From 595eefaa6fc0c0c54fefb3fdc0346dd91e2bb87d Mon Sep 17 00:00:00 2001 From: millmanorama Date: Mon, 13 Aug 2018 14:35:42 +0200 Subject: [PATCH] cleanup FirefoxExtractor and fix it for new approach. --- .../recentactivity/ChromeExtractor.java | 222 +++++---- .../autopsy/recentactivity/Extractor.java | 74 ++- .../recentactivity/FirefoxExtractor.java | 456 +++++++++--------- .../autopsy/recentactivity/IEExtractor.java | 10 +- .../RecentDocumentsLnkExtractor.java | 3 +- .../recentactivity/RegistryExtractor.java | 25 +- .../SearchEngineURLQueryAnalyzer.java | 3 +- 7 files changed, 420 insertions(+), 373 deletions(-) diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/ChromeExtractor.java b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/ChromeExtractor.java index 3d908b79db..d83eb296fc 100644 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/ChromeExtractor.java +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/ChromeExtractor.java @@ -40,11 +40,11 @@ import org.sleuthkit.autopsy.casemodule.services.FileManager; import org.sleuthkit.autopsy.coreutils.Logger; import org.sleuthkit.autopsy.datamodel.ContentUtils; import org.sleuthkit.autopsy.ingest.IngestJobContext; -import org.sleuthkit.autopsy.ingest.IngestServices; -import org.sleuthkit.autopsy.ingest.ModuleDataEvent; import org.sleuthkit.datamodel.AbstractFile; +import org.sleuthkit.datamodel.Blackboard; import org.sleuthkit.datamodel.BlackboardArtifact; import org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE; +import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_OS_ACCOUNT; import org.sleuthkit.datamodel.BlackboardAttribute; import org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE; import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME; @@ -68,7 +68,7 @@ import org.sleuthkit.datamodel.TskData; /** * Chrome recent activity extraction */ -class ChromeExtractor extends Extractor { +final class ChromeExtractor extends Extractor { private static final Logger logger = Logger.getLogger(ChromeExtractor.class.getName()); private static final String PARENT_MODULE_NAME = NbBundle.getMessage(ChromeExtractor.class, "Chrome.parentModuleName"); @@ -83,6 +83,7 @@ class ChromeExtractor extends Extractor { private Content dataSource; private IngestJobContext context; + private FileManager fileManager; @Override protected String getModuleName() { @@ -104,13 +105,15 @@ class ChromeExtractor extends Extractor { /** * Query for history databases and add artifacts */ - private void getHistory() throws TskCoreException { - FileManager fileManager = currentCase.getServices().getFileManager(); + @NbBundle.Messages({"# {0} - Extractor / program name", + "Extractor.errPostingArtifacts={0}:Error while trying to post artifacts."}) + private void getHistory() { + List historyFiles; try { historyFiles = fileManager.findFiles(dataSource, "History", "Chrome"); //NON-NLS } catch (TskCoreException ex) { - String msg = NbBundle.getMessage(this.getClass(), "Chrome.getHistory.errMsg.errGettingFiles"); + String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getHistory.errMsg.errGettingFiles"); logger.log(Level.SEVERE, msg, ex); this.addErrorMessage(this.getModuleName() + ": " + msg); return; @@ -126,7 +129,7 @@ class ChromeExtractor extends Extractor { // log a message if we don't have any allocated history files if (allocatedHistoryFiles.isEmpty()) { - String msg = NbBundle.getMessage(this.getClass(), "Chrome.getHistory.errMsg.couldntFindAnyFiles"); + String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getHistory.errMsg.couldntFindAnyFiles"); logger.log(Level.INFO, msg); return; } @@ -146,13 +149,13 @@ class ChromeExtractor extends Extractor { } catch (ReadContentInputStreamException ex) { logger.log(Level.WARNING, String.format("Error reading Chrome web history artifacts file '%s' (id=%d).", historyFile.getName(), historyFile.getId()), ex); //NON-NLS - this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getHistory.errMsg.errAnalyzingFile", + this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getHistory.errMsg.errAnalyzingFile", this.getModuleName(), historyFile.getName())); continue; } catch (IOException ex) { logger.log(Level.SEVERE, String.format("Error writing temp sqlite db file '%s' for Chrome web history artifacts file '%s' (id=%d).", temps, historyFile.getName(), historyFile.getId()), ex); //NON-NLS - this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getHistory.errMsg.errAnalyzingFile", + this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getHistory.errMsg.errAnalyzingFile", this.getModuleName(), historyFile.getName())); continue; } @@ -183,26 +186,36 @@ class ChromeExtractor extends Extractor { new BlackboardAttribute( TSK_DOMAIN, PARENT_MODULE_NAME, Util.extractDomain(Objects.toString(result.get("url"), "")))); //NON-NLS - bbartifacts.add(this.addArtifact(ARTIFACT_TYPE.TSK_WEB_HISTORY, historyFile, bbattributes)); + try { + BlackboardArtifact bbart = historyFile.newArtifact(ARTIFACT_TYPE.TSK_WEB_HISTORY); + bbart.addAttributes(bbattributes); + bbartifacts.add(bbart); + } catch (TskCoreException ex) { + logger.log(Level.SEVERE, "Error while trying to create Chrome history artifact.", ex); //NON-NLS + this.addErrorMessage( + NbBundle.getMessage(ChromeExtractor.class, "Chrome.getHistory.errMsg.errAnalyzingFile", + this.getModuleName(), historyFile.getName())); + } } dbFile.delete(); } - - IngestServices.getInstance().fireModuleDataEvent(new ModuleDataEvent( - PARENT_MODULE_NAME, - BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY, bbartifacts)); + try { + blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME); + } catch (Blackboard.BlackboardException ex) { + logger.log(Level.SEVERE, "Error while trying to post Chrome history artifact.", ex); //NON-NLS + this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName())); + } } /** * Search for bookmark files and make artifacts. */ private void getBookmark() { - FileManager fileManager = currentCase.getServices().getFileManager(); List bookmarkFiles; try { bookmarkFiles = fileManager.findFiles(dataSource, "Bookmarks", "Chrome"); //NON-NLS } catch (TskCoreException ex) { - String msg = NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errGettingFiles"); + String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errGettingFiles"); logger.log(Level.SEVERE, msg, ex); this.addErrorMessage(this.getModuleName() + ": " + msg); return; @@ -215,25 +228,25 @@ class ChromeExtractor extends Extractor { dataFound = true; Collection bbartifacts = new ArrayList<>(); - int j = 0; - while (j < bookmarkFiles.size()) { - AbstractFile bookmarkFile = bookmarkFiles.get(j++); + int index = 0; + while (index < bookmarkFiles.size()) { + AbstractFile bookmarkFile = bookmarkFiles.get(index++); if (bookmarkFile.getSize() == 0) { continue; } - String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + bookmarkFile.getName() + j + ".db"; //NON-NLS + String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + bookmarkFile.getName() + index + ".db"; //NON-NLS try { ContentUtils.writeToFile(bookmarkFile, new File(temps), context::dataSourceIngestIsCancelled); } catch (ReadContentInputStreamException ex) { logger.log(Level.WARNING, String.format("Error reading Chrome bookmark artifacts file '%s' (id=%d).", bookmarkFile.getName(), bookmarkFile.getId()), ex); //NON-NLS - this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errAnalyzingFile", + this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errAnalyzingFile", this.getModuleName(), bookmarkFile.getName())); continue; } catch (IOException ex) { logger.log(Level.SEVERE, String.format("Error writing temp sqlite db file '%s' for Chrome bookmark artifacts file '%s' (id=%d).", temps, bookmarkFile.getName(), bookmarkFile.getId()), ex); //NON-NLS - this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errAnalyzingFile", + this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errAnalyzingFile", this.getModuleName(), bookmarkFile.getName())); continue; } @@ -251,7 +264,7 @@ class ChromeExtractor extends Extractor { } catch (FileNotFoundException ex) { logger.log(Level.SEVERE, "Error while trying to read into the Bookmarks for Chrome.", ex); //NON-NLS this.addErrorMessage( - NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errAnalyzeFile", this.getModuleName(), + NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errAnalyzeFile", this.getModuleName(), bookmarkFile.getName())); continue; } @@ -269,7 +282,7 @@ class ChromeExtractor extends Extractor { jBookmarkArray = jBookmark.getAsJsonArray("children"); //NON-NLS } catch (JsonIOException | JsonSyntaxException | IllegalStateException ex) { logger.log(Level.WARNING, "Error parsing Json from Chrome Bookmark.", ex); //NON-NLS - this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errAnalyzingFile3", + this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errAnalyzingFile3", this.getModuleName(), bookmarkFile.getName())); continue; } @@ -302,10 +315,10 @@ class ChromeExtractor extends Extractor { } String domain = Util.extractDomain(url); try { - - Collection bbattributes = Arrays.asList(new BlackboardAttribute( - TSK_URL, PARENT_MODULE_NAME, - url), + Collection bbattributes = Arrays.asList( + new BlackboardAttribute( + TSK_URL, PARENT_MODULE_NAME, + url), new BlackboardAttribute( TSK_TITLE, PARENT_MODULE_NAME, name), @@ -318,34 +331,35 @@ class ChromeExtractor extends Extractor { new BlackboardAttribute( TSK_DOMAIN, PARENT_MODULE_NAME, domain)); - - bbartifacts.add(this.addArtifact(ARTIFACT_TYPE.TSK_WEB_BOOKMARK, bookmarkFile, bbattributes)); + BlackboardArtifact bbart = bookmarkFile.newArtifact(ARTIFACT_TYPE.TSK_WEB_BOOKMARK); + bbart.addAttributes(bbattributes); + bbartifacts.add(bbart); } catch (TskCoreException ex) { - logger.log(Level.SEVERE, "Error while trying to insert Chrome bookmark artifact{0}", ex); //NON-NLS + logger.log(Level.SEVERE, "Error while trying to insert Chrome bookmark artifact.", ex); //NON-NLS this.addErrorMessage( - NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errAnalyzingFile4", + NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errAnalyzingFile4", this.getModuleName(), bookmarkFile.getName())); } } dbFile.delete(); } - - IngestServices.getInstance().fireModuleDataEvent(new ModuleDataEvent( - PARENT_MODULE_NAME, - BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_BOOKMARK, bbartifacts)); + try { + blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME); + } catch (Blackboard.BlackboardException ex) { + logger.log(Level.SEVERE, "Error while trying to post Chrome bookmark artifact{0}", ex); //NON-NLS + this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName())); + } } /** * Queries for cookie files and adds artifacts */ - private void getCookie() throws TskCoreException { - - FileManager fileManager = currentCase.getServices().getFileManager(); + private void getCookie() { List cookiesFiles; try { cookiesFiles = fileManager.findFiles(dataSource, "Cookies", "Chrome"); //NON-NLS } catch (TskCoreException ex) { - String msg = NbBundle.getMessage(this.getClass(), "Chrome.getCookie.errMsg.errGettingFiles"); + String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getCookie.errMsg.errGettingFiles"); logger.log(Level.SEVERE, msg, ex); this.addErrorMessage(this.getModuleName() + ": " + msg); return; @@ -358,25 +372,25 @@ class ChromeExtractor extends Extractor { dataFound = true; Collection bbartifacts = new ArrayList<>(); - int j = 0; - while (j < cookiesFiles.size()) { - AbstractFile cookiesFile = cookiesFiles.get(j++); + int index = 0; + while (index < cookiesFiles.size()) { + AbstractFile cookiesFile = cookiesFiles.get(index++); if (cookiesFile.getSize() == 0) { continue; } - String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + cookiesFile.getName() + j + ".db"; //NON-NLS + String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + cookiesFile.getName() + index + ".db"; //NON-NLS try { ContentUtils.writeToFile(cookiesFile, new File(temps), context::dataSourceIngestIsCancelled); } catch (ReadContentInputStreamException ex) { logger.log(Level.WARNING, String.format("Error reading Chrome cookie artifacts file '%s' (id=%d).", cookiesFile.getName(), cookiesFile.getId()), ex); //NON-NLS - this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getCookie.errMsg.errAnalyzeFile", + this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getCookie.errMsg.errAnalyzeFile", this.getModuleName(), cookiesFile.getName())); continue; } catch (IOException ex) { logger.log(Level.SEVERE, String.format("Error writing temp sqlite db file '%s' for Chrome cookie artifacts file '%s' (id=%d).", temps, cookiesFile.getName(), cookiesFile.getId()), ex); //NON-NLS - this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getCookie.errMsg.errAnalyzeFile", + this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getCookie.errMsg.errAnalyzeFile", this.getModuleName(), cookiesFile.getName())); continue; } @@ -409,27 +423,37 @@ class ChromeExtractor extends Extractor { new BlackboardAttribute( TSK_PROG_NAME, PARENT_MODULE_NAME, getModuleName())); - bbartifacts.add(this.addArtifact(ARTIFACT_TYPE.TSK_WEB_COOKIE, cookiesFile, bbattributes)); + try { + BlackboardArtifact bbart = cookiesFile.newArtifact(ARTIFACT_TYPE.TSK_WEB_COOKIE); + bbart.addAttributes(bbattributes); + bbartifacts.add(bbart); + } catch (TskCoreException ex) { + logger.log(Level.SEVERE, "Error while trying to insert Chrome cookie artifact.", ex); //NON-NLS + this.addErrorMessage( + NbBundle.getMessage(ChromeExtractor.class, "Chrome.getCookie.errMsg.errAnalyzingFile", + this.getModuleName(), cookiesFile.getName())); + } } dbFile.delete(); } - - IngestServices.getInstance().fireModuleDataEvent(new ModuleDataEvent( - PARENT_MODULE_NAME, - BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE, bbartifacts)); + try { + blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME); + } catch (Blackboard.BlackboardException ex) { + logger.log(Level.SEVERE, "Error while trying to post Chrome cookie artifact.", ex); //NON-NLS + this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName())); + } } /** * Queries for download files and adds artifacts */ - private void getDownload() throws TskCoreException { - FileManager fileManager = currentCase.getServices().getFileManager(); + private void getDownload() { List downloadFiles; try { downloadFiles = fileManager.findFiles(dataSource, "History", "Chrome"); //NON-NLS } catch (TskCoreException ex) { - String msg = NbBundle.getMessage(this.getClass(), "Chrome.getDownload.errMsg.errGettingFiles"); + String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getDownload.errMsg.errGettingFiles"); logger.log(Level.SEVERE, msg, ex); this.addErrorMessage(this.getModuleName() + ": " + msg); return; @@ -442,25 +466,25 @@ class ChromeExtractor extends Extractor { dataFound = true; Collection bbartifacts = new ArrayList<>(); - int j = 0; - while (j < downloadFiles.size()) { - AbstractFile downloadFile = downloadFiles.get(j++); + int index = 0; + while (index < downloadFiles.size()) { + AbstractFile downloadFile = downloadFiles.get(index++); if (downloadFile.getSize() == 0) { continue; } - String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + downloadFile.getName() + j + ".db"; //NON-NLS + String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + downloadFile.getName() + index + ".db"; //NON-NLS try { ContentUtils.writeToFile(downloadFile, new File(temps), context::dataSourceIngestIsCancelled); } catch (ReadContentInputStreamException ex) { logger.log(Level.WARNING, String.format("Error reading Chrome download artifacts file '%s' (id=%d).", downloadFile.getName(), downloadFile.getId()), ex); //NON-NLS - this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getDownload.errMsg.errAnalyzeFiles1", + this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getDownload.errMsg.errAnalyzeFiles1", this.getModuleName(), downloadFile.getName())); continue; } catch (IOException ex) { logger.log(Level.SEVERE, String.format("Error writing temp sqlite db file '%s' for Chrome download artifacts file '%s' (id=%d).", temps, downloadFile.getName(), downloadFile.getId()), ex); //NON-NLS - this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getDownload.errMsg.errAnalyzeFiles1", + this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getDownload.errMsg.errAnalyzeFiles1", this.getModuleName(), downloadFile.getName())); continue; } @@ -497,30 +521,37 @@ class ChromeExtractor extends Extractor { if (pathID != -1) { bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PATH_ID, PARENT_MODULE_NAME, pathID)); } - BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, downloadFile, bbattributes); - if (bbart != null) { + try { + BlackboardArtifact bbart = downloadFile.newArtifact(ARTIFACT_TYPE.TSK_WEB_DOWNLOAD); + bbart.addAttributes(bbattributes); bbartifacts.add(bbart); + } catch (TskCoreException ex) { + logger.log(Level.SEVERE, "Error while trying to insert Chrome download artifact.", ex); //NON-NLS + this.addErrorMessage( + NbBundle.getMessage(ChromeExtractor.class, "Chrome.getDownload.errMsg.errAnalyzeFiles1", + this.getModuleName(), downloadFile.getName())); } } dbFile.delete(); } - - IngestServices.getInstance().fireModuleDataEvent(new ModuleDataEvent( - PARENT_MODULE_NAME, - BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, bbartifacts)); + try { + blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME); + } catch (Blackboard.BlackboardException ex) { + logger.log(Level.SEVERE, "Error while trying to post Chrome download artifact.", ex); //NON-NLS + this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName())); + } } /** * Queries for login files and adds artifacts */ - private void getLogin() throws TskCoreException, TskCoreException { - FileManager fileManager = currentCase.getServices().getFileManager(); + private void getLogin() { List signonFiles; try { signonFiles = fileManager.findFiles(dataSource, "signons.sqlite", "Chrome"); //NON-NLS } catch (TskCoreException ex) { - String msg = NbBundle.getMessage(this.getClass(), "Chrome.getLogin.errMsg.errGettingFiles"); + String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getLogin.errMsg.errGettingFiles"); logger.log(Level.SEVERE, msg, ex); this.addErrorMessage(this.getModuleName() + ": " + msg); return; @@ -533,25 +564,25 @@ class ChromeExtractor extends Extractor { dataFound = true; Collection bbartifacts = new ArrayList<>(); - int j = 0; - while (j < signonFiles.size()) { - AbstractFile signonFile = signonFiles.get(j++); + int index = 0; + while (index < signonFiles.size()) { + AbstractFile signonFile = signonFiles.get(index++); if (signonFile.getSize() == 0) { continue; } - String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + signonFile.getName() + j + ".db"; //NON-NLS + String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + signonFile.getName() + index + ".db"; //NON-NLS try { ContentUtils.writeToFile(signonFile, new File(temps), context::dataSourceIngestIsCancelled); } catch (ReadContentInputStreamException ex) { logger.log(Level.WARNING, String.format("Error reading Chrome login artifacts file '%s' (id=%d).", signonFile.getName(), signonFile.getId()), ex); //NON-NLS - this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getLogin.errMsg.errAnalyzingFiles", + this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getLogin.errMsg.errAnalyzingFiles", this.getModuleName(), signonFile.getName())); continue; } catch (IOException ex) { logger.log(Level.SEVERE, String.format("Error writing temp sqlite db file '%s' for Chrome login artifacts file '%s' (id=%d).", temps, signonFile.getName(), signonFile.getId()), ex); //NON-NLS - this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getLogin.errMsg.errAnalyzingFiles", + this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getLogin.errMsg.errAnalyzingFiles", this.getModuleName(), signonFile.getName())); continue; } @@ -588,22 +619,47 @@ class ChromeExtractor extends Extractor { TSK_DOMAIN, PARENT_MODULE_NAME, Objects.toString(result.get("signon_realm"), ""))); //NON-NLS - bbartifacts.add(this.addArtifact(ARTIFACT_TYPE.TSK_WEB_HISTORY, signonFile, bbattributes)); + try { + BlackboardArtifact bbart = signonFile.newArtifact(ARTIFACT_TYPE.TSK_WEB_HISTORY); + bbart.addAttributes(bbattributes); + bbartifacts.add(bbart); + } catch (TskCoreException ex) { + logger.log(Level.SEVERE, "Error while trying to insert Chrome login artifact.", ex); //NON-NLS + this.addErrorMessage( + NbBundle.getMessage(ChromeExtractor.class, "Chrome.getLogin.errMsg.errAnalyzingFiles", + this.getModuleName(), signonFile.getName())); + } // Don't add TSK_OS_ACCOUNT artifacts to the ModuleDataEvent - //TODO: Why not? Because it has a different artifact type? - BlackboardAttribute osAcctAttribute = new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_USER_NAME, PARENT_MODULE_NAME, - Objects.toString(result.get("username_value"), "").replaceAll("'", "''")); //NON-NLS + //TODO: Why not? Because it has a different artifact type? We can just post it seperately? + try { + BlackboardAttribute osAcctAttribute = new BlackboardAttribute(TSK_USER_NAME, PARENT_MODULE_NAME, + Objects.toString(result.get("username_value"), "").replaceAll("'", "''")); //NON-NLS + BlackboardArtifact osAccountArtifact = signonFile.newArtifact(TSK_OS_ACCOUNT); + osAccountArtifact.addAttributes(Collections.singleton(osAcctAttribute)); - this.addArtifact(ARTIFACT_TYPE.TSK_OS_ACCOUNT, signonFile, Collections.singleton(osAcctAttribute)); + blackboard.postArtifact(osAccountArtifact, PARENT_MODULE_NAME); + + } catch (TskCoreException ex) { + logger.log(Level.SEVERE, "Error while trying to insert Chrome os account artifact.", ex); //NON-NLS + this.addErrorMessage( + NbBundle.getMessage(ChromeExtractor.class, "Chrome.getLogin.errMsg.errAnalyzingFiles", + this.getModuleName(), signonFile.getName())); + } catch (Blackboard.BlackboardException ex) { + logger.log(Level.SEVERE, "Error while trying to post Chrome os account artifact.", ex); //NON-NLS + this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName())); + } } dbFile.delete(); } - IngestServices.getInstance().fireModuleDataEvent(new ModuleDataEvent( - PARENT_MODULE_NAME, - BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY, bbartifacts)); + try { + blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME); + } catch (Blackboard.BlackboardException ex) { + logger.log(Level.SEVERE, "Error while trying to post Chrome login artifact.", ex); //NON-NLS + this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName())); + } } private boolean isChromePreVersion30(String temps) { diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Extractor.java b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Extractor.java index 1a32e2b57b..becead2723 100644 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Extractor.java +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Extractor.java @@ -31,8 +31,8 @@ import org.openide.util.NbBundle; import org.openide.util.NbBundle.Messages; import org.sleuthkit.autopsy.casemodule.Case; import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException; +import org.sleuthkit.autopsy.casemodule.services.FileManager; import org.sleuthkit.autopsy.coreutils.Logger; -import org.sleuthkit.autopsy.coreutils.MessageNotifyUtil; import org.sleuthkit.autopsy.coreutils.SQLiteDBConnect; import org.sleuthkit.autopsy.ingest.IngestJobContext; import org.sleuthkit.autopsy.ingest.IngestModule.IngestModuleException; @@ -44,6 +44,9 @@ abstract class Extractor { protected Case currentCase; protected SleuthkitCase tskCase; + protected Blackboard blackboard; + protected FileManager fileManager; + private final ArrayList errorMessages = new ArrayList<>(); boolean dataFound = false; @@ -54,11 +57,16 @@ abstract class Extractor { */ abstract protected String getModuleName(); + @Messages({"Extract.indexError.message=Failed to index artifact for keyword search.", + "Extract.noOpenCase.errMsg=No open case available."