diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard1_Help.png b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard1_Help.png
index b59e064158..ce2842f348 100644
Binary files a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard1_Help.png and b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard1_Help.png differ
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard3_Help.png b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard3_Help.png
index 927231fc17..a2ee481917 100644
Binary files a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard3_Help.png and b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard3_Help.png differ
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/Autopsy_overview.png b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/Autopsy_overview.png
index b943fd0c5e..d9a9d4c76e 100644
Binary files a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/Autopsy_overview.png and b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/Autopsy_overview.png differ
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/CasePropertiesHelp.png b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/CasePropertiesHelp.png
index 04c1cdb0bb..3615310500 100644
Binary files a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/CasePropertiesHelp.png and b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/CasePropertiesHelp.png differ
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage-icon.png b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage-icon.png
index a36d4714ac..7ef648585c 100644
Binary files a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage-icon.png and b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage-icon.png differ
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage.html b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage.html
index 8403794fb5..0619442532 100644
--- a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage.html
+++ b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage.html
@@ -17,7 +17,7 @@
This will bring up the Add Image wizard. It will guide you through the process. Here are some notes on what is going on during the process:
-
The first panel will ask for the location and type of the disk image to add. You will also need to specify the timezone that the disk image came from so that the dates and times can be properly displayed and converted.
+
The first panel will ask you to browse for the image on your machine. You will also need to specify the timezone that the disk image came from so that the dates and times can be properly displayed and converted.
The second panel is when Autopsy is analyzing the disk image and populating the database with basic information. This can take a few minutes for large images.
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/caseProperties.html b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/caseProperties.html
index 4ce021926d..ce8d64a799 100644
--- a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/caseProperties.html
+++ b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/caseProperties.html
@@ -18,7 +18,6 @@ and open the template in the editor.
Change/update the case name
Delete the current case
-
Remove image(s) from the current case
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/createNewCase.html b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/createNewCase.html
index 5c0eac8426..937ad00978 100644
--- a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/createNewCase.html
+++ b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/createNewCase.html
@@ -15,7 +15,6 @@ and open the template in the editor.
There are several ways to create a new case:
Go to "File" and select "New Case..."
-
Select the icon on the toolbar
Press "Ctrl + N" on the keyboard
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashdb.PNG b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashdb.PNG
index 2ee7b86893..fdca192324 100644
Binary files a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashdb.PNG and b/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashdb.PNG differ
diff --git a/Case/manifest.mf b/Case/manifest.mf
deleted file mode 100644
index e581cd0028..0000000000
--- a/Case/manifest.mf
+++ /dev/null
@@ -1,8 +0,0 @@
-Manifest-Version: 1.0
-AutoUpdate-Show-In-Client: false
-OpenIDE-Module: org.sleuthkit.autopsy.casemodule/1
-OpenIDE-Module-Implementation-Version: 2
-OpenIDE-Module-Layer: org/sleuthkit/autopsy/casemodule/layer.xml
-OpenIDE-Module-Localizing-Bundle: org/sleuthkit/autopsy/casemodule/Bundle.properties
-OpenIDE-Module-Requires: org.openide.windows.WindowManager, org.netbeans.api.javahelp.Help
-
diff --git a/Case/nbproject/genfiles.properties b/Case/nbproject/genfiles.properties
deleted file mode 100644
index a20d5fbe85..0000000000
--- a/Case/nbproject/genfiles.properties
+++ /dev/null
@@ -1,8 +0,0 @@
-build.xml.data.CRC32=a2330d9e
-build.xml.script.CRC32=601bc2ba
-build.xml.stylesheet.CRC32=a56c6a5b@1.46.2
-# This file is used by a NetBeans-based IDE to track changes in generated files such as build-impl.xml.
-# Do not edit this file. You may delete it but then the IDE will never regenerate such files for you.
