxDH#zpyyT>FV@yT7MYE- zS_!udr9cFHPzoSI`8WDFLM!Q)X70woC(NP$q4 zK(a(eG08y#B`h(N&|IMaA>#y?!XPOXiGQ{=LAw+)3RryR(}6Z8@(8$*W%1ZY1H z0E5S3NhmBHg(qXC+e51i#wTlmWJ*OyPfREv!r;(Y44?mng+yu_{Mp}EEhJvhV+Y0q zln8^wEYLO>6iAm$cPioqNv8V@l7O5ZCmWfJ94=opVIf0L zN3vO;aH1eFZvw++VL%?phXRp6%(yS`ko_lvuWo08d_pJ+O~?w8vCwH$q$~gmTgc+F zDHDIqNh}tVNrqHr;w(@EGLDHNnUQ2eGMjBiVv(^}i)mDJfkX-jSfGpwB1dx}9unRh zYmNi(C;%Xup$J4Q5d}b`C>+@zH1h`mJisJOqi_{-q0|O=)1#76u^}ovfM=Weo0Cu^ zJOK|y!y-VWI3fyUbq6bFhufs z$&1SeJ*9w5Hk<{XNFZ6@@MJv6f=HNV?+uD2P~OT|aac5NGHf=BVh3>oQ2ucF00+c~ z1e}liq1cE)Kq?e_357f=QWh0LW;#&~2+OHFr#K5)fUF)Sz#v;zDpSR>8sK0ihL)JW z1OE$?XMiw7@Za%#hJIqP7E42f;y_oiD|0i*lKwr<*TA2cJfJouk&46U|6x=AgtMGX zOb5tTC=Q$E-xJ(2IhyPxJnn>42*gDFQUI1rMJiGP1cU5}TL9@exx@+p1RM}*lv7pm zai05?gtcI@iA)erMERQ&2q=OXnS~M%EfX?$%P)JQxhh zbUiF(&4ogjC7frFNW|lU;xBdjm^c3hH_d)3NB@)gbl9Y|jZhQ@RcnCMHAL{Y?!N+@ zWN_xPK!HT~ccD**Ov*Ct1c73noP$m#=%B-VI_ajeL{>=u$In#u{U1F*)Zd+alfK{O z`YzWuDez6;@7eWTu5VJ{o50_*>whK}{PVjqD1e^(LZCO{IJ5l2&|CCuk;8fk3^qqo zcFDogkLp5`ic&hmR@@4Nvu&HNrLjI zfx%{MqSLIsNOzl4tO7K*z+#>b-5*A0aW&_o>*5KFKRM*0?3AoNMAFTZmw%+4uydbb zeUzdFKQ<#6U!9kNjF!I{a4^AZL3)ErP(TfP&Q|)7Re^))OAh}grVl+fXu9eC^xf`~ zZBOOL$M*Rpx*6Yk`}S?Sr&iDE^Xm+XOy_LBejU~!G1i*f+uM86O4Trhe&^xChdCa3 zT7iW59AEU>_}X!VyvLo1Hd`CqT|k9s<^Blk>yRdKPo3M>E?SIvC?h!?!#c)fjT zX(=tadoUz8_`*R)+Xq4Ig7pufd7YM^V`LI34zDap>>X{1S#539C;jzmd3m|#S?@4w zbwRF29#~=@D`1)4`B~oi5s%y3RqT=b^DmfQXRg0&pggO-u}3@_f98xP zf#J8o&u@p7xw(0PvACg6npIMwV{t?!mz$mUA~G#4ZH>ED$xQ3kUkC${*~S|ay017z z?{h?`x5~q+um&)>#R^)s(1QAE*y^J5=dI;#baZs+G!k5u7VG3?Wo50%G4MDH@BZ+$E%X>V+7JYQX1-Q>DQB9Yvz ztE)S;8&D3n%*Y0G^Ur!G3W|LWHTGRvcc>zxzBepAcf`)lZZIMH%KIY@Y0kH=6%~o1 z)bVWr1awK;fGX^HUtc7kn>IK&sFRYCQs4b5^nD?LVK|qg8Gq~QjxlE|*bgxH&s|Zc RGNFWo(QRF5=T>jp^$$pT>?!~N delta 636 zcmV-?0)zdxGSdinJfd$ODs!X{(IT|;KRLCCVUE0x>F>bs+>17_%O)9#9T|< zCVXf7)@{scn8`4YVGdpwXclSl{9^jO?dzX!axY#zwKbQtsAFJbObS%-&#XwUm_=L| z_qJv}`S z(G6f`U|?V{G&HnfVq!Y@^XE@dWo6~ApFe-z78DeG%+1Yx?8Ao-lYclkIKm!3eq1do zDthqg)2EM-4PbI{ana!7;@bJ^*RKuv`T3^z?%nhF{P}b4t5>f=UcGvi!o$OpwrSHQ z6G1`2^_;*1$HWZBu-Uo$c?{z6f}#KgeE!}EUW(xrmz?Ckm+ z92}R>1Ci6o$!Q-yKfl!X@83QD{rl(q?c29WjEs=*RZ&stdjJ0Y{NKNSuVQ9q=FZN} zHg|V-e*?FGfq~&WJ3G7cj~_oS|M>CaDjy%8r>v~(99CA=BUQY-ymLN&{HXEq+j#c`d`0(RTdKyd;06wuk#8D3iBsUoVbpG761Ub W0o|5ngrVyI0000`xXb;%z4!C<`8>~m&F3>S=UmtK_x)Yxd%nNlbxxwYtAncY zJY^URrt0Kq>k0jFuzkIYp*510t1%B_VN#D{oucl8d0j*6Pviw;#$uX5GpP1v*GCe2?ymSkA*u^sC( zwNx(+uUyiu5#v2g5Gd4SKuk;NHzW(>0z=r!S=CzPLGTA3=xz{u_C z-N}jO;@8oI9v?p9ta{sAO;RI_S1d7+iELcqv0j} z+R1t;j*^RSI;!5CuDI|tP#}kjA8Hxddg}-Vn`(5RKmlLVy(R4dBK_!EQSTfgDoNM9<8TL1m}EHB(@~`6zqwqho$mW%MPasQMc87F^ z-nv)`73Fp3^)KhWIvRE7H|G!e zkF(6Z8;$r%R}kkT>o{{dKcsgpJXXi5X;ayvG0XZAJSS<)?o3qi;*@z*&i$lrAIxB9 zPke2HKIOJrHn(jr!NLBxOYqFcuNKgiMw1u!MZC=3T9$QM({8uxb5glMYudd^&0GV< zrR}gzzE(6nJg_nB%m9#QwII2h;d(#4eV)nf5AB2H5ij%)=SE%$Wz9UM7^d4i(iETL z880xso;KK%rh7#szrfO9NvE1QdG+#ceC^xU+XDb!{@#xp6i!h)21}X?z)W5CS>5Q^ zp-_YDb2wcSQLVMZ`G)LgN3{p-3)Y>yk$pOp7pWunNn^8q8Cu1x)Uk|?DsoKmC{0YT z<%2ofw-u)LzEppZSb!kI_J`xn-rvh2h}vH?F6wkK&t$k+^p2q4YxWL(QUXSnCYM~f z&(7<%4_|iKKW)s9eLW2w^Es#|nNeAMlW~yMtDmMjbgI5^V~R^pTT|W2F=vvOD3kwa z+CENl`q=FiX&Q*Lu>ZVE-v;6>564 z#!inHiJX|hox$5`)+TikZ{**N)$9oL`e?oBrQnZ!21my-=DD~AQckvIg$OFnJT$LV zR}Mu_6_Wb&ADt-5IR^U0S5z@7LwlN5HCU^!lmBCMci%L<Edq|OI@M)7#vbrZ+p?vrxJD{PnU6Uk;O0tSIR?K)}eJ3o=gy&gUP}-8E z;-TBSYj=LlyC;R(Z=1A(93Eh^VKBLEEE^klCmWl;nmm*yQ?i@lSi3^6Zk^Y0#O&-j z>Y)wp3N@QgCFD?xl;$`GWP2;_U1ha(k*ZTta?WFa{wttp@bQzpGh5EUm11HqULu*4 zIVOHxrHrIo5Qpo_qf^TxV%^cEtuJ*Hsf{?#kpl-B&nCpJnR+Kx&0c-af!xLSX3Q1u zEQo&pK1%zkU)R7FJ&JP|Bi79*3oN6l7ihZi{K*57Czz#9$|Iza1J>F`F@0q(|I{5g zS}WhAqI#w zHwn&v?bUw^gU#}0LA$Q6%W5*f>kbf^p&7fI%$BC;{jdSbw-7LxWKUcB2@2?pf(R0c_+&IX zA|e76VT$4jHlVR25($mLp>a4Qgg^=-xgwev$rTz(DaJW$K_MW3{LJEU;ZjZ-ofjse zAP~?ze1cr+b~`aNIFUelE~6KU7-%Qx1P@&g1VH037$OpbL*hv2$??#vi_5oYu5dy{ zNKdqw#z$jO7&M3Tw+NxgF8q7GA4UkN(8CYf6BP2o1OR9k4su0?laun#~*&?Zs130RP|Y3#|Xl2S1sDu8YZ;F%->5+D!(B;E|iKoV&<0+LQ=nwbK00v=Ci z$f%^klC9mHC6kQ3<`^vg);!MJ;X_a{KMkVHh^e8cY|yKS~b~50MbM}0hPyNQxMWs z!KIjmZ;gQ$mp-(&=AZ)c?X+j2qJtiscC+C*}77L&wj?dkLE* zlL`)()i0R_NL8dDgtTyQ+y{`3<5NHojk^Ja8s$Wl{58({fnfntq8S}ShdPU?DIJL? zfegs=Bpeb;089yVa|{DV$I5Q-H+CV9DT<&8KrGmu1op z0(3@~QqvZ__M2!wl=tac1^AY4wm^c_ELee~ighDO}$riIT^?Td8|UD>j@T;)$SRq_K9t-1UB z43}ZIW|am8Cjv&#W^zJ0X!#dZ4R|5Z!(qvPw&hyZqr1@?d&U&LnDz0d#H5$P#4{e} zc%=ot@z_$^v)(tY0;zQ60d+}hp0TpOzrO}-W$!ZGt52TD$40pNg@3+V{bF=bKCXI; zh&;4pPV%|CL8}AKwoO^7boB12Z0kMg`HM8v$jiM#q9kL3gQt~XTCj_2^H1=JdOPZS zZNkFBEVt861P2G7`>-)<>3-+>+xwhD44;dd340Saoi?V-OX*K<4VLV8G*UjjfB)>- z;o)I>+`)4Ky@9^SFHza9ZA%7!SUvuC8wMU3Tp% zy~v?>S%!myLtsfs$*L-5W>(hleH6N?Z)#jmdD+ajErSF5owuE)E=j6c?|#nztf@h2 zfJxHB3mrojHd?NGl{)`D>!W4t^>>|}vo4sWkI;+S7vC(N2YVAmx$*Q*rbP0&q^GAx z;X(&ezhXes%BB7@zVm(g@Q8S4v_+QY`+^VC<0*4=h^-IpAoIeU>|Aa0SFYduKT}ao A(*OVf delta 713 zcmV;)0yh2WGmr_8BNYLKX+uL$Nkc;*aB^>EX>4Tx04R~O9R_v*1otr4F_ZWfA_f-) zTn8h9lOPu;e|bqnK~y-)wb5@#6JZ<&@ZWB`oq0TY?N-{-ExQ^uAqkwyk0rf z-t0}^cRzT3pXbZ-0OXiQ<$I5W9(Xn^&krwNHux)Rf8DBFfuX8{TwdWuvFLnjoxiVN zyM5+!VDSg9%^4VhbtRcXbNDN72~{z*Qjd(t*>- zXfS7Bpqeeoo0G>mf@fcM>7gCJ4e6o6YuYe{yn?SP7__nwpMBqtT}bp$k5ruajlj z>2x~1d&L>qYPD|FXf$QPVDKeD5ch_Mhug9Z;_>)xlgael=ks;;^z>-gECT?L;c$4T z%jFscfNLt1>bleEEXo21p~oD@)wj2|?