From a2ff9d11213d2e31a0d6962946820ef439601e68 Mon Sep 17 00:00:00 2001 From: William Schaefer Date: Mon, 21 Sep 2020 10:52:53 -0400 Subject: [PATCH 01/14] 6871 document format parameters --- .../autopsy/recentactivity/Bundle.properties-MERGED | 6 ++++++ .../src/org/sleuthkit/autopsy/recentactivity/Chromium.java | 7 ++++++- 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Bundle.properties-MERGED b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Bundle.properties-MERGED index 4456663bd8..a842d76f74 100755 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Bundle.properties-MERGED +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Bundle.properties-MERGED @@ -159,13 +159,19 @@ Firefox.getDlV24.errMsg.errAnalyzeFile={0}: Error while trying to analyze file:{ Firefox.getDlV24.errMsg.errParsingArtifacts={0}: Error parsing {1} Firefox web download artifacts. Progress_Message_Analyze_Registry=Analyzing Registry Files Progress_Message_Analyze_Usage=Data Sources Usage Analysis +# {0} - browserName Progress_Message_Chrome_AutoFill=Chrome Auto Fill Browser {0} +# {0} - browserName Progress_Message_Chrome_Bookmarks=Chrome Bookmarks Browser {0} Progress_Message_Chrome_Cache=Chrome Cache +# {0} - browserName Progress_Message_Chrome_Cookies=Chrome Cookies Browser {0} +# {0} - browserName Progress_Message_Chrome_Downloads=Chrome Downloads Browser {0} Progress_Message_Chrome_FormHistory=Chrome Form History +# {0} - browserName Progress_Message_Chrome_History=Chrome History Browser {0} +# {0} - browserName Progress_Message_Chrome_Logins=Chrome Logins Browser {0} Progress_Message_Edge_Bookmarks=Microsoft Edge Bookmarks Progress_Message_Edge_Cookies=Microsoft Edge Cookies diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Chromium.java b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Chromium.java index b63e33ecdf..9d2318278b 100644 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Chromium.java +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/Chromium.java @@ -96,13 +96,18 @@ class Chromium extends Extract { .build(); - @Messages({ + @Messages({"# {0} - browserName", "Progress_Message_Chrome_History=Chrome History Browser {0}", + "# {0} - browserName", "Progress_Message_Chrome_Bookmarks=Chrome Bookmarks Browser {0}", + "# {0} - browserName", "Progress_Message_Chrome_Cookies=Chrome Cookies Browser {0}", + "# {0} - browserName", "Progress_Message_Chrome_Downloads=Chrome Downloads Browser {0}", "Progress_Message_Chrome_FormHistory=Chrome Form History", + "# {0} - browserName", "Progress_Message_Chrome_AutoFill=Chrome Auto Fill Browser {0}", + "# {0} - browserName", "Progress_Message_Chrome_Logins=Chrome Logins Browser {0}", "Progress_Message_Chrome_Cache=Chrome Cache", }) From ef333eb55e047a664569637dcfd47f6dd141a4b4 Mon Sep 17 00:00:00 2001 From: esaunders Date: Mon, 21 Sep 2020 13:53:50 -0400 Subject: [PATCH 02/14] Change default_userdir in Autopsy configuration file. --- build-windows-installer.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build-windows-installer.xml b/build-windows-installer.xml index 5e40e0ce55..e07d110568 100644 --- a/build-windows-installer.xml +++ b/build-windows-installer.xml @@ -178,7 +178,7 @@ - + From aacd633d14f9d5d9fe06276a1152a1111623bcbc Mon Sep 17 00:00:00 2001 From: apriestman Date: Tue, 22 Sep 2020 09:25:55 -0400 Subject: [PATCH 03/14] Add a space to the photo rec temp dir --- .../modules/photoreccarver/PhotoRecCarverFileIngestModule.