-nbproject/build-impl.xml.data.CRC32=a2330d9e
-nbproject/build-impl.xml.script.CRC32=65e93a36
-nbproject/build-impl.xml.stylesheet.CRC32=238281d1@1.46.2
diff --git a/Case/build.xml b/Core/build.xml
similarity index 77%
rename from Case/build.xml
rename to Core/build.xml
index 0cb0a367c5..155dc323fc 100644
--- a/Case/build.xml
+++ b/Core/build.xml
@@ -2,7 +2,7 @@
-
- Builds, tests, and runs the project org.sleuthkit.autopsy.casemodule.
+
+ Builds, tests, and runs the project org.sleuthkit.autopsy.core.
diff --git a/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard1_Help.png b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard1_Help.png
new file mode 100644
index 0000000000..b59e064158
Binary files /dev/null and b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard1_Help.png differ
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard2_Help.png b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard2_Help.png
similarity index 100%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard2_Help.png
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard2_Help.png
diff --git a/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard3_Help.png b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard3_Help.png
new file mode 100644
index 0000000000..927231fc17
Binary files /dev/null and b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/AddImageWizard3_Help.png differ
diff --git a/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/Autopsy_overview.png b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/Autopsy_overview.png
new file mode 100644
index 0000000000..b943fd0c5e
Binary files /dev/null and b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/Autopsy_overview.png differ
diff --git a/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/CasePropertiesHelp.png b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/CasePropertiesHelp.png
new file mode 100644
index 0000000000..04c1cdb0bb
Binary files /dev/null and b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/CasePropertiesHelp.png differ
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/NewCaseWizardHelp.png b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/NewCaseWizardHelp.png
similarity index 100%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/NewCaseWizardHelp.png
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/NewCaseWizardHelp.png
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/aboutImage.html b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/aboutImage.html
similarity index 98%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/aboutImage.html
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/aboutImage.html
index 7d0c8a61a6..d2c5578738 100644
--- a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/aboutImage.html
+++ b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/aboutImage.html
@@ -1,30 +1,30 @@
-
-
-
- Disk Image Basics
-
-
-
-
-
About Disk Images
-
- In Autopsy, an "image" refers to a byte-for-byte copy of a hard drive or other storage media. To analyze an image, you must use the Add Image Wizardto add it to a case.
-
-
Autopsy populates an embedded database for each image that it imports. This database is a SQLite database and it contains all of the file system metadata from the image. The database is stored in the case directory, but the image will stay in its original location. The image must remain accessible for the duration of the anlaysis because the database contains only basic file system information. The image is needed to retrieve file content.
-
-
Supported Formats
-
- Currently, Autopsy supports these image formats:
-
-
Raw Single (For example: *.img, *.dd, etc)
-
Raw Split (For example: *.001, *.002, *.aa, *.ab, etc)
-
EnCase (For example: *.e01, *e02, etc)
-
-
-
Removing an Image
-
- You cannot currently remove an image from a case.
-
-
-
-
+
+
+
+ Disk Image Basics
+
+
+
+
+
About Disk Images
+
+ In Autopsy, an "image" refers to a byte-for-byte copy of a hard drive or other storage media. To analyze an image, you must use the Add Image Wizardto add it to a case.
+
+
Autopsy populates an embedded database for each image that it imports. This database is a SQLite database and it contains all of the file system metadata from the image. The database is stored in the case directory, but the image will stay in its original location. The image must remain accessible for the duration of the anlaysis because the database contains only basic file system information. The image is needed to retrieve file content.
+
+
Supported Formats
+
+ Currently, Autopsy supports these image formats:
+
+
Raw Single (For example: *.img, *.dd, etc)
+
Raw Split (For example: *.001, *.002, *.aa, *.ab, etc)
+
EnCase (For example: *.e01, *e02, etc)
+
+
+
Removing an Image
+
+ You cannot currently remove an image from a case.
+
+
+
+
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/addImage-icon.png b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage-icon.png
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/addImage-icon.png
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage-icon.png
diff --git a/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage.html b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage.html
new file mode 100644
index 0000000000..9348bf490b
--- /dev/null
+++ b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/addImage.html
@@ -0,0 +1,30 @@
+
+
+
+ Adding Image Wizard
+
+
+
+
+
Adding An Image
+
+ There are two ways to add an image to the currently opened case:
+
+
Go to "File" and select "Add Image..."