`v*uP9ubbwLf4sn|YRH^GTAtieZ@F>2&_g ze*%q-jkjo;eiaA={4Fgl$MkxAD**ff08kVK7>030A`y(DsE{N{YJN7M9_D2fwCqp>U&i-i?MVN$8oQ5?s|OG``bU0q$=KfrSAc6+5P%a<~l vOr Date: Wed, 8 Sep 2021 14:38:40 -0400 Subject: [PATCH 05/10] Fixed string content page number issue --- .../textcontentviewer/Bundle.properties | 2 +- .../Bundle.properties-MERGED | 2 +- .../StringsContentPanel.form | 15 ++------ .../StringsContentPanel.java | 35 +++---------------- 4 files changed, 9 insertions(+), 45 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/Bundle.properties b/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/Bundle.properties index 341efff6d6..fb7c0f33cc 100644 --- a/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/Bundle.properties +++ b/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/Bundle.properties @@ -8,7 +8,7 @@ StringsContentPanel.selectAllMenuItem.text=Select All StringsContentPanel.currentPageLabel.text_1=1 StringsContentPanel.copyMenuItem.text=Copy StringsContentPanel.ofLabel.text_1=of -StringsContentPanel.totalPageLabel.text_1=100 +StringsContentPanel.totalPageLabel.text_1=1000 StringsContentPanel.languageLabel.toolTipText= StringsContentPanel.languageLabel.text=Script: StringsContentPanel.languageCombo.toolTipText=Language to attempt when interpreting (extracting and decoding) strings from binary data diff --git a/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/Bundle.properties-MERGED b/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/Bundle.properties-MERGED index 024103570d..c859dc8f33 100644 --- a/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/Bundle.properties-MERGED +++ b/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/Bundle.properties-MERGED @@ -9,7 +9,7 @@ StringsContentPanel.selectAllMenuItem.text=Select All StringsContentPanel.currentPageLabel.text_1=1 StringsContentPanel.copyMenuItem.text=Copy StringsContentPanel.ofLabel.text_1=of -StringsContentPanel.totalPageLabel.text_1=100 +StringsContentPanel.totalPageLabel.text_1=1000 StringsContentPanel.languageLabel.toolTipText= StringsContentPanel.languageLabel.text=Script: StringsContentPanel.languageCombo.toolTipText=Language to attempt when interpreting (extracting and decoding) strings from binary data diff --git a/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/StringsContentPanel.form b/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/StringsContentPanel.form index 6253570c82..6c579799b6 100644 --- a/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/StringsContentPanel.form +++ b/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/StringsContentPanel.form @@ -103,15 +103,6 @@ - - - - - - - - - @@ -158,13 +149,13 @@ - + - + - + diff --git a/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/StringsContentPanel.java b/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/StringsContentPanel.java index 750f143e0e..e83dadadef 100644 --- a/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/StringsContentPanel.java +++ b/Core/src/org/sleuthkit/autopsy/contentviewers/textcontentviewer/StringsContentPanel.java @@ -95,12 +95,11 @@ public class StringsContentPanel extends javax.swing.JPanel { currentPage = 1; currentOffset = 0; this.dataSource = null; - currentPageLabel.setText(""); + currentPageLabel.setText("1"); totalPageLabel.setText(""); prevPageButton.setEnabled(false); nextPageButton.setEnabled(false); outputViewPane.setText(""); // reset the output view - setComponentsVisibility(false); // hides the components that not needed } /** @@ -167,9 +166,6 @@ public class StringsContentPanel extends javax.swing.JPanel { panelPageOfCount.add(jSepMed1); currentPageLabel.setText(org.openide.util.NbBundle.getMessage(StringsContentPanel.class, "StringsContentPanel.currentPageLabel.text_1")); // NOI18N - currentPageLabel.setMaximumSize(new java.awt.Dimension(18, 25)); - currentPageLabel.setMinimumSize(new java.awt.Dimension(7, 25)); - currentPageLabel.setPreferredSize(new java.awt.Dimension(18, 25)); panelPageOfCount.add(currentPageLabel); jSepMed2.setPreferredSize(new java.awt.Dimension(5, 0)); @@ -185,9 +181,9 @@ public class StringsContentPanel extends javax.swing.JPanel { panelPageOfCount.add(jSepMed3); totalPageLabel.setText(org.openide.util.NbBundle.getMessage(StringsContentPanel.class, "StringsContentPanel.totalPageLabel.text_1")); // NOI18N - totalPageLabel.setMaximumSize(new java.awt.Dimension(21, 25)); - totalPageLabel.setMinimumSize(new java.awt.Dimension(21, 25)); - totalPageLabel.setPreferredSize(new java.awt.Dimension(21, 25)); + totalPageLabel.setMaximumSize(new java.awt.Dimension(25, 25)); + totalPageLabel.setMinimumSize(new java.awt.Dimension(25, 25)); + totalPageLabel.setPreferredSize(new java.awt.Dimension(25, 25)); panelPageOfCount.add(totalPageLabel); jSepMed4.setPreferredSize(new java.awt.Dimension(5, 0)); @@ -409,24 +405,6 @@ public class StringsContentPanel extends javax.swing.JPanel { worker.execute(); } - /** - * To set the visibility of specific components in this class. - * - * @param isVisible whether to show or hide the specific components - */ - private void setComponentsVisibility(boolean isVisible) { - currentPageLabel.setVisible(isVisible); - totalPageLabel.setVisible(isVisible); - ofLabel.setVisible(isVisible); - prevPageButton.setVisible(isVisible); - nextPageButton.setVisible(isVisible); - pageLabel.setVisible(isVisible); - pageLabel2.setVisible(isVisible); - goToPageTextField.setVisible(isVisible); - goToPageLabel.setVisible(isVisible); - languageCombo.setVisible(isVisible); - languageLabel.setVisible(isVisible); - } /** * Swingworker for getting the text from a content object. @@ -509,9 +487,7 @@ public class StringsContentPanel extends javax.swing.JPanel { int totalPage = Math.round((dataSource.getSize() - 1) / PAGE_LENGTH) + 1; totalPageLabel.setText(Integer.toString(totalPage)); - currentPageLabel.setText("1"); outputViewPane.setText(text); // set the output view - setComponentsVisibility(true); // shows the components that not needed outputViewPane.moveCaretPosition(0); setCursor(Cursor.getPredefinedCursor(Cursor.DEFAULT_CURSOR)); @@ -557,10 +533,7 @@ public class StringsContentPanel extends javax.swing.JPanel { prevPageButton.setEnabled(false); currentPage = 1; - totalPageLabel.setText("1"); - currentPageLabel.setText("1"); outputViewPane.setText(text); // set the output view - setComponentsVisibility(true); // shows the components that not needed outputViewPane.moveCaretPosition(0); setCursor(Cursor.getPredefinedCursor(Cursor.DEFAULT_CURSOR)); From 722cb2d898799b066dcaaac24f4c9dbef11c3c6c Mon Sep 17 00:00:00 2001 From: Richard Cordovano Date: Wed, 8 Sep 2021 15:07:38 -0400 Subject: [PATCH 06/10] 7797 fix analysis result tagging --- .../datamodel/BlackboardArtifactItem.java | 43 +++++++++++++++++++ .../autopsy/datamodel/DataArtifactItem.java | 41 ++++++++++++++++++ 2 files changed, 84 insertions(+) create mode 100755 Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactItem.java create mode 100755 Core/src/org/sleuthkit/autopsy/datamodel/DataArtifactItem.java diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactItem.java b/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactItem.java new file mode 100755 index 0000000000..3897e37311 --- /dev/null +++ b/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactItem.java @@ -0,0 +1,43 @@ +/* + * Autopsy Forensic Browser + * + * Copyright 2021-2021 Basis Technology Corp. + * Contact: carrier sleuthkit org + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.sleuthkit.autopsy.datamodel; + +import com.google.common.annotations.Beta; +import org.sleuthkit.datamodel.BlackboardArtifact; + +/** + * An abstract super class for an Autopsy Data Model item class with an + * underlying BlackboardArtifact Sleuth Kit Data Model object. + * + * @param The concrete BlackboardArtifact sub class type. + */ +public abstract class BlackboardArtifactItem extends TskContentItem { + + /** + * Constructs an Autopsy Data Model item with an underlying + * BlackboardArtifact Sleuth Kit Data Model object. + * + * @param blackboardArtifact The BlackboardArtifact object. + */ + @Beta + BlackboardArtifactItem(T blackboardArtifact) { + super(blackboardArtifact); + } + +} diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/DataArtifactItem.java b/Core/src/org/sleuthkit/autopsy/datamodel/DataArtifactItem.java new file mode 100755 index 0000000000..c43d3a311c --- /dev/null +++ b/Core/src/org/sleuthkit/autopsy/datamodel/DataArtifactItem.java @@ -0,0 +1,41 @@ +/* + * Autopsy Forensic Browser + * + * Copyright 2021-2021 Basis Technology Corp. + * Contact: carrier sleuthkit org + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.sleuthkit.autopsy.datamodel; + +import com.google.common.annotations.Beta; +import org.sleuthkit.datamodel.DataArtifact; + +/** + * An Autopsy Data Model item with an underlying DataArtifact Sleuth Kit Data + * Model object. + */ +public class DataArtifactItem extends BlackboardArtifactItem { + + /** + * Constructs an Autopsy Data Model item with an underlying DataArtifact + * Sleuth Kit Data Model object. + * + * @param dataArtifact The DataArtifact object. + */ + @Beta + DataArtifactItem(DataArtifact dataArtifact) { + super(dataArtifact); + } + +} From cae2fd798dae95836415ebe70635ef9686d51972 Mon Sep 17 00:00:00 2001 From: Richard Cordovano Date: Wed, 8 Sep 2021 15:14:02 -0400 Subject: [PATCH 07/10] 7797 fix analysis result tagging --- .../AddBlackboardArtifactTagAction.java | 19 +++++++++-- .../autopsy/actions/AddTagAction.java | 32 +++++++++++++------ .../AnalysisResultsContentViewer.java | 2 +- .../AnalysisResultsViewModel.java | 6 ++-- .../datamodel/AbstractContentNode.java | 2 +- .../autopsy/datamodel/AnalysisResultItem.java | 16 ++-------- .../datamodel/BlackboardArtifactItem.java | 3 +- .../datamodel/BlackboardArtifactNode.java | 17 ++++++---- .../autopsy/datamodel/TskContentItem.java | 16 ++++++---- 9 files changed, 