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Core/src/org/sleuthkit/autopsy/modules/photoreccarver/PhotoRecCarverFileIngestModule.java b/Core/src/org/sleuthkit/autopsy/modules/photoreccarver/PhotoRecCarverFileIngestModule.java index 8052316ab8..1b42cc7f47 100644 --- a/Core/src/org/sleuthkit/autopsy/modules/photoreccarver/PhotoRecCarverFileIngestModule.java +++ b/Core/src/org/sleuthkit/autopsy/modules/photoreccarver/PhotoRecCarverFileIngestModule.java @@ -86,7 +86,7 @@ final class PhotoRecCarverFileIngestModule implements FileIngestModule { static final boolean DEFAULT_CONFIG_INCLUDE_ELSE_EXCLUDE = false; - private static final String PHOTOREC_TEMP_SUBDIR = "Photorec"; + private static final String PHOTOREC_TEMP_SUBDIR = "PhotoRec Carver"; // NON-NLS Note that we need the space in this dir name (JIRA-6878) private static final String PHOTOREC_DIRECTORY = "photorec_exec"; //NON-NLS private static final String PHOTOREC_SUBDIRECTORY = "bin"; //NON-NLS private static final String PHOTOREC_EXECUTABLE = "photorec_win.exe"; //NON-NLS From 3514579c161de51a23d605e93d16e857e3d34ad2 Mon Sep 17 00:00:00 2001 From: Greg DiCristofaro Date: Tue, 22 Sep 2020 11:53:15 -0400 Subject: [PATCH 04/14] suppress popup --- .../datasourcesummary/uiutils/PieChartPanel.java | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/datasourcesummary/uiutils/PieChartPanel.java b/Core/src/org/sleuthkit/autopsy/datasourcesummary/uiutils/PieChartPanel.java index 466c578b60..2e65caca64 100644 --- a/Core/src/org/sleuthkit/autopsy/datasourcesummary/uiutils/PieChartPanel.java +++ b/Core/src/org/sleuthkit/autopsy/datasourcesummary/uiutils/PieChartPanel.java @@ -148,17 +148,12 @@ public class PieChartPanel extends AbstractLoadableComponent Date: Tue, 22 Sep 2020 12:46:26 -0400 Subject: [PATCH 05/14] Performance improvement --- Core/src/org/sleuthkit/autopsy/casemodule/Case.java | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/casemodule/Case.java b/Core/src/org/sleuthkit/autopsy/casemodule/Case.java index 3ad14f6137..395310e600 100644 --- a/Core/src/org/sleuthkit/autopsy/casemodule/Case.java +++ b/Core/src/org/sleuthkit/autopsy/casemodule/Case.java @@ -1468,9 +1468,16 @@ public class Case { */ public boolean hasData() { boolean hasDataSources = false; - try { - hasDataSources = (getDataSources().size() > 0); - } catch (TskCoreException ex) { + String query = "SELECT count(*) AS count FROM tsk_objects WHERE par_obj_id IS NULL"; + try (SleuthkitCase.CaseDbQuery dbQuery = caseDb.executeQuery(query)) { + ResultSet resultSet = dbQuery.getResultSet(); + if (resultSet.next()) { + long numDataSources = resultSet.getLong("count"); + if (numDataSources > 0) { + hasDataSources = true; + } + } + } catch (TskCoreException | SQLException ex) { logger.log(Level.SEVERE, "Error accessing case database", ex); //NON-NLS } return hasDataSources; From 58b69ed7e89cf1832971ccac8e6b6a0525ba6547 Mon Sep 17 00:00:00 2001 From: Eugene Livis Date: Tue, 22 Sep 2020 13:03:26 -0400 Subject: [PATCH 06/14] Not reading all data sources from case DB for the second time --- .../autopsy/imagegallery/ImageGalleryController.java | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/ImageGallery/src/org/sleuthkit/autopsy/imagegallery/ImageGalleryController.java b/ImageGallery/src/org/sleuthkit/autopsy/imagegallery/ImageGalleryController.java index 95509c4c16..730b91bfdd 