mirror of
https://github.com/elisspace/autopsy.git
synced 2026-10-01 23:09:56 +00:00
Updated python report module, added July2015 tutorial folder with code of final module
This commit is contained in:
@@ -28,24 +28,36 @@
|
||||
# OTHER DEALINGS IN THE SOFTWARE.
|
||||
|
||||
|
||||
# Report module for Autopsy.
|
||||
# Sample report module for Autopsy. Use as a starting point for new modules.
|
||||
#
|
||||
# Search for TODO for the things that you need to change
|
||||
# See http://sleuthkit.org/autopsy/docs/api-docs/3.1/index.html for documentation
|
||||
|
||||
from java.lang import System
|
||||
from org.sleuthkit.autopsy.casemodule import Case
|
||||
from org.sleuthkit.autopsy.report import GeneralReportModuleAdapter
|
||||
import os
|
||||
from java.lang import System
|
||||
from java.util.logging import Level
|
||||
from org.sleuthkit.autopsy.casemodule import Case
|
||||
from org.sleuthkit.autopsy.coreutils import Logger
|
||||
from org.sleuthkit.autopsy.report import GeneralReportModuleAdapter
|
||||
|
||||
# TODO: Rename this to something more specific
|
||||
|
||||
# TODO: Rename the class to something more specific
|
||||
class SampleGeneralReportModule(GeneralReportModuleAdapter):
|
||||
|
||||
# TODO: Rename this. Will be shown to users when making a report
|
||||
def getName(self):
|
||||
return "Sample Jython Report Module"
|
||||
moduleName = "Sample Report Module"
|
||||
|
||||
# TODO: rewrite this
|
||||
_logger = None
|
||||
def log(self, level, msg):
|
||||
if _logger == None:
|
||||
_logger = Logger.getLogger(self.moduleName)
|
||||
|
||||
self._logger.logp(level, self.__class__.__name__, inspect.stack()[1][3], msg)
|
||||
|
||||
def getName(self):
|
||||
return self.moduleName
|
||||
|
||||
# TODO: Give it a useful description
|
||||
def getDescription(self):
|
||||
return "A sample Jython report module"
|
||||
|
||||
@@ -54,30 +66,41 @@ class SampleGeneralReportModule(GeneralReportModuleAdapter):
|
||||
return "sampleReport.txt"
|
||||
|
||||
# TODO: Update this method to make a report
|
||||
# The 'baseReportDir' object being passed in is a string with the directory that reports are being stored in. Report should go into baseReportDir + getRelativeFilePath().
|
||||
# The 'progressBar' object is of type ReportProgressPanel.
|
||||
# See: http://sleuthkit.org/autopsy/docs/api-docs/3.1/classorg_1_1sleuthkit_1_1autopsy_1_1report_1_1_report_progress_panel.html
|
||||
def generateReport(self, baseReportDir, progressBar):
|
||||
|
||||
# For an example, we write a file with the number of files created in the past 2 weeks
|
||||
# Configure progress bar for 2 tasks
|
||||
progressBar.setIndeterminate(False)
|
||||
progressBar.start()
|
||||
progressBar.setMaximumProgress(2)
|
||||
# For an example, we write a file with the number of files created in the past 2 weeks
|
||||
# Configure progress bar for 2 tasks
|
||||
progressBar.setIndeterminate(False)
|
||||
progressBar.start()
|
||||
progressBar.setMaximumProgress(2)
|
||||
|
||||
# Get files by created in last two weeks.
|
||||
fileCount = 0
|
||||
autopsyCase = Case.getCurrentCase()
|
||||
sleuthkitCase = autopsyCase.getSleuthkitCase()
|
||||
currentTime = System.currentTimeMillis() / 1000
|
||||
minTime = currentTime - (14 * 24 * 60 * 60)
|
||||
otherFiles = sleuthkitCase.findFilesWhere("crtime > %d" % minTime)
|
||||
for otherFile in otherFiles:
|
||||
fileCount += 1
|
||||
progressBar.increment()
|
||||
|
||||
# Write the result to the report file.
|
||||
report = open(os.path.join(baseReportDir, self.getRelativeFilePath()), 'w')
|
||||
report.write("file count = %d" % fileCount)
|
||||
Case.getCurrentCase().addReport(report.name, "SampleGeneralReportModule", "Sample Python Report");
|
||||
report.close()
|
||||
|
||||
progressBar.increment()
|
||||
progressBar.complete()
|
||||
# Find epoch time of when 2 weeks ago was
|
||||
currentTime = System.currentTimeMillis() / 1000
|
||||
minTime = currentTime - (14 * 24 * 60 * 60) # (days * hours * minutes * seconds)
|
||||
|
||||
# Query the database for files that meet our criteria
|
||||
sleuthkitCase = Case.getCurrentCase().getSleuthkitCase()
|
||||
files = sleuthkitCase.findAllFilesWhere("crtime > %d" % minTime)
|
||||
|
||||
fileCount = 0
|
||||
for file in files:
|
||||
fileCount += 1
|
||||
# Could do something else here and write it to HTML, CSV, etc.
|
||||
|
||||
# Increment since we are done with step #1
|
||||
progressBar.increment()
|
||||
|
||||
# Write the count to the report file.
|
||||
fileName = os.path.join(baseReportDir, self.getRelativeFilePath())
|
||||
report = open(fileName, 'w')
|
||||
report.write("file count = %d" % fileCount)
|
||||
report.close()
|
||||
|
||||
# Add the report to the Case, so it is shown in the tree
|
||||
Case.getCurrentCase().addReport(fileName, self.moduleName, "File Count Report");
|
||||
|
||||
progressBar.increment()
|
||||
progressBar.complete()
|
||||
|
||||
Reference in New Issue
Block a user