}) final void init() throws IngestModuleException { try { currentCase = Case.getCurrentCaseThrows(); tskCase = currentCase.getSleuthkitCase(); + blackboard = tskCase.getBlackboard(); + fileManager = currentCase.getServices().getFileManager(); } catch (NoCurrentCaseException ex) { + //TODO: fix this error message throw new IngestModuleException(Bundle.Extract_indexError_message(), ex); } configExtractor(); @@ -95,51 +103,25 @@ abstract class Extractor { errorMessages.add(message); } - /** - * Generic method for adding a blackboard artifact to the blackboard and - * indexing it - * - * @param type is a blackboard.artifact_type enum to determine which - * type the artifact should be - * @param content is the AbstractFile object that needs to have the - * artifact added for it - * @param bbattributes is the collection of blackboard attributes that need - * to be added to the artifact after the artifact has - * been created - * @return The newly-created artifact - * - * @throws org.sleuthkit.datamodel.TskCoreException If there was a problem - * creating the artifact. - */ - protected BlackboardArtifact addArtifact(BlackboardArtifact.ARTIFACT_TYPE type, AbstractFile content, Collection bbattributes) throws TskCoreException { - BlackboardArtifact bbart = content.newArtifact(type); - bbart.addAttributes(bbattributes); - // index the artifact for keyword search - this.indexArtifact(bbart); - return bbart; - } - - /** - * Method to index a blackboard artifact for keyword search - * - * @param bbart Blackboard artifact to be indexed - */ - @Messages({"Extract.indexError.message=Failed to index artifact for keyword search.", - "Extract.noOpenCase.errMsg=No open case available."}) - void indexArtifact(BlackboardArtifact bbart) { - try { - Blackboard blackboard = Case.getCurrentCaseThrows().getSleuthkitCase().getBlackboard(); - // index the artifact for keyword search - blackboard.postArtifact(bbart, getModuleName()); - } catch (Blackboard.BlackboardException ex) { - logger.log(Level.SEVERE, "Unable to index blackboard artifact " + bbart.getDisplayName(), ex); //NON-NLS - MessageNotifyUtil.Notify.error(Bundle.Extract_indexError_message(), bbart.getDisplayName()); - } catch (NoCurrentCaseException ex) { - logger.log(Level.SEVERE, "Exception while getting open case.", ex); //NON-NLS - MessageNotifyUtil.Notify.error(Bundle.Extract_noOpenCase_errMsg(), bbart.getDisplayName()); - } - } - +// +// /** +// * Method to index a blackboard artifact for keyword search +// * +// * @param bbart Blackboard artifact to be indexed +// */ +// +// void postArtifacts(Collections bbarts) throws Blackboard.BlackboardException { +// +// // index the artifact for keyword search +// blackboard.postArtifact(bbarts, getModuleName()); +//// } catch (Blackboard.BlackboardException ex) { +//// logger.log(Level.SEVERE, "Unable to index blackboard artifact " + bbart.getDisplayName(), ex); //NON-NLS +//// MessageNotifyUtil.Notify.error(Bundle.Extract_indexError_message(), bbart.getDisplayName()); +//// } catch (NoCurrentCaseException ex) { +//// logger.log(Level.SEVERE, "Exception while getting open case.", ex); //NON-NLS +//// MessageNotifyUtil.Notify.error(Bundle.Extract_noOpenCase_errMsg(), bbart.getDisplayName()); +//// } +// } /** * Returns a List from a result set based on sql query. This is used to * query sqlite databases storing user recent activity data, such as in diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/FirefoxExtractor.java b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/FirefoxExtractor.java index 8d09631e1b..13d3bc787e 100644 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/FirefoxExtractor.java +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/FirefoxExtractor.java @@ -22,27 +22,42 @@ */ package org.sleuthkit.autopsy.recentactivity; +import com.google.common.collect.Lists; import java.io.File; import java.io.IOException; import java.io.UnsupportedEncodingException; import java.net.URLDecoder; import java.util.ArrayList; +import java.util.Arrays; import java.util.Collection; import java.util.HashMap; import java.util.List; +import java.util.Objects; import java.util.logging.Level; import org.openide.util.NbBundle; -import org.sleuthkit.autopsy.casemodule.services.FileManager; import org.sleuthkit.autopsy.coreutils.Logger; import org.sleuthkit.autopsy.datamodel.ContentUtils; import org.sleuthkit.autopsy.ingest.IngestJobContext; -import org.sleuthkit.autopsy.ingest.IngestServices; -import org.sleuthkit.autopsy.ingest.ModuleDataEvent; import org.sleuthkit.datamodel.AbstractFile; +import org.sleuthkit.datamodel.Blackboard; import org.sleuthkit.datamodel.BlackboardArtifact; -import org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE; +import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_BOOKMARK; +import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE; +import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD; +import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY; import org.sleuthkit.datamodel.BlackboardAttribute; -import org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_CREATED; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DOMAIN; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_NAME; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PATH; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PATH_ID; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PROG_NAME; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_REFERRER; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_TITLE; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_URL; +import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_VALUE; import org.sleuthkit.datamodel.Content; import org.sleuthkit.datamodel.ReadContentInputStream.ReadContentInputStreamException; import org.sleuthkit.datamodel.TskCoreException; @@ -50,22 +65,25 @@ import org.sleuthkit.datamodel.TskCoreException; /** * Firefox recent activity extraction */ -class FirefoxExtractor extends Extractor { +final class FirefoxExtractor extends Extractor { private static final Logger logger = Logger.getLogger(FirefoxExtractor.class.getName()); + private static final String PARENT_MODULE_NAME = NbBundle.getMessage(FirefoxExtractor.class, + "Firefox.parentModuleName.noSpace"); + private static final String HISTORY_QUERY = "SELECT moz_historyvisits.id,url,title,visit_count,(visit_date/1000000) AS visit_date,from_visit,(SELECT url FROM moz_places WHERE id=moz_historyvisits.from_visit) as ref FROM moz_places, moz_historyvisits WHERE moz_places.id = moz_historyvisits.place_id AND hidden = 0"; //NON-NLS private static final String COOKIE_QUERY = "SELECT name,value,host,expiry,(lastAccessed/1000000) AS lastAccessed,(creationTime/1000000) AS creationTime FROM moz_cookies"; //NON-NLS private static final String COOKIE_QUERY_V3 = "SELECT name,value,host,expiry,(lastAccessed/1000000) AS lastAccessed FROM moz_cookies"; //NON-NLS private static final String BOOKMARK_QUERY = "SELECT fk, moz_bookmarks.title, url, (moz_bookmarks.dateAdded/1000000) AS dateAdded FROM moz_bookmarks INNER JOIN moz_places ON moz_bookmarks.fk=moz_places.id"; //NON-NLS private static final String DOWNLOAD_QUERY = "SELECT target, source,(startTime/1000000) AS startTime, maxBytes FROM moz_downloads"; //NON-NLS private static final String DOWNLOAD_QUERY_V24 = "SELECT url, content AS target, (lastModified/1000000) AS lastModified FROM moz_places, moz_annos WHERE moz_places.id = moz_annos.place_id AND moz_annos.anno_attribute_id = 3"; //NON-NLS - private final IngestServices services = IngestServices.getInstance(); + private Content dataSource; private IngestJobContext context; @Override protected String getModuleName() { - return NbBundle.getMessage(FirefoxExtractor.class, "Firefox.getModuleName()"); + return