diff --git a/Core/src/org/sleuthkit/autopsy/contentviewers/contextviewer/Bundle.properties-MERGED b/Core/src/org/sleuthkit/autopsy/contentviewers/contextviewer/Bundle.properties-MERGED index c8cebe69fc..06646d7070 100755 --- a/Core/src/org/sleuthkit/autopsy/contentviewers/contextviewer/Bundle.properties-MERGED +++ b/Core/src/org/sleuthkit/autopsy/contentviewers/contextviewer/Bundle.properties-MERGED @@ -16,8 +16,14 @@ ContextViewer.message=Message ContextViewer.messageFrom=From ContextViewer.messageOn=On ContextViewer.messageTo=To +ContextViewer.networkOn=Network Traffic +ContextViewer.networkUnknown=Network Traffic at unknown time +ContextViewer.networkUsage=Network Usage ContextViewer.on=Opened at +ContextViewer.programExecution=Program Execution: ContextViewer.recentDocs=Recent Documents: +ContextViewer.runOn=Program Run On +ContextViewer.runUnknown=\ Program Run at unknown time ContextViewer.title=Context ContextViewer.toolTip=Displays context for selected file. ContextViewer.unknown=Opened at unknown time diff --git a/Core/src/org/sleuthkit/autopsy/contentviewers/contextviewer/ContextViewer.java b/Core/src/org/sleuthkit/autopsy/contentviewers/contextviewer/ContextViewer.java index f6d7e8f366..7eb25144d3 100644 --- a/Core/src/org/sleuthkit/autopsy/contentviewers/contextviewer/ContextViewer.java +++ b/Core/src/org/sleuthkit/autopsy/contentviewers/contextviewer/ContextViewer.java @@ -53,7 +53,12 @@ public final class ContextViewer extends javax.swing.JPanel implements DataConte private static final Logger logger = Logger.getLogger(ContextViewer.class.getName()); private static final int ARTIFACT_STR_MAX_LEN = 1024; private static final int ATTRIBUTE_STR_MAX_LEN = 200; - + + // Defines artifacts that are not defined in Blackboard Artifact + private static final String NETWORK_USAGE_ARTIFACT_NAME = "RA_SRU_NETWORK_USAGE"; //NON-NLS + private static final String APPLICATION_RESOURCE_ARTIFACT_NAME = "RA_SRU_APPLICATION_RESOURCE"; //NON-NLS + + // defines a list of artifacts that provide context for a file private static final List SOURCE_CONTEXT_ARTIFACTS = new ArrayList<>(); private final List contextSourcePanels = new ArrayList<>(); @@ -334,7 +339,9 @@ public final class ContextViewer extends javax.swing.JPanel implements DataConte @NbBundle.Messages({ "ContextViewer.attachmentSource=Attached to: ", "ContextViewer.downloadSource=Downloaded from: ", - "ContextViewer.recentDocs=Recent Documents: " + "ContextViewer.recentDocs=Recent Documents: ", + "ContextViewer.programExecution=Program Execution: ", + "ContextViewer.networkUsage=Network Usage" }) private void setSourceFields(BlackboardArtifact associatedArtifact) throws TskCoreException { if (BlackboardArtifact.ARTIFACT_TYPE.TSK_MESSAGE.getTypeID() == associatedArtifact.getArtifactTypeID() @@ -357,6 +364,19 @@ public final class ContextViewer extends javax.swing.JPanel implements DataConte javax.swing.JPanel usagePanel = new ContextUsagePanel(sourceName, sourceText, associatedArtifact); contextUsagePanels.add(usagePanel); + } else if (BlackboardArtifact.ARTIFACT_TYPE.TSK_PROG_RUN.getTypeID() == associatedArtifact.getArtifactTypeID() + || Case.getCurrentCase().getSleuthkitCase().getArtifactType(APPLICATION_RESOURCE_ARTIFACT_NAME).getTypeID() == associatedArtifact.getArtifactTypeID()) { + String sourceName = Bundle.ContextViewer_programExecution(); + String sourceText = programExecArtifactToString(associatedArtifact); + javax.swing.JPanel usagePanel = new ContextUsagePanel(sourceName, sourceText, associatedArtifact); + contextUsagePanels.add(usagePanel); + + } else if (Case.getCurrentCase().getSleuthkitCase().getArtifactType(NETWORK_USAGE_ARTIFACT_NAME).getTypeID() == associatedArtifact.getArtifactTypeID()) { + String sourceName = Bundle.ContextViewer_networkUsage(); + String sourceText = networkUsageArtifactToString(associatedArtifact); + javax.swing.JPanel usagePanel = new ContextUsagePanel(sourceName, sourceText, associatedArtifact); + contextUsagePanels.add(usagePanel); + } } @@ -376,12 +396,17 @@ public final class ContextViewer extends javax.swing.JPanel implements DataConte }) private String webDownloadArtifactToString(BlackboardArtifact artifact) throws TskCoreException { StringBuilder sb = new StringBuilder(ARTIFACT_STR_MAX_LEN); - Map attributesMap = getAttributesMap(artifact); + Map attributesMap = getAttributesMap(artifact); + SleuthkitCase skCase = Case.getCurrentCase().getSleuthkitCase(); + BlackboardAttribute.Type urlType = skCase.getAttributeType(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_URL.getLabel()); + BlackboardAttribute.Type dateTimeCreatedType = skCase.getAttributeType(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_CREATED.getLabel()); + + if (BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD.getTypeID() == artifact.getArtifactTypeID() || BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_CACHE.getTypeID() == artifact.getArtifactTypeID()) { - appendAttributeString(sb, BlackboardAttribute.ATTRIBUTE_TYPE.TSK_URL, attributesMap, Bundle.ContextViewer_downloadURL()); - appendAttributeString(sb, BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_CREATED, attributesMap, Bundle.ContextViewer_downloadedOn()); + appendAttributeString(sb, urlType, attributesMap, Bundle.ContextViewer_downloadURL()); + appendAttributeString(sb, dateTimeCreatedType, attributesMap, Bundle.ContextViewer_downloadedOn()); } return sb.toString(); } @@ -402,13 +427,15 @@ public final class ContextViewer extends javax.swing.JPanel implements DataConte }) private String recentDocArtifactToString(BlackboardArtifact artifact) throws TskCoreException { StringBuilder sb = new StringBuilder(ARTIFACT_STR_MAX_LEN); - Map attributesMap = getAttributesMap(artifact); - - BlackboardAttribute attribute = attributesMap.get(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME); + Map attributesMap = getAttributesMap(artifact); + SleuthkitCase skCase = Case.getCurrentCase().getSleuthkitCase(); + BlackboardAttribute.Type dateTimeType = skCase.getAttributeType(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME.getLabel()); + BlackboardAttribute attribute = attributesMap.get(dateTimeType); + if (BlackboardArtifact.ARTIFACT_TYPE.TSK_RECENT_OBJECT.getTypeID() == artifact.getArtifactTypeID()) { if (attribute.getValueLong() > 0) { - appendAttributeString(sb, BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME, attributesMap, Bundle.ContextViewer_on()); + appendAttributeString(sb, dateTimeType, attributesMap, Bundle.ContextViewer_on()); } else { sb.append(Bundle.ContextViewer_unknown()); } @@ -416,6 +443,72 @@ public final class ContextViewer extends javax.swing.JPanel implements DataConte return sb.toString(); } + /** + * Returns a display string with Program Execution + * artifact. + * + * @param artifact artifact to get doc from. + * + * @return Display string with download URL and date/time. + * + * @throws TskCoreException + */ + @NbBundle.Messages({ + "ContextViewer.runOn=Program Run On", + "ContextViewer.runUnknown= Program Run at unknown time" + }) + private String programExecArtifactToString(BlackboardArtifact artifact) throws TskCoreException { + StringBuilder sb = new StringBuilder(ARTIFACT_STR_MAX_LEN); + Map attributesMap = getAttributesMap(artifact); + + SleuthkitCase skCase = Case.getCurrentCase().getSleuthkitCase(); + BlackboardAttribute.Type dateTimeType = skCase.getAttributeType(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME.getLabel()); + + BlackboardAttribute attribute = attributesMap.get(dateTimeType); + + if (BlackboardArtifact.ARTIFACT_TYPE.TSK_PROG_RUN.getTypeID() == artifact.getArtifactTypeID() + || Case.getCurrentCase().getSleuthkitCase().getArtifactType(APPLICATION_RESOURCE_ARTIFACT_NAME).getTypeID() == artifact.getArtifactTypeID()) { + if (attribute != null && attribute.getValueLong() > 0) { + appendAttributeString(sb, dateTimeType, attributesMap, Bundle.ContextViewer_runOn()); + } else { + sb.append(Bundle.ContextViewer_runUnknown()); + } + } + return sb.toString(); + } + + /** + * Returns a display string with Network Usage + * artifact. + * + * @param artifact artifact to get doc from. + * + * @return Display string with download URL and date/time. + * + * @throws TskCoreException + */ + @NbBundle.Messages({ + "ContextViewer.networkOn=Network Traffic", + "ContextViewer.networkUnknown=Network Traffic at unknown time" + }) + private String networkUsageArtifactToString(BlackboardArtifact artifact) throws TskCoreException { + StringBuilder sb = new StringBuilder(ARTIFACT_STR_MAX_LEN); + Map attributesMap = getAttributesMap(artifact); + + SleuthkitCase skCase = Case.getCurrentCase().getSleuthkitCase(); + BlackboardAttribute.Type dateTimeType = skCase.getAttributeType(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME.getLabel()); + + BlackboardAttribute attribute = attributesMap.get(dateTimeType); + + if (Case.getCurrentCase().getSleuthkitCase().getArtifactType(NETWORK_USAGE_ARTIFACT_NAME).getTypeID() == artifact.getArtifactTypeID()) { + if (attribute != null && attribute.getValueLong() > 0) { + appendAttributeString(sb, dateTimeType, attributesMap, Bundle.ContextViewer_networkOn()); + } else { + sb.append(Bundle.ContextViewer_networkUnknown()); + } + } + return sb.toString(); + } /** * Returns a abbreviated display string for a message artifact. * @@ -434,18 +527,27 @@ public final class ContextViewer extends javax.swing.JPanel implements DataConte private String msgArtifactToAbbreviatedString(BlackboardArtifact artifact) throws TskCoreException { StringBuilder sb = new StringBuilder(ARTIFACT_STR_MAX_LEN); - Map attributesMap = getAttributesMap(artifact); + Map attributesMap = getAttributesMap(artifact); + + SleuthkitCase skCase = Case.getCurrentCase().getSleuthkitCase(); + BlackboardAttribute.Type dateTimeType = skCase.getAttributeType(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME.getLabel()); + BlackboardAttribute.Type phoneNumberFromType = skCase.getAttributeType(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PHONE_NUMBER_FROM.getLabel()); + BlackboardAttribute.Type phoneNumberToType = skCase.getAttributeType(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PHONE_NUMBER_TO.getLabel()); + BlackboardAttribute.Type emailFromType = skCase.getAttributeType(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_EMAIL_FROM.getLabel()); + BlackboardAttribute.Type emailToType = skCase.getAttributeType(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_EMAIL_TO.getLabel()); + BlackboardAttribute.Type dateTimeSentType = skCase.getAttributeType(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_SENT.getLabel()); + if (BlackboardArtifact.ARTIFACT_TYPE.TSK_MESSAGE.getTypeID() == artifact.getArtifactTypeID()) { sb.append(Bundle.ContextViewer_message()).append(' '); - appendAttributeString(sb, BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PHONE_NUMBER_FROM, attributesMap, Bundle.ContextViewer_messageFrom()); - appendAttributeString(sb, BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PHONE_NUMBER_TO, attributesMap, Bundle.ContextViewer_messageTo()); - appendAttributeString(sb, BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME, attributesMap, Bundle.ContextViewer_messageOn()); + appendAttributeString(sb, phoneNumberFromType, attributesMap, Bundle.ContextViewer_messageFrom()); + appendAttributeString(sb, phoneNumberToType, attributesMap, Bundle.ContextViewer_messageTo()); + appendAttributeString(sb, dateTimeType, attributesMap, Bundle.ContextViewer_messageOn()); } else if (BlackboardArtifact.ARTIFACT_TYPE.TSK_EMAIL_MSG.getTypeID() == artifact.getArtifactTypeID()) { sb.append(Bundle.ContextViewer_email()).append(' '); - appendAttributeString(sb, BlackboardAttribute.ATTRIBUTE_TYPE.TSK_EMAIL_FROM, attributesMap, Bundle.ContextViewer_messageFrom()); - appendAttributeString(sb, BlackboardAttribute.ATTRIBUTE_TYPE.TSK_EMAIL_TO, attributesMap, Bundle.ContextViewer_messageTo()); - appendAttributeString(sb, BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_SENT, attributesMap, Bundle.ContextViewer_messageOn()); + appendAttributeString(sb, emailFromType, attributesMap, Bundle.ContextViewer_messageFrom()); + appendAttributeString(sb, emailToType, attributesMap, Bundle.ContextViewer_messageTo()); + appendAttributeString(sb, dateTimeSentType, attributesMap, Bundle.ContextViewer_messageOn()); } return sb.toString(); } @@ -460,8 +562,8 @@ public final class ContextViewer extends javax.swing.JPanel implements DataConte * @param prependStr Optional string that is prepended before the * attribute value. */ - private void appendAttributeString(StringBuilder sb, BlackboardAttribute.ATTRIBUTE_TYPE attribType, - Map attributesMap, String prependStr) { + private void appendAttributeString(StringBuilder sb, BlackboardAttribute.Type attribType, + Map attributesMap, String prependStr) { BlackboardAttribute attribute = attributesMap.get(attribType); if (attribute != null) { @@ -485,12 +587,15 @@ public final class ContextViewer extends javax.swing.JPanel implements DataConte * * @throws