70 insertions(+), 43 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/actions/AddBlackboardArtifactTagAction.java b/Core/src/org/sleuthkit/autopsy/actions/AddBlackboardArtifactTagAction.java index 26d1c7a9bc..06a3e2e39e 100644 --- a/Core/src/org/sleuthkit/autopsy/actions/AddBlackboardArtifactTagAction.java +++ b/Core/src/org/sleuthkit/autopsy/actions/AddBlackboardArtifactTagAction.java @@ -1,7 +1,7 @@ /* * Autopsy Forensic Browser * - * Copyright 2011-2019 Basis Technology Corp. + * Copyright 2013-2021 Basis Technology Corp. * Contact: carrier sleuthkit org * * Licensed under the Apache License, Version 2.0 (the "License"); @@ -29,6 +29,7 @@ import org.openide.windows.WindowManager; import org.sleuthkit.autopsy.casemodule.Case; import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException; import org.sleuthkit.autopsy.coreutils.Logger; +import org.sleuthkit.autopsy.datamodel.BlackboardArtifactItem; import org.sleuthkit.datamodel.BlackboardArtifact; import org.sleuthkit.datamodel.Content; import org.sleuthkit.datamodel.TagName; @@ -46,6 +47,8 @@ import org.sleuthkit.datamodel.TskCoreException; }) public class AddBlackboardArtifactTagAction extends AddTagAction { + private static final long serialVersionUID = 1L; + // This class is a singleton to support multi-selection of nodes, since // org.openide.nodes.NodeOp.findActions(Node[] nodes) will only pick up an Action if every // node in the array returns a reference to the same action object from Node.getActions(boolean). @@ -82,8 +85,14 @@ public class AddBlackboardArtifactTagAction extends AddTagAction { * invocation of addTag(), we don't want to tag the same * BlackboardArtifact more than once, so we dedupe the * BlackboardArtifacts by stuffing them into a HashSet. + * + * RC (9/8/21): The documentation does NOT say that lookupAll() can + * return duplicates. That would be very broken. What motivated this + * "de-duping" ? */ - selectedArtifacts.addAll(Utilities.actionsGlobalContext().lookupAll(BlackboardArtifact.class)); + for (BlackboardArtifactItem item : Utilities.actionsGlobalContext().lookupAll(BlackboardArtifactItem.class)) { + selectedArtifacts.add(item.getTskContent()); + } } else { for (Content content : getContentToTag()) { if (content instanceof BlackboardArtifact) { @@ -111,4 +120,10 @@ public class AddBlackboardArtifactTagAction extends AddTagAction { } }).start(); } + + @Override + public Object clone() throws CloneNotSupportedException { + return super.clone(); + } + } diff --git a/Core/src/org/sleuthkit/autopsy/actions/AddTagAction.java b/Core/src/org/sleuthkit/autopsy/actions/AddTagAction.java index 9c059205f5..725cdb504d 100644 --- a/Core/src/org/sleuthkit/autopsy/actions/AddTagAction.java +++ b/Core/src/org/sleuthkit/autopsy/actions/AddTagAction.java @@ -1,7 +1,7 @@ /* * Autopsy Forensic Browser * - * Copyright 2013-2020 Basis Technology Corp. + * Copyright 2013-2021 Basis Technology Corp. * Contact: carrier sleuthkit org * * Licensed under the Apache License, Version 2.0 (the "License"); @@ -44,33 +44,40 @@ import org.sleuthkit.datamodel.TskCoreException; import org.sleuthkit.datamodel.TskData; /** - * An abstract base class for Actions that allow users to tag SleuthKit data + * An abstract base class for Actions that allow users to tag Sleuth Kit data * model objects. */ abstract class AddTagAction extends AbstractAction implements Presenter.Popup { private static final long serialVersionUID = 1L; private static final String NO_COMMENT = ""; - private final Collection content = new HashSet<>(); + private final Collection contentObjsToTag; + /** + * Constructs an instance of an abstract base class for Actions that allow + * users to tag Sleuth Kit data model objects. + * + * @param menuText The menu item text. + */ AddTagAction(String menuText) { super(menuText); + contentObjsToTag = new HashSet<>(); } @Override public JMenuItem getPopupPresenter() { - content.clear(); + contentObjsToTag.clear(); return new TagMenu(); } /** - * Get the collection of content which may have been specified for this + * Getz the collection of content which may have been specified for this * action. Empty collection returned when no content was specified. * * @return The specified content for this action. */ Collection getContentToTag() { - return Collections.unmodifiableCollection(content); + return Collections.unmodifiableCollection(contentObjsToTag); } /** @@ -83,8 +90,8 @@ abstract class AddTagAction extends AbstractAction implements Presenter.Popup { * apply to the Content specified. */ public JMenuItem getMenuForContent(Collection contentToTag) { - content.clear(); - content.addAll(contentToTag); + contentObjsToTag.clear(); + contentObjsToTag.addAll(contentToTag); return new TagMenu(); } @@ -111,6 +118,11 @@ abstract class AddTagAction extends AbstractAction implements Presenter.Popup { */ abstract protected void addTag(TagName tagName, String comment); + @Override + public Object clone() throws CloneNotSupportedException { + return