mirror of
https://github.com/elisspace/autopsy.git
synced 2026-10-05 08:46:20 +00:00
Merge pull request #3047 from raman-bt/eur853-androidPythonModules
853: Android python modules create accounts & relationships
This commit is contained in:
@@ -43,10 +43,13 @@ from org.sleuthkit.datamodel import BlackboardAttribute
|
||||
from org.sleuthkit.datamodel.BlackboardAttribute import ATTRIBUTE_TYPE
|
||||
from org.sleuthkit.datamodel import Content
|
||||
from org.sleuthkit.datamodel import TskCoreException
|
||||
from org.sleuthkit.datamodel import Account
|
||||
|
||||
import traceback
|
||||
import general
|
||||
|
||||
deviceAccount = None
|
||||
|
||||
"""
|
||||
Locates a variety of different call log databases, parses them, and populates the blackboard.
|
||||
"""
|
||||
@@ -81,6 +84,15 @@ class CallLogAnalyzer(general.AndroidComponentAnalyzer):
|
||||
|
||||
def analyze(self, dataSource, fileManager, context):
|
||||
try:
|
||||
|
||||
# Create a 'Device' account using the data source device id
|
||||
datasourceObjId = dataSource.getDataSource().getId()
|
||||
ds = Case.getCurrentCase().getSleuthkitCase().getDataSource(datasourceObjId)
|
||||
deviceID = ds.getDeviceId()
|
||||
|
||||
global deviceAccount
|
||||
deviceAccount = Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().getOrCreateAccount(Account.Type.DEVICE, deviceID, general.MODULE_NAME, dataSource)
|
||||
|
||||
absFiles = fileManager.findFiles(dataSource, "logs.db")
|
||||
absFiles.addAll(fileManager.findFiles(dataSource, "contacts.db"))
|
||||
absFiles.addAll(fileManager.findFiles(dataSource, "contacts2.db"))
|
||||
@@ -130,6 +142,12 @@ class CallLogAnalyzer(general.AndroidComponentAnalyzer):
|
||||
artifact.addAttribute(BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DIRECTION, general.MODULE_NAME, directionString))
|
||||
artifact.addAttribute(BlackboardAttribute(ATTRIBUTE_TYPE.TSK_NAME, general.MODULE_NAME, name))
|
||||
|
||||
# Create an account
|
||||
calllogAccount = Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().getOrCreateAccount(Account.Type.PHONE, number, general.MODULE_NAME, abstractFile);
|
||||
|
||||
# create relationship between accounts
|
||||
Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().addRelationships(deviceAccount, [calllogAccount], artifact);
|
||||
|
||||
bbartifacts.append(artifact)
|
||||
|
||||
try:
|
||||
|
||||
@@ -41,10 +41,13 @@ from org.sleuthkit.datamodel import BlackboardArtifact
|
||||
from org.sleuthkit.datamodel import BlackboardAttribute
|
||||
from org.sleuthkit.datamodel import Content
|
||||
from org.sleuthkit.datamodel import TskCoreException
|
||||
from org.sleuthkit.datamodel import Account
|
||||
|
||||
import traceback
|
||||
import general
|
||||
|
||||
deviceAccount = None
|
||||
|
||||
"""
|
||||
Locates a variety of different contacts databases, parses them, and populates the blackboard.