+
Select the icon on the toolbar
+
+
+
+ This will bring up the Add Image wizard. It will guide you through the process. Here are some notes on what is going on during the process:
+
+
The first panel will ask for the location and type of the disk image to add. You will also need to specify the timezone that the disk image came from so that the dates and times can be properly displayed and converted.
+
+
The second panel is when Autopsy is analyzing the disk image and populating the database with basic information. This can take a few minutes for large images.
+
+
The third panel allows you to choose which ingest modules to run on the image. Refer to the Image Ingest part of the help guide for more details.
+
+
Once you select the ingest modules that you want to use, they will run in the background. You can choose to add another image or exit the Add Image wizard.
+
+
Note that Autopsy will store the path to the image in its configuration file. If the image moves, then Autopsy will give an error because it can't find the image file.
+
+
\ No newline at end of file
diff --git a/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/caseProperties.html b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/caseProperties.html
new file mode 100644
index 0000000000..4ce021926d
--- /dev/null
+++ b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/caseProperties.html
@@ -0,0 +1,48 @@
+
+
+
+
+ Case Properties Window
+
+
+
+
+
Case Properties Window
+
+ Case Properties Window is the window where you can check some information about the currently opened case (case name, case creation date, case directory, and images in this case.
+
+ In this window, you can also do the following things:
+
+
Change/update the case name
+
Delete the current case
+
Remove image(s) from the current case
+
+
+
+
How to Open Case Properties Window
+
+ To open the "Case Properties" window, go to "File" and then select "Case Properties..."
+
+
+
Example
+
+ Here's an example of the "Case Properties" window:
+
+
+
+
+
\ No newline at end of file
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-about.html b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-about.html
similarity index 98%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-about.html
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-about.html
index ced5e907a3..fa6abf736f 100644
--- a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-about.html
+++ b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-about.html
@@ -1,26 +1,26 @@
-
-
- About Cases
-
-
-
-
-
About Cases
-
- In Autopsy, a "case" is a container concept for a set of images. The set of images could be from multiple drives in a single computer or from multiple computers. When you make a case, it will create a directory to hold all of the information. The directory will contain a configuration file, some databases, and some other information. The configuration file as a .aut extension.
-
-
-
If you want to view case details or edit some case information, use the Case Properties window.
-
-
- To open a case, choose "Open Case" from the File menu or use the "Ctrl + O" keyboard short cut.
- Navigate to the case directory and select the ".aut" file.
-
-
-
+
+
+ About Cases
+
+
+
+
+
About Cases
+
+ In Autopsy, a "case" is a container concept for a set of images. The set of images could be from multiple drives in a single computer or from multiple computers. When you make a case, it will create a directory to hold all of the information. The directory will contain a configuration file, some databases, and some other information. The configuration file as a .aut extension.
+
+
+
If you want to view case details or edit some case information, use the Case Properties window.
+
+
+ To open a case, choose "Open Case" from the File menu or use the "Ctrl + O" keyboard short cut.
+ Navigate to the case directory and select the ".aut" file.
+
+
+
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-hs.xml b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-hs.xml
similarity index 100%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-hs.xml
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-hs.xml
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-idx.xml b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-idx.xml
similarity index 100%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-idx.xml
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-idx.xml
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-map.xml b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-map.xml
similarity index 100%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-map.xml
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-map.xml
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-toc.xml b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-toc.xml
similarity index 100%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-toc.xml
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/casemodule-toc.xml
diff --git a/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/createNewCase.html b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/createNewCase.html
new file mode 100644
index 0000000000..5c0eac8426
--- /dev/null
+++ b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/createNewCase.html
@@ -0,0 +1,43 @@
+
+
+
+
+ Creating A Case
+
+
+
+
+
Creating a Case
+
+ There are several ways to create a new case:
+
+
Go to "File" and select "New Case..."