TskCoreException */ - private Map getAttributesMap(BlackboardArtifact artifact) throws TskCoreException { - Map attributeMap = new HashMap<>(); + private Map getAttributesMap(BlackboardArtifact artifact) throws TskCoreException { + SleuthkitCase skCase = Case.getCurrentCase().getSleuthkitCase(); + + Map attributeMap = new HashMap<>(); List attributeList = artifact.getAttributes(); for (BlackboardAttribute attribute : attributeList) { - BlackboardAttribute.ATTRIBUTE_TYPE type = BlackboardAttribute.ATTRIBUTE_TYPE.fromID(attribute.getAttributeType().getTypeID()); + BlackboardAttribute.Type type = skCase.getAttributeType(attribute.getAttributeType().getTypeName()); +// BlackboardAttribute.ATTRIBUTE_TYPE type = BlackboardAttribute.ATTRIBUTE_TYPE.fromID(attribute.getAttributeType().getTypeID()); attributeMap.put(type, attribute); } diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/ExtractSru.java b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/ExtractSru.java index b6d8542dff..f83182898d 100644 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/ExtractSru.java +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/ExtractSru.java @@ -66,8 +66,7 @@ final class ExtractSru extends Extract { private IngestJobContext context; - private static final String APPLICATION_EXECUTION_ARTIFACT_NAME = "TSK_APPLICATION_EXECUTION"; //NON-NLS - private static final String NETWORK_USAGE_ARTIFACT_NAME = "RA_SRU_NETWORK_USAGE_BIN"; //NON-NLS + private static final String NETWORK_USAGE_ARTIFACT_NAME = "RA_SRU_NETWORK_USAGE"; //NON-NLS private static final String APPLICATION_RESOURCE_ARTIFACT_NAME = "RA_SRU_APPLICATION_RESOURCE"; //NON-NLS private static final String NETWORK_PROFILE_NAME_ATTRIBUTE_NAME = "RA_SRU_NETWORK_PROFILE_NAME"; //NON-NLS @@ -102,7 +101,7 @@ final class ExtractSru extends Extract { try { createSruArtifactType(); } catch (TskCoreException ex) { - logger.log(Level.WARNING, String.format("%s, %s or $s may not have been created.", APPLICATION_EXECUTION_ARTIFACT_NAME, NETWORK_USAGE_ARTIFACT_NAME, APPLICATION_RESOURCE_ARTIFACT_NAME), ex); + logger.log(Level.WARNING, String.format("%s or $s may not have been created.", NETWORK_USAGE_ARTIFACT_NAME, APPLICATION_RESOURCE_ARTIFACT_NAME), ex); } FileManager fileManager = Case.getCurrentCase().getServices().getFileManager(); @@ -271,14 +270,14 @@ final class ExtractSru extends Extract { String filePath = FilenameUtils.getPath(normalizePathName); if (fileName.contains(" [")) { fileName = fileName.substring(0, fileName.indexOf(" [")); - fileName.trim(); } + fileName.trim(); List sourceFiles; try { sourceFiles = fileManager.findFiles(dataSource, fileName, filePath); //NON-NLS for (AbstractFile sourceFile : sourceFiles) { if (sourceFile.getParentPath().endsWith(filePath)) { - applicationFilesFound.put(sourceName, sourceFile); + applicationFilesFound.put(sourceName.toLowerCase(), sourceFile); } } @@ -354,7 +353,7 @@ final class ExtractSru extends Extract { BlackboardArtifact bbart = sruAbstractFile.newArtifact(artifactType.getTypeID()); bbart.addAttributes(bbattributes); bba.add(bbart); - BlackboardArtifact associateBbArtifact = createAssociatedArtifact(applicationName, bbart); + BlackboardArtifact associateBbArtifact = createAssociatedArtifact(applicationName.toLowerCase(), bbart); if (associateBbArtifact != null) { bba.add(associateBbArtifact); } @@ -431,7 +430,7 @@ final class ExtractSru extends Extract { BlackboardArtifact bbart = sruAbstractFile.newArtifact(artifactType.getTypeID()); bbart.addAttributes(bbattributes); bba.add(bbart); - BlackboardArtifact associateBbArtifact = createAssociatedArtifact(applicationName, bbart); + BlackboardArtifact associateBbArtifact = createAssociatedArtifact(applicationName.toLowerCase(), bbart); if (associateBbArtifact != null) { bba.add(associateBbArtifact); } @@ -484,11 +483,6 @@ final class ExtractSru extends Extract { */ private void createSruArtifactType() throws TskCoreException { - try { - tskCase.addBlackboardArtifactType(APPLICATION_EXECUTION_ARTIFACT_NAME, "Application Execution"); //NON-NLS - } catch (TskDataException ex) { - logger.log(Level.INFO, String.format("%s may have already been defined for this case", APPLICATION_EXECUTION_ARTIFACT_NAME)); - } try { tskCase.addBlackboardArtifactType(NETWORK_USAGE_ARTIFACT_NAME, "SRU Network Usage"); //NON-NLS } catch (TskDataException ex) {