super.clone(); + } + /** * Instances of this class implement a context menu user interface for * creating or selecting a tag name for a tag and specifying an optional tag @@ -126,7 +138,7 @@ abstract class AddTagAction extends AbstractAction implements Presenter.Popup { super(getActionDisplayName()); // Get the current set of tag names. - Map tagNamesMap = null; + Map tagNamesMap; List standardTagNames = TagsManager.getStandardTagNames(); Map tagSetMenuMap = new HashMap<>(); List standardTagMenuitems = new ArrayList<>(); @@ -240,5 +252,7 @@ abstract class AddTagAction extends AbstractAction implements Presenter.Popup { return tagNameItem; } + } + } diff --git a/Core/src/org/sleuthkit/autopsy/contentviewers/analysisresults/AnalysisResultsContentViewer.java b/Core/src/org/sleuthkit/autopsy/contentviewers/analysisresults/AnalysisResultsContentViewer.java index b056eb11db..d40f6c2a39 100644 --- a/Core/src/org/sleuthkit/autopsy/contentviewers/analysisresults/AnalysisResultsContentViewer.java +++ b/Core/src/org/sleuthkit/autopsy/contentviewers/analysisresults/AnalysisResultsContentViewer.java @@ -132,7 +132,7 @@ public class AnalysisResultsContentViewer implements DataContentViewer { return true; } - TskContentItem contentItem = node.getLookup().lookup(TskContentItem.class); + TskContentItem contentItem = node.getLookup().lookup(TskContentItem.class); if (!Objects.isNull(contentItem)) { Content content = contentItem.getTskContent(); try { diff --git a/Core/src/org/sleuthkit/autopsy/contentviewers/analysisresults/AnalysisResultsViewModel.java b/Core/src/org/sleuthkit/autopsy/contentviewers/analysisresults/AnalysisResultsViewModel.java index 37e4114168..b470f9dfb7 100644 --- a/Core/src/org/sleuthkit/autopsy/contentviewers/analysisresults/AnalysisResultsViewModel.java +++ b/Core/src/org/sleuthkit/autopsy/contentviewers/analysisresults/AnalysisResultsViewModel.java @@ -1,7 +1,7 @@ /* * Autopsy Forensic Browser * - * Copyright 2021 Basis Technology Corp. + * Copyright 2021-2021 Basis Technology Corp. * Contact: carrier sleuthkit org * * Licensed under the Apache License, Version 2.0 (the "License"); @@ -251,7 +251,7 @@ public class AnalysisResultsViewModel { * selected in the content viewer and get the analyzed content * as the source of the analysis results to display. */ - selectedAnalysisResult = analysisResultItem.getAnalysisResult(); + selectedAnalysisResult = analysisResultItem.getTskContent(); selectedObjectId = selectedAnalysisResult.getId(); analyzedContent = selectedAnalysisResult.getParent(); } else { @@ -260,7 +260,7 @@ public class AnalysisResultsViewModel { * an analysis result. Use it as the source of the analysis * results to display. */ - TskContentItem contentItem = node.getLookup().lookup(TskContentItem.class); + TskContentItem contentItem = node.getLookup().lookup(TskContentItem.class); analyzedContent = contentItem.getTskContent(); selectedObjectId = analyzedContent.getId(); } diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/AbstractContentNode.java b/Core/src/org/sleuthkit/autopsy/datamodel/AbstractContentNode.java index daf8cd84da..2b8428280a 100644 --- a/Core/src/org/sleuthkit/autopsy/datamodel/AbstractContentNode.java +++ b/Core/src/org/sleuthkit/autopsy/datamodel/AbstractContentNode.java @@ -102,7 +102,7 @@ public abstract class AbstractContentNode extends ContentNode * @param content Underlying Content instances */ AbstractContentNode(T content) { - this(content, Lookups.fixed(content, new TskContentItem(content))); + this(content, Lookups.fixed(content, new TskContentItem<>(content))); } /** diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/AnalysisResultItem.java b/Core/src/org/sleuthkit/autopsy/datamodel/AnalysisResultItem.java index 442d070f5c..20ee3652c0 100755 --- a/Core/src/org/sleuthkit/autopsy/datamodel/AnalysisResultItem.java +++ b/Core/src/org/sleuthkit/autopsy/datamodel/AnalysisResultItem.java @@ -22,30 +22,20 @@ import com.google.common.annotations.Beta; import org.sleuthkit.datamodel.AnalysisResult; /** - * An Autopsy Data Model item with an underlying analysis result Sleuth Kit Data + * An Autopsy Data Model item with an underlying AnalysisResult Sleuth Kit Data * Model object. */ -public class AnalysisResultItem extends TskContentItem { +public class AnalysisResultItem extends BlackboardArtifactItem { /** * Constructs an Autopsy Data Model item with an underlying AnalysisResult * Sleuth Kit Data Model object. * - * @param analysisResult The analysis result. + * @param analysisResult The AnalysisResult object. */ @Beta AnalysisResultItem(AnalysisResult analysisResult) { super(analysisResult); } - /** - * Gets the underlying analysis result. - * - * @return The analysis result. - */ - @Beta - public AnalysisResult getAnalysisResult() { - return (AnalysisResult) (getTskContent()); - } - } diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactItem.java b/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactItem.java index 3897e37311..8d4cab5ea5 100755 --- a/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactItem.java +++ b/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactItem.java @@ -23,7 +23,8 @@ import org.sleuthkit.datamodel.BlackboardArtifact; /** * An abstract super class for an Autopsy Data Model item class with an - * underlying BlackboardArtifact Sleuth Kit Data Model object. + * underlying BlackboardArtifact Sleuth Kit Data Model object, i.e., a + * DataArtifact or an AnalysisResult. * * @param The concrete BlackboardArtifact sub class type. */ diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java b/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java index 469c069aae..0072654ccb 100644 --- a/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java +++ b/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java @@ -81,6 +81,7 @@ import org.sleuthkit.autopsy.texttranslation.TextTranslationService; import org.sleuthkit.autopsy.datamodel.utils.FileNameTransTask; import org.sleuthkit.datamodel.AnalysisResult; import org.sleuthkit.datamodel.BlackboardArtifact.Category; +import org.sleuthkit.datamodel.DataArtifact; import org.sleuthkit.datamodel.Score; /** @@ -232,7 +233,7 @@ public class BlackboardArtifactNode extends AbstractContentNode artifactItem; if (artifact instanceof AnalysisResult) { artifactItem = new AnalysisResultItem((AnalysisResult) artifact); } else { - artifactItem = new TskContentItem(artifact); + artifactItem = new DataArtifactItem((DataArtifact) artifact); } /* * Create the Lookup. + * + * NOTE: For now, we are putting both the Autopsy Data Model item and + * the Sleuth Kit Data Model item in the Lookup so that code that is not + * aware of the new Autopsy Data Model will still function. */ if (content == null) { return Lookups.fixed(artifact, artifactItem); @@ -385,7 +390,7 @@ public class BlackboardArtifactNode extends AbstractContentNode The type of the underlying Sleuth Kit Data Model object. */ @Beta -public class TskContentItem { +public class TskContentItem { - private final Content tskContent; + private final T content; /** * Constructs an Autopsy Data Model item with an underlying Sleuth Kit Data * Model object that implements the Sleuth Kit Data Model's Content * interface. * - * @param content The underlying Sleuth Kit Data Model object. + * @param content The Sleuth Kit Data Model object. * */ @Beta - TskContentItem(Content sleuthKitContent) { - this.tskContent = sleuthKitContent; + TskContentItem(T content) { + this.content = content; } /** @@ -49,8 +51,8 @@ public class TskContentItem { * @return The Sleuth Kit Data Model object. */ @Beta - public Content getTskContent() { - return tskContent; + public T getTskContent() { + return content; } } From d03c1dc789bef8d0e14579373370c33e1b06202a Mon Sep 17 00:00:00 2001 From: Richard Cordovano Date: Wed, 8 Sep 2021 15:20:38 -0400 Subject: [PATCH 08/10] 7797 fix analysis result tagging --- Core/src/org/sleuthkit/autopsy/actions/AddTagAction.java | 6 +++--- .../sleuthkit/autopsy/datamodel/AbstractContentNode.java | 3 +-- .../sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java | 2 +- 3 files changed, 5 insertions(+), 6 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/actions/AddTagAction.java b/Core/src/org/sleuthkit/autopsy/actions/AddTagAction.java index 725cdb504d..ff3dc08e04 100644 --- a/Core/src/org/sleuthkit/autopsy/actions/AddTagAction.java +++ b/Core/src/org/sleuthkit/autopsy/actions/AddTagAction.java @@ -44,7 +44,7 @@ import org.sleuthkit.datamodel.TskCoreException; import org.sleuthkit.datamodel.TskData; /** - * An abstract base class for Actions that allow users to tag Sleuth Kit data + * An abstract super class for Actions that allow users to tag Sleuth Kit data * model objects. */ abstract class AddTagAction extends AbstractAction implements Presenter.Popup { @@ -54,7 +54,7 @@ abstract class AddTagAction extends AbstractAction implements Presenter.Popup { private final Collection contentObjsToTag; /** - * Constructs an instance of an abstract base class for Actions that allow + * Constructs an instance of an abstract super class for Actions that allow * users to tag Sleuth Kit data model objects. * * @param menuText The menu item text. @@ -71,7 +71,7 @@ abstract class AddTagAction extends AbstractAction implements Presenter.Popup { } /** - * Getz the collection of content which may have been specified for this + * Get the collection of content which may have been specified for this * action. Empty collection returned when no content was specified. * * @return The specified content for this action. diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/AbstractContentNode.java b/Core/src/org/sleuthkit/autopsy/datamodel/AbstractContentNode.java index 2b8428280a..cb4bb9794c 100644 --- a/Core/src/org/sleuthkit/autopsy/datamodel/AbstractContentNode.java +++ b/Core/src/org/sleuthkit/autopsy/datamodel/AbstractContentNode.java @@ -1,7 +1,7 @@ /* * Autopsy Forensic Browser * - * Copyright 2011-2019 Basis Technology Corp. + * Copyright 