+
Select the icon on the toolbar
+
Press "Ctrl + N" on the keyboard
+
+
+
+
The "New Case" wizard dialog will open and you will need to enter the case name and base directory. Each case will have its own directory and the path of the directory is created by combining the "base directory" with the "case name". If the directory already exists, you will need to either delete the existing directory or choose a different combination of names.
+
+
Example:
+
+ Here's an example of the "New Case" wizard dialog:
+
+
+
+
+
\ No newline at end of file
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashDbMgmt.html b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashDbMgmt.html
similarity index 98%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashDbMgmt.html
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashDbMgmt.html
index a2a81abef9..8c9339045f 100644
--- a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashDbMgmt.html
+++ b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashDbMgmt.html
@@ -1,48 +1,48 @@
-
-
-
- Hash Database Management
-
-
-
-
-
Hash Database Management Window
-
- The Hash Database Management window is where you can set and update your hash database information. Hash databases are used to identify files that are 'known'.
-
-
Known good files are those that can be safely ignored. This set of files frequently includes standard OS and application files.
-
Known bad (also called notable) files are those that should raise awareness. This set will vary depending on the type of investigation, but common examples include contraband images and malware.
-
-
-
-
Notable / Known Bad Hashsets
-
Autopsy allows for multiple known bad hash databases to be set. Autopsy supports three formats:
-
-
EnCase: An EnCase hashset file.
-
MD5sum: Output from running the md5, md5sum, or md5deep program on a set of files.
-
NSRL: The format of the NSRL database
-
-
-
NIST NSRL
-
Autopsy can use the NIST NSRL to detect 'known files'. Note that the NSRL contains hashes of 'known files' that may be good or bad depending on your perspective and investigation type. For example, the existence of a piece of financial software
- may be interesting to your investigation and that software could be in the NSRL. Therefore, Autopsy treats files that are found in the NSRL as simply 'known' and does not specify good or bad. Ingest modules have the option of ignoring files that were found in the NSRL.
-
-
To use the NSRL, you must concatenate all of the NSRLFile.txt files together. You can use 'cat' on a Unix system or from within Cygwin to do this.
-
-
Adding Hashsets
-
Autopsy needs an index of the hashset. It can make one if you import only the hashset. When you select the database from within this window, it will tell you if the index needs to be created. Autopsy
- uses the hash database management system from The Sleuth Kit. You can manually create an index using the 'hfind' command line tool.
-
-
You can also specify only the index file and not use the full hashset. This can save space. To do this, specify the .idx file from the Hash Database Management window.
-
-
Using Hashsets
-
There is an ingest module that will hash the files and look them up in the hashsets. It will flag files that were in the notable hashset and those results will be shown in the Results tree of the Data Explorer.
-
-
Other ingest modules are able to use the known status of a file to decide if they should ignore the file or process it.
-
-
You can also see the results in the File Search window. There is an option to choose the 'known status'. From here, you can do a search to see all 'known bad' files.
- From here, you can also choose to ignore all 'known' files that were found in the NSRL. You can also see the status of the file in a column when the file is listed.
+ The Hash Database Management window is where you can set and update your hash database information. Hash databases are used to identify files that are 'known'.
+
+
Known good files are those that can be safely ignored. This set of files frequently includes standard OS and application files.
+
Known bad (also called notable) files are those that should raise awareness. This set will vary depending on the type of investigation, but common examples include contraband images and malware.
+
+
+
+
Notable / Known Bad Hashsets
+
Autopsy allows for multiple known bad hash databases to be set. Autopsy supports three formats:
+
+
EnCase: An EnCase hashset file.
+
MD5sum: Output from running the md5, md5sum, or md5deep program on a set of files.
+
NSRL: The format of the NSRL database
+
+
+
NIST NSRL
+
Autopsy can use the NIST NSRL to detect 'known files'. Note that the NSRL contains hashes of 'known files' that may be good or bad depending on your perspective and investigation type. For example, the existence of a piece of financial software
+ may be interesting to your investigation and that software could be in the NSRL. Therefore, Autopsy treats files that are found in the NSRL as simply 'known' and does not specify good or bad. Ingest modules have the option of ignoring files that were found in the NSRL.