100644 --- a/ImageGallery/src/org/sleuthkit/autopsy/imagegallery/ImageGalleryController.java +++ b/ImageGallery/src/org/sleuthkit/autopsy/imagegallery/ImageGalleryController.java @@ -246,7 +246,8 @@ public final class ImageGalleryController { tagsManager.registerListener(groupManager); tagsManager.registerListener(categoryManager); hashSetManager = new HashSetManager(drawableDB); - setModelIsStale(isDataSourcesTableStale()); + boolean isStale = isDataSourcesTableStale(); + setModelIsStale(isStale); dbExecutor = getNewDBExecutor(); listeningEnabled.addListener((observable, wasPreviouslyEnabled, isEnabled) -> { @@ -258,7 +259,7 @@ public final class ImageGalleryController { */ if (isEnabled && !wasPreviouslyEnabled && (Case.getCurrentCaseThrows().getCaseType() == CaseType.SINGLE_USER_CASE) - && isDataSourcesTableStale()) { + && isStale) { rebuildDrawablesDb(); } } catch (NoCurrentCaseException ex) { From 8a564c631a5e5306db642e48f00f5a3c0d76ee65 Mon Sep 17 00:00:00 2001 From: apriestman Date: Tue, 22 Sep 2020 13:29:25 -0400 Subject: [PATCH 07/14] Combine Picture Analyzer bullets. --- NEWS.txt | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/NEWS.txt b/NEWS.txt index d9c67e6a17..beaed367aa 100644 --- a/NEWS.txt +++ b/NEWS.txt @@ -5,8 +5,7 @@ Expanded Discovery UI to support searching for and basic display of web domains. Ingest Modules: Added iOS Analyzer module based on iLEAPP and a subset of its artifacts. -Support for HEIC/HEIF images by converting them to JPEGs using ImageMagick (which retains EXIF). -New Picture Analyzer module that does HEIC conversion and EXIF extraction (replaces the previous EXIF module). +New Picture Analyzer module that does EXIF extraction and HEIC conversion. HEIC/HEIF images are converted to JPEGs that retain EXIF using ImageMagick. (Replaces the previous EXIF ingest module) Added support for the latest version of Edge browser that is based on Chromium into Recent Activity. Other Chromium-based browsers are also supported. Updated the rules that search Web History artifacts for search queries. Expanded module to support multiple search engines for ambiguous URLs. Bluetooth pairing artifacts are created based on RegRipper output. From e3173a29d815bceb07828a0681eea81ce7e5b896 Mon Sep 17 00:00:00 2001 From: apriestman Date: Tue, 22 Sep 2020 13:39:35 -0400 Subject: [PATCH 08/14] Revision. --- NEWS.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/NEWS.txt b/NEWS.txt index beaed367aa..7f37faa9c8 100644 --- a/NEWS.txt +++ b/NEWS.txt @@ -5,7 +5,7 @@ Expanded Discovery UI to support searching for and basic display of web domains. Ingest Modules: Added iOS Analyzer module based on iLEAPP and a subset of its artifacts. -New Picture Analyzer module that does EXIF extraction and HEIC conversion. HEIC/HEIF images are converted to JPEGs that retain EXIF using ImageMagick. (Replaces the previous EXIF ingest module) +New Picture Analyzer module that does EXIF extraction and HEIC conversion. HEIC/HEIF images are converted to JPEGs that retain EXIF using ImageMagick (replaces the previous EXIF ingest module). Added support for the latest version of Edge browser that is based on Chromium into Recent Activity. Other Chromium-based browsers are also supported. Updated the rules that search Web History artifacts for search queries. Expanded module to support multiple search engines for ambiguous URLs. Bluetooth pairing artifacts