|
||||
"""
|
||||
@@ -55,6 +58,15 @@ class ContactAnalyzer(general.AndroidComponentAnalyzer):
|
||||
|
||||
def analyze(self, dataSource, fileManager, context):
|
||||
try:
|
||||
|
||||
# Create a 'Device' account using the data source device id
|
||||
datasourceObjId = dataSource.getDataSource().getId()
|
||||
ds = Case.getCurrentCase().getSleuthkitCase().getDataSource(datasourceObjId)
|
||||
deviceID = ds.getDeviceId()
|
||||
|
||||
global deviceAccount
|
||||
deviceAccount = Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().getOrCreateAccount(Account.Type.DEVICE, deviceID, general.MODULE_NAME, dataSource)
|
||||
|
||||
absFiles = fileManager.findFiles(dataSource, "contacts.db")
|
||||
absFiles.addAll(fileManager.findFiles(dataSource, "contacts2.db"))
|
||||
if absFiles.isEmpty():
|
||||
@@ -129,8 +141,16 @@ class ContactAnalyzer(general.AndroidComponentAnalyzer):
|
||||
artifact.addAttribute(BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_NAME, general.MODULE_NAME, name))
|
||||
if mimetype == "vnd.android.cursor.item/phone_v2":
|
||||
artifact.addAttribute(BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PHONE_NUMBER, general.MODULE_NAME, data1))
|
||||
acctType = Account.Type.PHONE
|
||||
else:
|
||||
artifact.addAttribute(BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_EMAIL, general.MODULE_NAME, data1))
|
||||
acctType = Account.Type.EMAIL
|
||||
|
||||
# Create an account
|
||||
contactAccount = Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().getOrCreateAccount(acctType, data1, general.MODULE_NAME, abstractFile);
|
||||
|
||||
# create relationship between accounts
|
||||
Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().addRelationships(deviceAccount, [contactAccount], artifact);
|
||||
|
||||
oldName = name
|
||||
|
||||
|
||||
@@ -41,10 +41,13 @@ from org.sleuthkit.datamodel import BlackboardArtifact
|
||||
from org.sleuthkit.datamodel import BlackboardAttribute
|
||||
from org.sleuthkit.datamodel import Content
|
||||
from org.sleuthkit.datamodel import TskCoreException
|
||||
from org.sleuthkit.datamodel import Account
|
||||
|
||||
import traceback
|
||||
import general
|
||||
|
||||
deviceAccount = None
|
||||
|
||||
"""
|
||||
Locates database for the Tango app and adds info to blackboard.
|
||||
"""
|
||||
@@ -55,6 +58,14 @@ class TangoMessageAnalyzer(general.AndroidComponentAnalyzer):
|
||||
|
||||
def analyze(self, dataSource, fileManager, context):
|
||||
try:
|
||||
# Create a 'Device' account using the data source device id
|
||||
datasourceObjId = dataSource.getDataSource().getId()
|
||||
ds = Case.getCurrentCase().getSleuthkitCase().getDataSource(datasourceObjId)
|
||||
deviceID = ds.getDeviceId()
|
||||
|
||||
global deviceAccount
|
||||
deviceAccount = Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().getOrCreateAccount(Account.Type.DEVICE, deviceID, general.MODULE_NAME, dataSource)
|
||||
|
||||
absFiles = fileManager.findFiles(dataSource, "tc.db")
|
||||
for abstractFile in absFiles:
|
||||
try:
|
||||
|
||||
@@ -42,10 +42,13 @@ from org.sleuthkit.datamodel import BlackboardArtifact
|
||||
from org.sleuthkit.datamodel import BlackboardAttribute
|
||||
from org.sleuthkit.datamodel import Content
|
||||
from org.sleuthkit.datamodel import TskCoreException
|
||||
from org.sleuthkit.datamodel import Account
|
||||
|
||||
import traceback
|
||||
import general
|
||||
|
||||
deviceAccount = None
|
||||
|
||||
"""
|
||||
Finds database with SMS/MMS messages and adds them to blackboard.