NbBundle.getMessage(FirefoxExtractor.class, "Firefox.moduleName"); } @Override @@ -75,12 +93,12 @@ class FirefoxExtractor extends Extractor { dataFound = false; this.getHistory(); this.getBookmark(); - this.getDownload(); + getDownloadPreVersion24(); + getDownloadVersion24(); this.getCookie(); } private void getHistory() { - FileManager fileManager = currentCase.getServices().getFileManager(); List historyFiles; try { historyFiles = fileManager.findFiles(dataSource, "places.sqlite", "Firefox"); //NON-NLS @@ -99,14 +117,14 @@ class FirefoxExtractor extends Extractor { dataFound = true; Collection bbartifacts = new ArrayList<>(); - int j = 0; + int index = 0; for (AbstractFile historyFile : historyFiles) { if (historyFile.getSize() == 0) { continue; } String fileName = historyFile.getName(); - String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + j + ".db"; //NON-NLS + String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + index + ".db"; //NON-NLS try { ContentUtils.writeToFile(historyFile, new File(temps), context::dataSourceIngestIsCancelled); } catch (ReadContentInputStreamException ex) { @@ -132,52 +150,53 @@ class FirefoxExtractor extends Extractor { List> tempList = this.dbConnect(temps, HISTORY_QUERY); logger.log(Level.INFO, "{0} - Now getting history from {1} with {2} artifacts identified.", new Object[]{getModuleName(), temps, tempList.size()}); //NON-NLS for (HashMap result : tempList) { - Collection bbattributes = new ArrayList<>(); - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - ((result.get("url").toString() != null) ? result.get("url").toString() : ""))); //NON-NLS - //bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL_DECODED.getTypeID(), "RecentActivity", ((result.get("url").toString() != null) ? EscapeUtil.decodeURL(result.get("url").toString()) : ""))); - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - (Long.valueOf(result.get("visit_date").toString())))); //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_REFERRER, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - ((result.get("ref").toString() != null) ? result.get("ref").toString() : ""))); //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_TITLE, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - ((result.get("title").toString() != null) ? result.get("title").toString() : ""))); //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - NbBundle.getMessage(this.getClass(), "Firefox.getModuleName()"))); - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DOMAIN, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), (Util.extractDomain((result.get("url").toString() != null) ? result.get("url").toString() : "")))); //NON-NLS - BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_HISTORY, historyFile, bbattributes); - if (bbart != null) { + Collection bbattributes = Arrays.asList( + new BlackboardAttribute( + TSK_URL, PARENT_MODULE_NAME, + Objects.toString(result.get("url"), "")),//NON-NLS + new BlackboardAttribute( + TSK_DATETIME_ACCESSED, PARENT_MODULE_NAME, + Long.valueOf(result.get("visit_date").toString())), //NON-NLS + new BlackboardAttribute( + TSK_REFERRER, PARENT_MODULE_NAME, + Objects.toString(result.get("ref"), "")), //NON-NLS + new BlackboardAttribute( + TSK_TITLE, PARENT_MODULE_NAME, + Objects.toString(result.get("title"), "")), //NON-NLS + new BlackboardAttribute( + TSK_PROG_NAME, PARENT_MODULE_NAME, + getModuleName()), + new BlackboardAttribute( + TSK_DOMAIN, PARENT_MODULE_NAME, + Util.extractDomain(Objects.toString(result.get("url"), "")))); //NON-NLS + try { + BlackboardArtifact bbart = historyFile.newArtifact(TSK_WEB_HISTORY); + bbart.addAttributes(bbattributes); bbartifacts.add(bbart); + } catch (TskCoreException ex) { + logger.log(Level.SEVERE, "Error while trying to create Firefox history artifact.", ex); //NON-NLS + this.addErrorMessage( + NbBundle.getMessage(ChromeExtractor.class, "Firefox.getHistory.errMsg.errAnalyzeFile=", //NON-NLS + this.getModuleName(), historyFile.getName())); } + } - ++j; + index++; dbFile.delete(); } - - services.fireModuleDataEvent(new ModuleDataEvent( - NbBundle.getMessage(this.getClass(), "Firefox.parentModuleName"), - BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY, bbartifacts)); + try { + blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME); + } catch (Blackboard.BlackboardException ex) { + logger.log(Level.SEVERE, "Error while trying to post Firefox history artifact.", ex); //NON-NLS + this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName())); + } } /** * Queries for bookmark files and adds artifacts */ private void getBookmark() { - - FileManager fileManager = currentCase.getServices().getFileManager(); List bookmarkFiles; try { bookmarkFiles = fileManager.findFiles(dataSource, "places.sqlite", "Firefox"); //NON-NLS @@ -195,13 +214,13 @@ class FirefoxExtractor extends Extractor { dataFound = true; Collection bbartifacts = new ArrayList<>(); - int j = 0; + int index = 0; for (AbstractFile bookmarkFile : bookmarkFiles) { if (bookmarkFile.getSize() == 0) { continue; } String fileName = bookmarkFile.getName(); - String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + j + ".db"; //NON-NLS + String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + index + ".db"; //NON-NLS try { ContentUtils.writeToFile(bookmarkFile, new File(temps), context::dataSourceIngestIsCancelled); } catch (ReadContentInputStreamException ex) { @@ -227,49 +246,51 @@ class FirefoxExtractor extends Extractor { logger.log(Level.INFO, "{0} - Now getting bookmarks from {1} with {2} artifacts identified.", new Object[]{getModuleName(), temps, tempList.size()}); //NON-NLS for (HashMap result : tempList) { - Collection bbattributes = new ArrayList<>(); - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - ((result.get("url").toString() != null) ? result.get("url").toString() : ""))); //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_TITLE, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - ((result.get("title").toString() != null) ? result.get("title").toString() : ""))); //NON-NLS - if (Long.valueOf(result.get("dateAdded").toString()) > 0) { //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_CREATED, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - (Long.valueOf(result.get("dateAdded").toString())))); //NON-NLS + Collection bbattributes = Lists.newArrayList( + new BlackboardAttribute( + TSK_URL, PARENT_MODULE_NAME, + Objects.toString(result.get("url"), "")), //NON-NLS + new BlackboardAttribute( + TSK_TITLE, PARENT_MODULE_NAME, + Objects.toString(result.get("title"), "")), //NON-NLS + new BlackboardAttribute( + TSK_PROG_NAME, PARENT_MODULE_NAME, + getModuleName()), + new BlackboardAttribute( + TSK_DOMAIN, PARENT_MODULE_NAME, + Util.extractDomain(Objects.toString(result.get("url"), "")))); //NON-NLS + Long createdTime = Long.valueOf(result.get("dateAdded").toString()); + if (createdTime > 0) { //NON-NLS + bbattributes.add(new BlackboardAttribute( + TSK_DATETIME_CREATED, PARENT_MODULE_NAME, + createdTime)); //NON-NLS } - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - NbBundle.getMessage(this.getClass(), "Firefox.getModuleName()"))); - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DOMAIN, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - (Util.extractDomain((result.get("url").toString() != null) ? result.get("url").toString() : "")))); //NON-NLS - - BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_BOOKMARK, bookmarkFile, bbattributes); - if (bbart != null) { + try { + BlackboardArtifact bbart = bookmarkFile.newArtifact(TSK_WEB_BOOKMARK); + bbart.addAttributes(bbattributes); bbartifacts.add(bbart); + } catch (TskCoreException ex) { + logger.log(Level.SEVERE, "Error while trying to create Firefox bookmark artifact.", ex); //NON-NLS + this.addErrorMessage( + NbBundle.getMessage(ChromeExtractor.class, "Firefox.getBookmark.errMsg.errAnalyzeFile=", //NON-NLS + this.getModuleName(), bookmarkFile.getName())); } } - ++j; + index++; dbFile.delete(); } - - services.fireModuleDataEvent(new ModuleDataEvent( - NbBundle.getMessage(this.getClass(), "Firefox.parentModuleName"), - BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_BOOKMARK, bbartifacts)); + try { + blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME); + } catch (Blackboard.BlackboardException ex) { + logger.log(Level.SEVERE, "Error while trying to post Firefox bookmark artifact.", ex); //NON-NLS + this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName())); + } } /** * Queries for cookies file and adds artifacts */ private void getCookie() { - FileManager fileManager = currentCase.getServices().getFileManager(); List cookiesFiles; try { cookiesFiles = fileManager.findFiles(dataSource, "cookies.sqlite", "Firefox"); //NON-NLS @@ -287,13 +308,13 @@ class FirefoxExtractor extends Extractor { dataFound = true; Collection bbartifacts = new ArrayList<>(); - int j = 0; + int index = 0; for (AbstractFile cookiesFile : cookiesFiles) { if (cookiesFile.getSize() == 0) { continue; } String fileName = cookiesFile.getName(); - String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + j + ".db"; //NON-NLS + String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + index + ".db"; //NON-NLS try { ContentUtils.writeToFile(cookiesFile, new File(temps), context::dataSourceIngestIsCancelled); } catch (ReadContentInputStreamException ex) { @@ -317,71 +338,57 @@ class FirefoxExtractor extends Extractor { break; } boolean checkColumn = Util.checkColumn("creationTime", "moz_cookies", temps); //NON-NLS - String query; - if (checkColumn) { - query = COOKIE_QUERY; - } else { - query = COOKIE_QUERY_V3; - } + String query = checkColumn ? COOKIE_QUERY : COOKIE_QUERY_V3; List> tempList = this.dbConnect(temps, query); logger.log(Level.INFO, "{0} - Now getting cookies from {1} with {2} artifacts identified.", new Object[]{getModuleName(), temps, tempList.size()}); //NON-NLS for (HashMap result : tempList) { - Collection bbattributes = new ArrayList<>(); - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - ((result.get("host").toString() != null) ? result.get("host").toString() : ""))); //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - (Long.valueOf(result.get("lastAccessed").toString())))); //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_NAME, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - ((result.get("name").toString() != null) ? result.get("name").toString() : ""))); //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_VALUE, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - ((result.get("value").toString() != null) ? result.get("value").toString() : ""))); //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - NbBundle.getMessage(this.getClass(), "Firefox.getModuleName()"))); - - if (checkColumn == true) { - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_CREATED, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), + Collection bbattributes = Lists.newArrayList( + new BlackboardAttribute( + TSK_URL, PARENT_MODULE_NAME, + Objects.toString(result.get("host"), "")), //NON-NLS + new BlackboardAttribute( + TSK_DATETIME, PARENT_MODULE_NAME, + Long.valueOf(result.get("lastAccessed").toString())), //NON-NLS + new BlackboardAttribute( + TSK_NAME, PARENT_MODULE_NAME, + Objects.toString(result.get("name"), "")), //NON-NLS + new BlackboardAttribute( + TSK_VALUE, PARENT_MODULE_NAME, + Objects.toString(result.get("value"), "")), //NON-NLS + new BlackboardAttribute( + TSK_PROG_NAME, PARENT_MODULE_NAME, + getModuleName()), + new BlackboardAttribute( + TSK_DOMAIN, PARENT_MODULE_NAME, + Util.extractDomain(result.get("host").toString()).replaceFirst("^\\.+(?!$)", ""))); //NON-NLS + if (checkColumn) { + bbattributes.add(new BlackboardAttribute( + TSK_DATETIME_CREATED, PARENT_MODULE_NAME, (Long.valueOf(result.get("creationTime").toString())))); //NON-NLS } - String domain = Util.extractDomain(result.get("host").toString()); //NON-NLS - domain = domain.replaceFirst("^\\.+(?!$)", ""); - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DOMAIN, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), domain)); - - BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_COOKIE, cookiesFile, bbattributes); - if (bbart != null) { + try { + BlackboardArtifact bbart = cookiesFile.newArtifact(TSK_WEB_COOKIE); + bbart.addAttributes(bbattributes); bbartifacts.add(bbart); + } catch (TskCoreException ex) { + logger.log(Level.SEVERE, "Error while trying to create Firefox cookie artifact.", ex); //NON-NLS + this.addErrorMessage( + NbBundle.getMessage(ChromeExtractor.class, "Firefox.getCookie.errMsg.errAnalyzeFile=", //NON-NLS + this.getModuleName(), cookiesFile.getName())); } } - ++j; + ++index; dbFile.delete(); } - services.fireModuleDataEvent(new ModuleDataEvent( - NbBundle.getMessage(this.getClass(), "Firefox.parentModuleName"), - BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE, bbartifacts)); - } - - /** - * Queries for downloads files and adds artifacts - */ - private void getDownload() { - getDownloadPreVersion24(); - getDownloadVersion24(); + try { + blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME); + } catch (Blackboard.BlackboardException ex) { + logger.log(Level.SEVERE, "Error while trying to post Firefox cookie artifact.", ex); //NON-NLS + this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName())); + } } /** @@ -391,7 +398,6 @@ class FirefoxExtractor extends Extractor { */ private void getDownloadPreVersion24() { - FileManager fileManager = currentCase.getServices().getFileManager(); List downloadsFiles; try { downloadsFiles = fileManager.findFiles(dataSource, "downloads.sqlite", "Firefox"); //NON-NLS @@ -409,13 +415,13 @@ class FirefoxExtractor extends Extractor { dataFound = true; Collection bbartifacts = new ArrayList<>(); - int j = 0; + int index = 0; for (AbstractFile downloadsFile : downloadsFiles) { if (downloadsFile.getSize() == 0) { continue; } String fileName = downloadsFile.getName(); - String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + j + ".db"; //NON-NLS + String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + index + ".db"; //NON-NLS int errors = 0; try { ContentUtils.writeToFile(downloadsFile, new File(temps), context::dataSourceIngestIsCancelled); @@ -443,52 +449,43 @@ class FirefoxExtractor extends Extractor { logger.log(Level.INFO, "{0}- Now getting downloads from {1} with {2} artifacts identified.", new Object[]{getModuleName(), temps, tempList.size()}); //NON-NLS for (HashMap result : tempList) { - Collection bbattributes = new ArrayList<>(); - - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - ((result.get("source").toString() != null) ? result.get("source").toString() : ""))); //NON-NLS - //bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL_DECODED.getTypeID(), "RecentActivity", ((result.get("source").toString() != null) ? EscapeUtil.decodeURL(result.get("source").toString()) : ""))); - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - (Long.valueOf(result.get("startTime").toString())))); //NON-NLS + Collection bbattributes = Lists.newArrayList( + new BlackboardAttribute(TSK_URL, PARENT_MODULE_NAME, + Objects.toString(result.get("source"), "")), //NON-NLS + new BlackboardAttribute(TSK_DATETIME_ACCESSED, PARENT_MODULE_NAME, + Long.valueOf(result.get("startTime").toString())), //NON-NLS + new BlackboardAttribute(TSK_PROG_NAME, PARENT_MODULE_NAME, + getModuleName()), + new BlackboardAttribute(TSK_DOMAIN, PARENT_MODULE_NAME, + Util.extractDomain(Objects.toString(result.get("source"), "")))); //NON-NLS String target = result.get("target").toString(); //NON-NLS - if (target != null) { - try { - String decodedTarget = URLDecoder.decode(target.replaceAll("file:///", ""), "UTF-8"); //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PATH, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - decodedTarget)); - long pathID = Util.findID(dataSource, decodedTarget); - if (pathID != -1) { - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PATH_ID, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - pathID)); - } - } catch (UnsupportedEncodingException ex) { - logger.log(Level.SEVERE, "Error decoding Firefox download URL in " + temps, ex); //NON-NLS - errors++; + try { + String decodedTarget = URLDecoder.decode(target.replaceAll("file:///", ""), "UTF-8"); //NON-NLS + bbattributes.add(new BlackboardAttribute( + TSK_PATH, PARENT_MODULE_NAME, + decodedTarget)); + long pathID = Util.findID(dataSource, decodedTarget); + if (pathID != -1) { + bbattributes.add(new BlackboardAttribute( + TSK_PATH_ID, PARENT_MODULE_NAME, + pathID)); } + } catch (UnsupportedEncodingException ex) { + logger.log(Level.SEVERE, "Error decoding Firefox download URL in " + temps, ex); //NON-NLS + errors++; } + try { - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - NbBundle.getMessage(this.getClass(), "Firefox.getModuleName()"))); - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DOMAIN, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - (Util.extractDomain((result.get("source").toString() != null) ? result.get("source").toString() : "")))); //NON-NLS - - BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, downloadsFile, bbattributes); - if (bbart != null) { + BlackboardArtifact bbart = downloadsFile.newArtifact(TSK_WEB_DOWNLOAD); + bbart.addAttributes(bbattributes); bbartifacts.add(bbart); + } catch (TskCoreException ex) { + logger.log(Level.SEVERE, "Error while trying to create Firefox download artifact.", ex); //NON-NLS + this.addErrorMessage( + NbBundle.getMessage(ChromeExtractor.class, "Firefox.getDlPre24.errMsg.errAnalyzeFiles", //NON-NLS + this.getModuleName(), downloadsFile.getName())); } } if (errors > 0) { @@ -496,14 +493,16 @@ class FirefoxExtractor extends Extractor { NbBundle.getMessage(this.getClass(), "Firefox.getDlPre24.errMsg.errParsingArtifacts", this.getModuleName(), errors)); } - j++; + index++; dbFile.delete(); - break; } - services.fireModuleDataEvent(new ModuleDataEvent( - NbBundle.getMessage(this.getClass(), "Firefox.parentModuleName"), - BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, bbartifacts)); + try { + blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME); + } catch (Blackboard.BlackboardException ex) { + logger.log(Level.SEVERE, "Error while trying to post Firefox download artifact.", ex); //NON-NLS + this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName())); + } } /** @@ -512,7 +511,6 @@ class FirefoxExtractor extends Extractor { * Downloads are stored in the places database. */ private void getDownloadVersion24() { - FileManager fileManager = currentCase.getServices().getFileManager(); List downloadsFiles; try { downloadsFiles = fileManager.findFiles(dataSource, "places.sqlite", "Firefox"); //NON-NLS @@ -530,13 +528,13 @@ class FirefoxExtractor extends Extractor { dataFound = true; Collection bbartifacts = new ArrayList<>(); - int j = 0; + int index = 0; for (AbstractFile downloadsFile : downloadsFiles) { if (downloadsFile.getSize() == 0) { continue; } String fileName = downloadsFile.getName(); - String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + "-downloads" + j + ".db"; //NON-NLS + String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + "-downloads" + index + ".db"; //NON-NLS int errors = 0; try { ContentUtils.writeToFile(downloadsFile, new File(temps), context::dataSourceIngestIsCancelled); @@ -566,65 +564,63 @@ class FirefoxExtractor extends Extractor { logger.log(Level.INFO, "{0} - Now getting downloads from {1} with {2} artifacts identified.", new Object[]{getModuleName(), temps, tempList.size()}); //NON-NLS for (HashMap result : tempList) { - Collection bbattributes = new ArrayList<>(); - - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - ((result.get("url").toString() != null) ? result.get("url").toString() : ""))); //NON-NLS - //bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL_DECODED.getTypeID(), "RecentActivity", ((result.get("source").toString() != null) ? EscapeUtil.decodeURL(result.get("source").toString()) : ""))); - //TODO Revisit usage of deprecated constructor as per TSK-583 - //bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_LAST_ACCESSED.getTypeID(), "RecentActivity", "Last Visited", (Long.valueOf(result.get("startTime").toString())))); + Collection bbattributes = Lists.newArrayList( + new BlackboardAttribute( + TSK_URL, PARENT_MODULE_NAME, + result.get("url").toString()), //NON-NLS + new BlackboardAttribute( + TSK_DATETIME_ACCESSED, PARENT_MODULE_NAME, + Long.valueOf(result.get("lastModified").toString())), //NON-NLS + new BlackboardAttribute( + TSK_PROG_NAME, PARENT_MODULE_NAME, + getModuleName()), + new BlackboardAttribute( + TSK_DOMAIN, PARENT_MODULE_NAME, + Util.extractDomain(result.get("url").toString()))); //NON-NLS String target = result.get("target").toString(); //NON-NLS - if (target != null) { - try { - String decodedTarget = URLDecoder.decode(target.replaceAll("file:///", ""), "UTF-8"); //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PATH, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - decodedTarget)); - long pathID = Util.findID(dataSource, decodedTarget); - if (pathID != -1) { - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PATH_ID, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - pathID)); - } - } catch (UnsupportedEncodingException ex) { - logger.log(Level.SEVERE, "Error decoding Firefox download URL in " + temps, ex); //NON-NLS - errors++; - } - } - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - Long.valueOf(result.get("lastModified").toString()))); //NON-NLS - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - NbBundle.getMessage(this.getClass(), "Firefox.getModuleName()"))); - bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DOMAIN, - NbBundle.getMessage(this.getClass(), - "Firefox.parentModuleName.noSpace"), - (Util.extractDomain((result.get("url").toString() != null) ? result.get("url").toString() : "")))); //NON-NLS - BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, downloadsFile, bbattributes); - if (bbart != null) { + try { + String decodedTarget = URLDecoder.decode(target.replaceAll("file:///", ""), "UTF-8"); //NON-NLS + bbattributes.add(new BlackboardAttribute( + TSK_PATH, PARENT_MODULE_NAME, + decodedTarget)); + long pathID = Util.findID(dataSource, decodedTarget); + if (pathID != -1) { + bbattributes.add(new BlackboardAttribute( + TSK_PATH_ID, PARENT_MODULE_NAME, + pathID)); + } + } catch (UnsupportedEncodingException ex) { + logger.log(Level.SEVERE, "Error decoding Firefox download URL in " + temps, ex); //NON-NLS + errors++; + } + + try { + BlackboardArtifact bbart = downloadsFile.newArtifact(TSK_WEB_DOWNLOAD); + bbart.addAttributes(bbattributes); bbartifacts.add(bbart); + } catch (TskCoreException ex) { + logger.log(Level.SEVERE, "Error while trying to create Firefox download artifact.", ex); //NON-NLS + this.addErrorMessage( + NbBundle.getMessage(ChromeExtractor.class, "Firefox.getDlV24.errMsg.errAnalyzeFile", //NON-NLS + this.getModuleName(), downloadsFile.getName())); } } if (errors > 0) { this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Firefox.getDlV24.errMsg.errParsingArtifacts", this.getModuleName(), errors)); } - j++; + index++; dbFile.delete(); - break; + } - services.fireModuleDataEvent(new ModuleDataEvent( - NbBundle.getMessage(this.getClass(), "Firefox.parentModuleName"), - BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, bbartifacts)); + try { + blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME); + } catch (Blackboard.BlackboardException ex) { + logger.log(Level.SEVERE, "Error while trying to post Firefox download artifact.", ex); //NON-NLS + this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName())); + } } } diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/IEExtractor.java b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/IEExtractor.java index 4bc0d6c70d..4e1b5bbaae 100644 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/IEExtractor.java +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/IEExtractor.java @@ -29,7 +29,6 @@ import java.io.FileInputStream; import java.io.FileNotFoundException; import java.io.IOException; import java.io.InputStreamReader; -import java.nio.file.Path; import java.text.ParseException; import java.text.SimpleDateFormat; import java.util.ArrayList; @@ -59,7 +58,6 @@ import org.sleuthkit.datamodel.