+
+
To use the NSRL, you must concatenate all of the NSRLFile.txt files together. You can use 'cat' on a Unix system or from within Cygwin to do this.
+
+
Adding Hashsets
+
Autopsy needs an index of the hashset. It can make one if you import only the hashset. When you select the database from within this window, it will tell you if the index needs to be created. Autopsy
+ uses the hash database management system from The Sleuth Kit. You can manually create an index using the 'hfind' command line tool.
+
+
You can also specify only the index file and not use the full hashset. This can save space. To do this, specify the .idx file from the Hash Database Management window.
+
+
Using Hashsets
+
There is an ingest module that will hash the files and look them up in the hashsets. It will flag files that were in the notable hashset and those results will be shown in the Results tree of the Data Explorer.
+
+
Other ingest modules are able to use the known status of a file to decide if they should ignore the file or process it.
+
+
You can also see the results in the File Search window. There is an option to choose the 'known status'. From here, you can do a search to see all 'known bad' files.
+ From here, you can also choose to ignore all 'known' files that were found in the NSRL. You can also see the status of the file in a column when the file is listed.
+
+
+
+
diff --git a/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashdb.PNG b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashdb.PNG
new file mode 100644
index 0000000000..2ee7b86893
Binary files /dev/null and b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/hashdb.PNG differ
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/new-icon.png b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/new-icon.png
similarity index 100%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/new-icon.png
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/new-icon.png
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/open-icon.png b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/open-icon.png
similarity index 100%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/open-icon.png
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/open-icon.png
diff --git a/Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/overview.html b/Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/overview.html
old mode 100755
new mode 100644
similarity index 100%
rename from Case/javahelp/org/sleuthkit/autopsy/casemodule/docs/overview.html
rename to Core/javahelp/org/sleuthkit/autopsy/casemodule/docs/overview.html
diff --git a/Core/manifest.mf b/Core/manifest.mf
new file mode 100644
index 0000000000..52e09f6dc3
--- /dev/null
+++ b/Core/manifest.mf
@@ -0,0 +1,8 @@
+Manifest-Version: 1.0
+OpenIDE-Module: org.sleuthkit.autopsy.core/3
+OpenIDE-Module-Localizing-Bundle: org/sleuthkit/autopsy/core/Bundle.properties
+OpenIDE-Module-Layer: org/sleuthkit/autopsy/core/layer.xml
+OpenIDE-Module-Implementation-Version: 1
+OpenIDE-Module-Requires: org.openide.windows.WindowManager, org.netbeans.api.javahelp.Help
+AutoUpdate-Show-In-Client: true
+
diff --git a/Case/nbproject/build-impl.xml b/Core/nbproject/build-impl.xml
similarity index 96%
rename from Case/nbproject/build-impl.xml
rename to Core/nbproject/build-impl.xml
index 974323e28a..061262d2d8 100644
--- a/Case/nbproject/build-impl.xml
+++ b/Core/nbproject/build-impl.xml
@@ -3,7 +3,7 @@
*** GENERATED FROM project.xml - DO NOT EDIT ***
*** EDIT ../build.xml INSTEAD ***
-->
-
+
diff --git a/Case/nbproject/platform.properties b/Core/nbproject/platform.properties
similarity index 100%
rename from Case/nbproject/platform.properties
rename to Core/nbproject/platform.properties
diff --git a/Case/nbproject/project.properties b/Core/nbproject/project.properties
similarity index 72%
rename from Case/nbproject/project.properties
rename to Core/nbproject/project.properties
index 65c2412360..e84197de12 100644
--- a/Case/nbproject/project.properties
+++ b/Core/nbproject/project.properties
@@ -1,4 +1,3 @@
javac.source=1.6
javac.compilerargs=-Xlint -Xlint:-serial
-javahelp.hs=casemodule-hs.xml
spec.version.base=1.0
diff --git a/Case/nbproject/project.xml b/Core/nbproject/project.xml
similarity index 98%
rename from Case/nbproject/project.xml
rename to Core/nbproject/project.xml
index d264d97853..4151ee9f98 100644
--- a/Case/nbproject/project.xml
+++ b/Core/nbproject/project.xml
@@ -3,10 +3,9 @@
org.netbeans.modules.apisupport.project
- org.sleuthkit.autopsy.casemodule
+ org.sleuthkit.autopsy.core
-
org.netbeans.modules.settings
diff --git a/Case/nbproject/suite.properties b/Core/nbproject/suite.properties
similarity index 100%
rename from Case/nbproject/suite.properties
rename to Core/nbproject/suite.properties
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageAction.java b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageAction.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageAction.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageAction.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageErrorsDialog.form b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageErrorsDialog.form
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageErrorsDialog.form
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageErrorsDialog.form
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageErrorsDialog.java b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageErrorsDialog.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageErrorsDialog.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageErrorsDialog.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel1.form b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel1.form
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel1.form
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel1.form
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel1.java b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel1.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel1.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel1.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel2.form b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel2.form
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel2.form
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel2.form
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel2.java b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel2.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel2.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel2.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel3.form b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel3.form