|
||||
"""
|
||||
@@ -56,6 +59,15 @@ class TextMessageAnalyzer(general.AndroidComponentAnalyzer):
|
||||
|
||||
def analyze(self, dataSource, fileManager, context):
|
||||
try:
|
||||
|
||||
# Create a 'Device' account using the data source device id
|
||||
datasourceObjId = dataSource.getDataSource().getId()
|
||||
ds = Case.getCurrentCase().getSleuthkitCase().getDataSource(datasourceObjId)
|
||||
deviceID = ds.getDeviceId()
|
||||
|
||||
global deviceAccount
|
||||
deviceAccount = Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().getOrCreateAccount(Account.Type.DEVICE, deviceID, general.MODULE_NAME, dataSource)
|
||||
|
||||
absFiles = fileManager.findFiles(dataSource, "mmssms.db")
|
||||
for abstractFile in absFiles:
|
||||
try:
|
||||
@@ -105,6 +117,12 @@ class TextMessageAnalyzer(general.AndroidComponentAnalyzer):
|
||||
artifact.addAttribute(BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_TEXT, general.MODULE_NAME, body))
|
||||
artifact.addAttribute(BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_MESSAGE_TYPE, general.MODULE_NAME, "SMS Message"))
|
||||
|
||||
# Create an account
|
||||
msgAccount = Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().getOrCreateAccount(Account.Type.PHONE, address, general.MODULE_NAME, abstractFile);
|
||||
|
||||
# create relationship between accounts
|
||||
Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().addRelationships(deviceAccount, [msgAccount], artifact);
|
||||
|
||||
bbartifacts.append(artifact)
|
||||
try:
|
||||
# index the artifact for keyword search
|
||||
|
||||
@@ -38,10 +38,14 @@ from org.sleuthkit.datamodel import BlackboardArtifact
|
||||
from org.sleuthkit.datamodel import BlackboardAttribute
|
||||
from org.sleuthkit.datamodel import Content
|
||||
from org.sleuthkit.datamodel import TskCoreException
|
||||
from org.sleuthkit.datamodel import Account
|
||||
|
||||
import traceback
|
||||
import general
|
||||
|
||||
wwfAccountType = None
|
||||
deviceAccount = None
|
||||
|
||||
"""
|
||||
Analyzes messages from Words With Friends
|
||||
"""
|
||||
@@ -52,6 +56,18 @@ class WWFMessageAnalyzer(general.AndroidComponentAnalyzer):
|
||||
|
||||
def analyze(self, dataSource, fileManager, context):
|
||||
try:
|
||||
|
||||
global wwfAccountType
|
||||
wwfAccountType = Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().addAccountType("WWF", "Words with Friends")
|
||||
|
||||
# Create a 'Device' account using the data source device id
|
||||
datasourceObjId = dataSource.getDataSource().getId()
|
||||
ds = Case.getCurrentCase().getSleuthkitCase().getDataSource(datasourceObjId)
|
||||
deviceID = ds.getDeviceId()
|
||||
|
||||
global deviceAccount
|
||||
deviceAccount = Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().getOrCreateAccount(Account.Type.DEVICE, deviceID, general.MODULE_NAME, dataSource)
|
||||
|
||||
absFiles = fileManager.findFiles(dataSource, "WordsFramework")
|
||||
for abstractFile in absFiles:
|
||||
try:
|
||||
@@ -95,6 +111,12 @@ class WWFMessageAnalyzer(general.AndroidComponentAnalyzer):
|
||||
artifact.addAttribute(BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_TEXT, general.MODULE_NAME, message))
|
||||
artifact.addAttribute(BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_MESSAGE_TYPE, general.MODULE_NAME, "Words With Friends Message"))
|
||||
|
||||
# Create an account
|
||||
wwfAccount = Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().getOrCreateAccount(wwfAccountType, user_id, general.MODULE_NAME, abstractFile);
|
||||
|
||||
# create relationship between accounts
|
||||
Case.getCurrentCase().getSleuthkitCase().getCommunicationsManager().addRelationships(deviceAccount, [wwfAccount], artifact);
|
||||
|
||||
try:
|
||||
# index the artifact for keyword search
|
||||
blackboard = Case.getCurrentCase().getServices().getBlackboard()
|
||||
|
||||
Reference in New Issue
Block a user