*; import org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE; import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_OS_ACCOUNT; import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE; -import org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE; import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME; import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED; import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_CREATED; @@ -153,8 +151,10 @@ class IEExtractor extends Extractor { NbBundle.getMessage(this.getClass(), "ExtractIE.moduleName.text")), new BlackboardAttribute( TSK_DOMAIN, PARENT_MODULE_NAME_NO_SPACE, Util.extractDomain(getURLFromIEBookmarkFile(fav)))); + BlackboardArtifact bbart = fav.newArtifact(ARTIFACT_TYPE.TSK_WEB_BOOKMARK); + bbart.addAttributes(bbattributes); - bbartifacts.add(this.addArtifact(ARTIFACT_TYPE.TSK_WEB_BOOKMARK, fav, bbattributes)); + bbartifacts.add(bbart); } services.fireModuleDataEvent(new ModuleDataEvent( @@ -249,8 +249,10 @@ class IEExtractor extends Extractor { new BlackboardAttribute( TSK_DOMAIN, PARENT_MODULE_NAME_NO_SPACE, Util.extractDomain(URL))); + BlackboardArtifact bbart = cookiesFile.newArtifact(TSK_WEB_COOKIE); + bbart.addAttributes(bbattributes); - bbartifacts.add(this.addArtifact(TSK_WEB_COOKIE, cookiesFile, bbattributes)); + bbartifacts.add(bbart); } services.fireModuleDataEvent(new ModuleDataEvent( NbBundle.getMessage(this.getClass(), "ExtractIE.parentModuleName"), TSK_WEB_COOKIE, bbartifacts)); diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/RecentDocumentsLnkExtractor.java b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/RecentDocumentsLnkExtractor.java index efef7851d9..27899a82e9 100644 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/RecentDocumentsLnkExtractor.java +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/RecentDocumentsLnkExtractor.java @@ -122,7 +122,8 @@ class RecentDocumentsLnkExtractor extends Extractor { NbBundle.getMessage(this.getClass(), "RecentDocumentsByLnk.parentModuleName.noSpace"), recentFile.getCrtime())); - this.addArtifact(ARTIFACT_TYPE.TSK_RECENT_OBJECT, recentFile, bbattributes); + BlackboardArtifact bbart = recentFile.newArtifact(ARTIFACT_TYPE.TSK_RECENT_OBJECT); + bbart.addAttributes(bbattributes); } services.fireModuleDataEvent(new ModuleDataEvent( NbBundle.getMessage(this.getClass(), "RecentDocumentsByLnk.parentModuleName"), diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/RegistryExtractor.java b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/RegistryExtractor.java index a1b4b1f3c0..7d38270de8 100644 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/RegistryExtractor.java +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/RegistryExtractor.java @@ -531,7 +531,8 @@ class RegistryExtractor extends Extractor { new BlackboardAttribute(TSK_REMOTE_PATH, PARENT_MODULE_NAME, remoteName)); - addArtifact(TSK_REMOTE_DRIVE, regAbstractFile, bbattributes); + BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_REMOTE_DRIVE); + bbart.addAttributes(bbattributes); } catch (TskCoreException ex) { logger.log(Level.SEVERE, "Error adding network drive artifact to blackboard."); //NON-NLS } @@ -550,7 +551,8 @@ class RegistryExtractor extends Extractor { TSK_PATH, PARENT_MODULE_NAME, homeDir)); - addArtifact(TSK_OS_ACCOUNT, regAbstractFile, bbattributes); + BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_OS_ACCOUNT); + bbart.addAttributes(bbattributes); } catch (TskCoreException ex) { logger.log(Level.SEVERE, "Error adding account artifact to blackboard."); //NON-NLS } @@ -570,7 +572,8 @@ class RegistryExtractor extends Extractor { if (mtime != null) { bbattributes.add(new BlackboardAttribute(TSK_DATETIME_ACCESSED, PARENT_MODULE_NAME, mtime)); } - addArtifact(TSK_RECENT_OBJECT, regAbstractFile, bbattributes); + BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_RECENT_OBJECT); + bbart.addAttributes(bbattributes); } catch (TskCoreException ex) { logger.log(Level.SEVERE, "Error adding recent object artifact to blackboard."); //NON-NLS } @@ -593,7 +596,8 @@ class RegistryExtractor extends Extractor { new BlackboardAttribute( TSK_DATETIME, PARENT_MODULE_NAME, itemMtime)); - addArtifact(ARTIFACT_TYPE.TSK_INSTALLED_PROG, regAbstractFile, bbattributes); + BlackboardArtifact bbart = regAbstractFile.newArtifact(ARTIFACT_TYPE.TSK_INSTALLED_PROG); + bbart.addAttributes(bbattributes); } catch (TskCoreException ex) { logger.log(Level.SEVERE, "Error adding installed program artifact to blackboard."); //NON-NLS } @@ -626,7 +630,9 @@ class RegistryExtractor extends Extractor { new BlackboardAttribute( TSK_DEVICE_ID, PARENT_MODULE_NAME, deviceID)); - usbBBartifacts.add(addArtifact(TSK_DEVICE_ATTACHED, regAbstractFile, bbattributes)); + BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_DEVICE_ATTACHED); + bbart.addAttributes(bbattributes); + usbBBartifacts.add(bbart); } catch (TskCoreException ex) { logger.log(Level.SEVERE, "Error adding device attached artifact to blackboard."); //NON-NLS } @@ -659,7 +665,8 @@ class RegistryExtractor extends Extractor { // Check if there is already an OS_INFO artifact for this file and add to that if possible ArrayList results = caseDB.getBlackboardArtifacts(TSK_OS_INFO, regAbstractFile.getId()); if (results.isEmpty()) { - addArtifact(TSK_OS_INFO, regAbstractFile, bbattributes); + BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_OS_INFO); + bbart.addAttributes(bbattributes); } else { results.get(0).addAttributes(bbattributes); //TODO: does it need to get re-indexed? @@ -700,7 +707,8 @@ class RegistryExtractor extends Extractor { // Check if there is already an OS_INFO artifact for this file and add to that if possible ArrayList results = caseDB.getBlackboardArtifacts(TSK_OS_INFO, regAbstractFile.getId()); if (results.isEmpty()) { - addArtifact(TSK_OS_INFO, regAbstractFile, bbattributes); + BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_OS_INFO); + bbart.addAttributes(bbattributes); } else { results.get(0).addAttributes(bbattributes); } @@ -786,7 +794,8 @@ class RegistryExtractor extends Extractor { // Check if there is already an OS_INFO artifact for this file, and add to that if possible. ArrayList results = caseDB.getBlackboardArtifacts(TSK_OS_INFO, regAbstractFile.getId()); if (results.isEmpty()) { - addArtifact(TSK_OS_INFO, regAbstractFile, bbattributes); + BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_OS_INFO); + bbart.addAttributes(bbattributes); } else { results.get(0).addAttributes(bbattributes); } diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/SearchEngineURLQueryAnalyzer.java b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/SearchEngineURLQueryAnalyzer.java index ea3f73442d..b87777766c 100644 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/SearchEngineURLQueryAnalyzer.java +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/SearchEngineURLQueryAnalyzer.java @@ -367,7 +367,8 @@ class SearchEngineURLQueryAnalyzer extends Extractor { bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED, NbBundle.getMessage(this.getClass(), "SearchEngineURLQueryAnalyzer.parentModuleName"), last_accessed)); - this.addArtifact(ARTIFACT_TYPE.TSK_WEB_SEARCH_QUERY, file, bbattributes); + BlackboardArtifact bbart = file.newArtifact(ARTIFACT_TYPE.TSK_WEB_SEARCH_QUERY); + bbart.addAttributes(bbattributes); se.increment(); ++totalQueries; }