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel3.form
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel3.form
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel3.java b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel3.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel3.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel3.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel4.form b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel4.form
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel4.form
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel4.form
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel4.java b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel4.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel4.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageVisualPanel4.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageWizardIterator.java b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageWizardIterator.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageWizardIterator.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageWizardIterator.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel1.java b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel1.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel1.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel1.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel2.java b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel2.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel2.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel2.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel3.java b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel3.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel3.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel3.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel4.java b/Core/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel4.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel4.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/AddImageWizardPanel4.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/Bundle.properties b/Core/src/org/sleuthkit/autopsy/casemodule/Bundle.properties.old
old mode 100755
new mode 100644
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/Bundle.properties
rename to Core/src/org/sleuthkit/autopsy/casemodule/Bundle.properties.old
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/ButtonColumn.java b/Core/src/org/sleuthkit/autopsy/casemodule/ButtonColumn.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/ButtonColumn.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/ButtonColumn.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/Case.java b/Core/src/org/sleuthkit/autopsy/casemodule/Case.java
old mode 100755
new mode 100644
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/Case.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/Case.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/CaseCloseAction.java b/Core/src/org/sleuthkit/autopsy/casemodule/CaseCloseAction.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/CaseCloseAction.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/CaseCloseAction.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/CaseConfigFileInterface.java b/Core/src/org/sleuthkit/autopsy/casemodule/CaseConfigFileInterface.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/CaseConfigFileInterface.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/CaseConfigFileInterface.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/CaseDeleteAction.java b/Core/src/org/sleuthkit/autopsy/casemodule/CaseDeleteAction.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/CaseDeleteAction.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/CaseDeleteAction.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/CaseNewAction.java b/Core/src/org/sleuthkit/autopsy/casemodule/CaseNewAction.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/CaseNewAction.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/CaseNewAction.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/CaseOpenAction.java b/Core/src/org/sleuthkit/autopsy/casemodule/CaseOpenAction.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/CaseOpenAction.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/CaseOpenAction.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/CasePropertiesAction.java b/Core/src/org/sleuthkit/autopsy/casemodule/CasePropertiesAction.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/CasePropertiesAction.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/CasePropertiesAction.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/CasePropertiesForm.form b/Core/src/org/sleuthkit/autopsy/casemodule/CasePropertiesForm.form
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/CasePropertiesForm.form
rename to Core/src/org/sleuthkit/autopsy/casemodule/CasePropertiesForm.form
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/CasePropertiesForm.java b/Core/src/org/sleuthkit/autopsy/casemodule/CasePropertiesForm.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/CasePropertiesForm.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/CasePropertiesForm.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/CueBannerPanel.form b/Core/src/org/sleuthkit/autopsy/casemodule/CueBannerPanel.form
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/CueBannerPanel.form
rename to Core/src/org/sleuthkit/autopsy/casemodule/CueBannerPanel.form
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/CueBannerPanel.java b/Core/src/org/sleuthkit/autopsy/casemodule/CueBannerPanel.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/CueBannerPanel.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/CueBannerPanel.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/GeneralFilter.java b/Core/src/org/sleuthkit/autopsy/casemodule/GeneralFilter.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/GeneralFilter.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/GeneralFilter.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/IngestConfigurator.java b/Core/src/org/sleuthkit/autopsy/casemodule/IngestConfigurator.java
similarity index 96%
rename from Case/src/org/sleuthkit/autopsy/casemodule/IngestConfigurator.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/IngestConfigurator.java
index 9a3b9c6b31..ce5f34ac63 100644
--- a/Case/src/org/sleuthkit/autopsy/casemodule/IngestConfigurator.java
+++ b/Core/src/org/sleuthkit/autopsy/casemodule/IngestConfigurator.java
@@ -1,62 +1,62 @@
-/*
- * Autopsy Forensic Browser
- *
- * Copyright 2011 Basis Technology Corp.