2012-2021 Basis Technology Corp. * Contact: carrier sleuthkit org * * Licensed under the Apache License, Version 2.0 (the "License"); @@ -39,7 +39,6 @@ import org.sleuthkit.autopsy.centralrepository.datamodel.CorrelationAttributeIns import org.sleuthkit.autopsy.centralrepository.datamodel.CorrelationAttributeInstance.Type; import org.sleuthkit.autopsy.corecomponents.DataResultViewerTable; import org.sleuthkit.autopsy.coreutils.Logger; -import org.sleuthkit.datamodel.AnalysisResult; import org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE; import org.sleuthkit.datamodel.Content; import org.sleuthkit.datamodel.Score; diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java b/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java index 0072654ccb..f11c75784e 100644 --- a/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java +++ b/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java @@ -368,7 +368,7 @@ public class BlackboardArtifactNode extends AbstractContentNode artifactItem; if (artifact instanceof AnalysisResult) { From b8598d0b1413c7aa57db2ce4a3b01bcb5352d20f Mon Sep 17 00:00:00 2001 From: Richard Cordovano Date: Wed, 8 Sep 2021 16:15:50 -0400 Subject: [PATCH 09/10] 7959 comment out data artifacts ingest pipeline --- .../CentralRepoIngestModuleFactory.java | 18 ++++++++--------- .../ingest/DataArtifactIngestPipeline.java | 8 ++++---- .../autopsy/ingest/IngestJobPipeline.java | 20 +++++++++---------- .../autopsy/ingest/IngestJobSettings.java | 2 +- .../autopsy/ingest/IngestModuleFactory.java | 14 ++++++------- .../autopsy/ingest/IngestModuleTemplate.java | 12 +++++------ 6 files changed, 37 insertions(+), 37 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/centralrepository/ingestmodule/CentralRepoIngestModuleFactory.java b/Core/src/org/sleuthkit/autopsy/centralrepository/ingestmodule/CentralRepoIngestModuleFactory.java index 39c80abefc..22ce22f65f 100644 --- a/Core/src/org/sleuthkit/autopsy/centralrepository/ingestmodule/CentralRepoIngestModuleFactory.java +++ b/Core/src/org/sleuthkit/autopsy/centralrepository/ingestmodule/CentralRepoIngestModuleFactory.java @@ -121,14 +121,14 @@ public class CentralRepoIngestModuleFactory extends IngestModuleFactoryAdapter { throw new IllegalArgumentException("Expected settings argument to be an instance of IngestSettings"); } - @Override - public boolean isDataArtifactIngestModuleFactory() { - return true; - } - - @Override - public DataArtifactIngestModule createDataArtifactIngestModule(IngestModuleIngestJobSettings settings) { - return new CentralRepoDataArtifactIngestModule(); - } +// @Override +// public boolean isDataArtifactIngestModuleFactory() { +// return true; +// } +// +// @Override +// public DataArtifactIngestModule createDataArtifactIngestModule(IngestModuleIngestJobSettings settings) { +// return new CentralRepoDataArtifactIngestModule(); +// } } diff --git a/Core/src/org/sleuthkit/autopsy/ingest/DataArtifactIngestPipeline.java b/Core/src/org/sleuthkit/autopsy/ingest/DataArtifactIngestPipeline.java index 824d7d7fe9..a25485a352 100755 --- a/Core/src/org/sleuthkit/autopsy/ingest/DataArtifactIngestPipeline.java +++ b/Core/src/org/sleuthkit/autopsy/ingest/DataArtifactIngestPipeline.java @@ -44,10 +44,10 @@ final class DataArtifactIngestPipeline extends IngestTaskPipeline> acceptModuleTemplate(IngestModuleTemplate template) { Optional> module = Optional.empty(); - if (template.isDataArtifactIngestModuleTemplate()) { - DataArtifactIngestModule ingestModule = template.createDataArtifactIngestModule(); - module = Optional.of(new DataArtifactIngestPipelineModule(ingestModule, template.getModuleName())); - } +// if (template.isDataArtifactIngestModuleTemplate()) { +// DataArtifactIngestModule ingestModule = template.createDataArtifactIngestModule(); +// module = Optional.of(new DataArtifactIngestPipelineModule(ingestModule, template.getModuleName())); +// } return module; } diff --git a/Core/src/org/sleuthkit/autopsy/ingest/IngestJobPipeline.java b/Core/src/org/sleuthkit/autopsy/ingest/IngestJobPipeline.java index c68dde5911..bdaaa9f3a9 100644 --- a/Core/src/org/sleuthkit/autopsy/ingest/IngestJobPipeline.java +++ b/Core/src/org/sleuthkit/autopsy/ingest/IngestJobPipeline.java @@ -368,9 +368,9 @@ final class IngestJobPipeline { if (template.isFileIngestModuleTemplate()) { addModuleTemplateToSortingMap(javaFileModuleTemplates, jythonFileModuleTemplates, template); } - if (template.isDataArtifactIngestModuleTemplate()) { - addModuleTemplateToSortingMap(javaArtifactModuleTemplates, jythonArtifactModuleTemplates, template); - } +// if (template.isDataArtifactIngestModuleTemplate()) { +// addModuleTemplateToSortingMap(javaArtifactModuleTemplates, jythonArtifactModuleTemplates, template); +// } } /** @@ -616,13 +616,13 @@ final class IngestJobPipeline { type = IngestModuleType.MULTIPLE; } } - if (moduleTemplate.isDataArtifactIngestModuleTemplate()) { - if (type == null) { - type = IngestModuleType.DATA_ARTIFACT; - } else { - type = IngestModuleType.MULTIPLE; - } - } +// if (moduleTemplate.isDataArtifactIngestModuleTemplate()) { +// if (type == null) { +// type = IngestModuleType.DATA_ARTIFACT; +// } else { +// type = IngestModuleType.MULTIPLE; +// } +// } return type; } diff --git a/Core/src/org/sleuthkit/autopsy/ingest/IngestJobSettings.java b/Core/src/org/sleuthkit/autopsy/ingest/IngestJobSettings.java index 7de83ded4c..8f2db29849 100644 --- a/Core/src/org/sleuthkit/autopsy/ingest/IngestJobSettings.java +++ b/Core/src/org/sleuthkit/autopsy/ingest/IngestJobSettings.java @@ -318,7 +318,7 @@ public final class IngestJobSettings { // Add modules that are going to be used for this ingest depending on type. for (IngestModuleFactory moduleFactory : allModuleFactories) { - if (moduleFactory.isDataArtifactIngestModuleFactory() || ingestType.equals(IngestType.ALL_MODULES)) { + if (/*moduleFactory.isDataArtifactIngestModuleFactory() ||*/ ingestType.equals(IngestType.ALL_MODULES)) { moduleFactories.add(moduleFactory); } else if (this.ingestType.equals(IngestType.DATA_SOURCE_ONLY) && moduleFactory.isDataSourceIngestModuleFactory()) { moduleFactories.add(moduleFactory); diff --git a/Core/src/org/sleuthkit/autopsy/ingest/IngestModuleFactory.java b/Core/src/org/sleuthkit/autopsy/ingest/IngestModuleFactory.java index e473086d18..15fb96eded 100644 --- a/Core/src/org/sleuthkit/autopsy/ingest/IngestModuleFactory.java +++ b/Core/src/org/sleuthkit/autopsy/ingest/IngestModuleFactory.java @@ -228,7 +228,7 @@ public interface IngestModuleFactory { * * @return A file ingest module instance. */ - default FileIngestModule createFileIngestModule(IngestModuleIngestJobSettings ingestOptions) { + default FileIngestModule createFileIngestModule(IngestModuleIngestJobSettings settings) { throw new UnsupportedOperationException(); } @@ -238,9 +238,9 @@ public interface IngestModuleFactory { * * @return True or false. */ - default boolean isDataArtifactIngestModuleFactory() { - return false; - } +// default boolean isDataArtifactIngestModuleFactory() { +// return false; +// } /** * Creates a data artifact ingest module instance. @@ -267,8 +267,8 @@ public interface IngestModuleFactory { * * @return A file ingest module instance. */ - default DataArtifactIngestModule createDataArtifactIngestModule(IngestModuleIngestJobSettings settings) { - throw new UnsupportedOperationException(); - } +// default DataArtifactIngestModule createDataArtifactIngestModule(IngestModuleIngestJobSettings settings) { +// throw new UnsupportedOperationException(); +// } } diff --git a/Core/src/org/sleuthkit/autopsy/ingest/IngestModuleTemplate.java b/Core/src/org/sleuthkit/autopsy/ingest/IngestModuleTemplate.java index 26285f6439..0bb947c1cd 100644 --- a/Core/src/org/sleuthkit/autopsy/ingest/IngestModuleTemplate.java +++ b/Core/src/org/sleuthkit/autopsy/ingest/IngestModuleTemplate.java @@ -85,13 +85,13 @@ public final class IngestModuleTemplate { return moduleFactory.createFileIngestModule(settings); } - public boolean isDataArtifactIngestModuleTemplate() { - return moduleFactory.isDataArtifactIngestModuleFactory(); - } +// public boolean isDataArtifactIngestModuleTemplate() { +// return moduleFactory.isDataArtifactIngestModuleFactory(); +// } - public DataArtifactIngestModule createDataArtifactIngestModule() { - return moduleFactory.createDataArtifactIngestModule(settings); - } +// public DataArtifactIngestModule createDataArtifactIngestModule() { +// return moduleFactory.createDataArtifactIngestModule(settings); +// } public void setEnabled(boolean enabled) { this.enabled = enabled; From 37e4b4a6d87ea7c941af7c3ae09524d571155c0d Mon Sep 17 00:00:00 2001 From: Mark McKinnon Date: Thu, 9 Sep 2021 09:50:18 -0400 Subject: [PATCH 10/10] Update shellbags_xp.pl Fix output of characters for shellbags_xp --- thirdparty/rr-full/plugins/shellbags_xp.pl | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/thirdparty/rr-full/plugins/shellbags_xp.pl b/thirdparty/rr-full/plugins/shellbags_xp.pl index 4eaea3e58d..25082ea89b 100644 --- a/thirdparty/rr-full/plugins/shellbags_xp.pl +++ b/thirdparty/rr-full/plugins/shellbags_xp.pl @@ -37,9 +37,6 @@ package shellbags_xp; use strict; use Time::Local; -require 'shellitems.pl'; - - my %config = (hive => "NTUSER\.DAT", hivemask => 32, output => "report", @@ -779,13 +776,13 @@ sub parseFolderEntry { $str = substr($data,$ofs,length($data) - 30); my $longname = (split(/\x00\x00/,$str,2))[0]; - $longname =~ s/\x00//g; - + $longname = $longname.chr 0x00; + if ($longname ne "") { $item{name} = Utf16ToUtf8($longname); } else { - $item{name} = _Utf16ToUtf8($shortname); + $item{name} = Utf16ToUtf8($shortname); } return %item; } @@ -934,5 +931,14 @@ sub printData { return @display; } +#--------------------------------------------------------------------- +# Utf16ToUtf8() +#--------------------------------------------------------------------- +sub Utf16ToUtf8 { + my $str = $_[0]; + Encode::from_to($str,'UTF-16LE','utf8'); + my $str2 = Encode::decode_utf8($str); + return $str; +} 1;