are created based on RegRipper output. From ccfa2abe1795b48a2c2b4440592a2f35a24b24ab Mon Sep 17 00:00:00 2001 From: Richard Cordovano Date: Tue, 22 Sep 2020 14:23:59 -0400 Subject: [PATCH 09/14] Update Autopsy app version to 4.17.0 --- docs/doxygen-user/Doxyfile | 4 ++-- docs/doxygen/Doxyfile | 4 ++-- nbproject/project.properties | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/doxygen-user/Doxyfile b/docs/doxygen-user/Doxyfile index eaa570e291..a87d92a966 100644 --- a/docs/doxygen-user/Doxyfile +++ b/docs/doxygen-user/Doxyfile @@ -38,7 +38,7 @@ PROJECT_NAME = "Autopsy User Documentation" # could be handy for archiving the generated documentation or if some version # control system is used. -PROJECT_NUMBER = 4.16.0 +PROJECT_NUMBER = 4.17.0 # Using the PROJECT_BRIEF tag one can provide an optional one line description # for a project that appears at the top of each page and should give viewer a @@ -1025,7 +1025,7 @@ GENERATE_HTML = YES # The default directory is: html. # This tag requires that the tag GENERATE_HTML is set to YES. -HTML_OUTPUT = 4.16.0 +HTML_OUTPUT = 4.17.0 # The HTML_FILE_EXTENSION tag can be used to specify the file extension for each # generated HTML page (for example: .htm, .php, .asp). diff --git a/docs/doxygen/Doxyfile b/docs/doxygen/Doxyfile index 261517d081..722e81fb14 100644 --- a/docs/doxygen/Doxyfile +++ b/docs/doxygen/Doxyfile @@ -38,7 +38,7 @@ PROJECT_NAME = "Autopsy" # could be handy for archiving the generated documentation or if some version # control system is used. -PROJECT_NUMBER = 4.16.0 +PROJECT_NUMBER = 4.17.0 # Using the PROJECT_BRIEF tag one can provide an optional one line description # for a project that appears a the top of each page and should give viewer a @@ -1066,7 +1066,7 @@ GENERATE_HTML = YES # The default directory is: html. # This tag requires that the tag GENERATE_HTML is set to YES. -HTML_OUTPUT = api-docs/4.16.0/ +HTML_OUTPUT = api-docs/4.17.0/ # The HTML_FILE_EXTENSION tag can be used to specify the file extension for each # generated HTML page (for example: .htm, .php, .asp). diff --git a/nbproject/project.properties b/nbproject/project.properties index ab90694891..422d61ca70 100644 --- a/nbproject/project.properties +++ b/nbproject/project.properties @@ -4,7 +4,7 @@ app.title=Autopsy ### lowercase version of above app.name=${branding.token} ### if left unset, version will default to today's date -app.version=4.16.0 +app.version=4.17.0 ### build.type must be one of: DEVELOPMENT, RELEASE #build.type=RELEASE build.type=DEVELOPMENT From 78a5c996137f07749b9c33b7ea816eb4eb990e20 Mon Sep 17 00:00:00 2001 From: William Schaefer Date: Tue, 22 Sep 2020 15:35:37 -0400 Subject: [PATCH 10/14] 6794 sort data sources in discovery filter list --- .../autopsy/discovery/ui/DataSourceFilterPanel.java | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/Core/src/org/sleuthkit/autopsy/discovery/ui/DataSourceFilterPanel.java b/Core/src/org/sleuthkit/autopsy/discovery/ui/DataSourceFilterPanel.java index ec4b819696..ab54df4341 100644 --- a/Core/src/org/sleuthkit/autopsy/discovery/ui/DataSourceFilterPanel.java +++ b/Core/src/org/sleuthkit/autopsy/discovery/ui/DataSourceFilterPanel.java @@ -18,6 +18,7 @@ */ package org.sleuthkit.autopsy.discovery.ui; +import java.util.Collections; import org.sleuthkit.autopsy.discovery.search.AbstractFilter; import java.util.List; import java.util.logging.Level; @@ -141,10 +142,13 @@ final class DataSourceFilterPanel extends AbstractDiscoveryFilterPanel { try { DefaultListModel dsListModel = (DefaultListModel) dataSourceList.getModel(); dsListModel.removeAllElements(); - for (DataSource ds : Case.getCurrentCase().getSleuthkitCase().getDataSources()) { + List dataSources = Case.getCurrentCase().getSleuthkitCase().getDataSources(); + Collections.sort(dataSources, (DataSource ds1, DataSource ds2) -> ds1.getName().compareToIgnoreCase(ds2.getName())); + for (DataSource ds : dataSources) { dsListModel.add(count, new DataSourceItem(ds)); count++; } + } catch (TskCoreException ex) { logger.log(Level.SEVERE, "Error loading data sources", ex); dataSourceCheckbox.setEnabled(false); From d7aa9bc7add4abed58316da614007536623c8775 Mon Sep 17 00:00:00 2001 From: Richard Cordovano Date: Tue, 22 Sep 2020 17:03:24 -0400 Subject: [PATCH 11/14] Disable Codacy utility class naming rule --- ruleset.xml | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/ruleset.xml b/ruleset.xml index 468f95087e..0564776c75 100644 --- a/ruleset.xml +++ b/ruleset.xml @@ -219,8 +219,17 @@ - - + + + + + + + + + + + From 1de66cabc489b18d5aed1a298e3640f5594c57fc Mon Sep 17 00:00:00 2001 From: Richard Cordovano Date: Tue, 22 Sep 2020 17:29:51 -0400 Subject: [PATCH 12/14] Format Codacy rules file --- ruleset.xml | 603 ++++++++++++++++++++++++++-------------------------- 1 file changed, 302 insertions(+), 301 deletions(-) diff --git a/ruleset.xml b/ruleset.xml index 0564776c75..b854394891 100644 --- a/ruleset.xml +++ b/ruleset.xml @@ -1,307 +1,308 @@ - - Ruleset used by Autopsy - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + From 3d12a641a8a1a0c6612aa90f323dbf4ae6552c1e Mon Sep 17 00:00:00 2001 From: Richard Cordovano Date: Tue, 22 Sep 2020 17:33:48 -0400 Subject: [PATCH 13/14] Disable Codacy utility class naming rule --- ruleset.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/ruleset.xml b/ruleset.xml index b854394891..24f285b959 100644 --- a/ruleset.xml +++ b/ruleset.xml @@ -226,8 +226,8 @@ - - + From 1520d8159ab95eb4efd5466063a6d5cec6f37c2b Mon Sep 17 00:00:00 2001 From: Eugene Livis Date: Wed, 23 Sep 2020 09:24:47 -0400 Subject: [PATCH 14/14] Reverted --- .../autopsy/imagegallery/ImageGalleryController.java | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/ImageGallery/src/org/sleuthkit/autopsy/imagegallery/ImageGalleryController.java b/ImageGallery/src/org/sleuthkit/autopsy/imagegallery/ImageGalleryController.java index 730b91bfdd..95509c4c16 100644 --- a/ImageGallery/src/org/sleuthkit/autopsy/imagegallery/ImageGalleryController.java +++ b/ImageGallery/src/org/sleuthkit/autopsy/imagegallery/ImageGalleryController.java @@ -246,8 +246,7 @@ public final class ImageGalleryController { tagsManager.registerListener(groupManager); tagsManager.registerListener(categoryManager); hashSetManager = new HashSetManager(drawableDB); - boolean isStale = isDataSourcesTableStale(); - setModelIsStale(isStale); + setModelIsStale(isDataSourcesTableStale()); dbExecutor = getNewDBExecutor(); listeningEnabled.addListener((observable, wasPreviouslyEnabled, isEnabled) -> { @@ -259,7 +258,7 @@ public final class ImageGalleryController { */ if (isEnabled && !wasPreviouslyEnabled && (Case.getCurrentCaseThrows().getCaseType() == CaseType.SINGLE_USER_CASE) - && isStale) { + && isDataSourcesTableStale()) { rebuildDrawablesDb(); } } catch (NoCurrentCaseException ex) {