- * Contact: carrier sleuthkit org
- *
- * Licensed under the Apache License, Version 2.0 (the "License");
- * you may not use this file except in compliance with the License.
- * You may obtain a copy of the License at
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
- * Unless required by applicable law or agreed to in writing, software
- * distributed under the License is distributed on an "AS IS" BASIS,
- * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
- * See the License for the specific language governing permissions and
- * limitations under the License.
- */
-package org.sleuthkit.autopsy.casemodule;
-
-import javax.swing.JPanel;
-import org.sleuthkit.datamodel.Image;
-
-/**
- * Lookup interface for ingest configuration dialog
- */
-public interface IngestConfigurator {
- /**
- * get JPanel container with the configurator
- * @return
- */
- JPanel getIngestConfigPanel();
-
- /**
- * set image for the ingest
- * @param image to enqueue to ingest
- */
- void setImage(Image image);
-
- /**
- * start ingest enqueing previously set image
- */
- void start();
-
- /**
- * save configuration of lastly selected service
- */
- void save();
-
- /**
- * reload the simple panel
- */
- void reload();
-
- /**
- * find out if ingest is currently running
- *
- * @return true if ingest process is running, false otherwise
- */
- boolean isIngestRunning();
-
-}
+/*
+ * Autopsy Forensic Browser
+ *
+ * Copyright 2011 Basis Technology Corp.
+ * Contact: carrier sleuthkit org
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.sleuthkit.autopsy.casemodule;
+
+import javax.swing.JPanel;
+import org.sleuthkit.datamodel.Image;
+
+/**
+ * Lookup interface for ingest configuration dialog
+ */
+public interface IngestConfigurator {
+ /**
+ * get JPanel container with the configurator
+ * @return
+ */
+ JPanel getIngestConfigPanel();
+
+ /**
+ * set image for the ingest
+ * @param image to enqueue to ingest
+ */
+ void setImage(Image image);
+
+ /**
+ * start ingest enqueing previously set image
+ */
+ void start();
+
+ /**
+ * save configuration of lastly selected service
+ */
+ void save();
+
+ /**
+ * reload the simple panel
+ */
+ void reload();
+
+ /**
+ * find out if ingest is currently running
+ *
+ * @return true if ingest process is running, false otherwise
+ */
+ boolean isIngestRunning();
+
+}
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel1.form b/Core/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel1.form
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel1.form
rename to Core/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel1.form
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel1.java b/Core/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel1.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel1.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel1.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel2.form b/Core/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel2.form
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel2.form
rename to Core/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel2.form
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel2.java b/Core/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel2.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel2.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/NewCaseVisualPanel2.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardAction.java b/Core/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardAction.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardAction.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardAction.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardPanel1.java b/Core/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardPanel1.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardPanel1.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardPanel1.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardPanel2.java b/Core/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardPanel2.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardPanel2.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/NewCaseWizardPanel2.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/OpenRecentCasePanel.form b/Core/src/org/sleuthkit/autopsy/casemodule/OpenRecentCasePanel.form
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/OpenRecentCasePanel.form
rename to Core/src/org/sleuthkit/autopsy/casemodule/OpenRecentCasePanel.form
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/OpenRecentCasePanel.java b/Core/src/org/sleuthkit/autopsy/casemodule/OpenRecentCasePanel.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/OpenRecentCasePanel.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/OpenRecentCasePanel.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/RecentCases.java b/Core/src/org/sleuthkit/autopsy/casemodule/RecentCases.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/RecentCases.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/RecentCases.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/RecentItems.java b/Core/src/org/sleuthkit/autopsy/casemodule/RecentItems.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/RecentItems.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/RecentItems.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/StartupWindow.java b/Core/src/org/sleuthkit/autopsy/casemodule/StartupWindow.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/StartupWindow.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/StartupWindow.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/UpdateRecentCases.java b/Core/src/org/sleuthkit/autopsy/casemodule/UpdateRecentCases.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/UpdateRecentCases.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/UpdateRecentCases.java
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/XMLCaseManagement.java b/Core/src/org/sleuthkit/autopsy/casemodule/XMLCaseManagement.java
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/XMLCaseManagement.java
rename to Core/src/org/sleuthkit/autopsy/casemodule/XMLCaseManagement.java
diff --git a/Core/src/org/sleuthkit/autopsy/casemodule/addImage-icon.png b/Core/src/org/sleuthkit/autopsy/casemodule/addImage-icon.png
new file mode 100644
index 0000000000..a36d4714ac
Binary files /dev/null and b/Core/src/org/sleuthkit/autopsy/casemodule/addImage-icon.png differ
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/btn_icon_add_image.png b/Core/src/org/sleuthkit/autopsy/casemodule/btn_icon_add_image.png
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/btn_icon_add_image.png
rename to Core/src/org/sleuthkit/autopsy/casemodule/btn_icon_add_image.png
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/btn_icon_close_case.png b/Core/src/org/sleuthkit/autopsy/casemodule/btn_icon_close_case.png
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/btn_icon_close_case.png
rename to Core/src/org/sleuthkit/autopsy/casemodule/btn_icon_close_case.png
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/btn_icon_create_new_case.png b/Core/src/org/sleuthkit/autopsy/casemodule/btn_icon_create_new_case.png
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/btn_icon_create_new_case.png
rename to Core/src/org/sleuthkit/autopsy/casemodule/btn_icon_create_new_case.png
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/btn_icon_open_existing.png b/Core/src/org/sleuthkit/autopsy/casemodule/btn_icon_open_existing.png
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/btn_icon_open_existing.png
rename to Core/src/org/sleuthkit/autopsy/casemodule/btn_icon_open_existing.png
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/btn_icon_open_recent.png b/Core/src/org/sleuthkit/autopsy/casemodule/btn_icon_open_recent.png
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/btn_icon_open_recent.png
rename to Core/src/org/sleuthkit/autopsy/casemodule/btn_icon_open_recent.png
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/casemodule-helpset.xml b/Core/src/org/sleuthkit/autopsy/casemodule/casemodule-helpset.xml
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/casemodule-helpset.xml
rename to Core/src/org/sleuthkit/autopsy/casemodule/casemodule-helpset.xml
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/close-icon.png b/Core/src/org/sleuthkit/autopsy/casemodule/close-icon.png
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/close-icon.png
rename to Core/src/org/sleuthkit/autopsy/casemodule/close-icon.png
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/layer.xml b/Core/src/org/sleuthkit/autopsy/casemodule/layer.xml.old
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/layer.xml
rename to Core/src/org/sleuthkit/autopsy/casemodule/layer.xml.old
diff --git a/Case/src/org/sleuthkit/autopsy/casemodule/package.dox b/Core/src/org/sleuthkit/autopsy/casemodule/package.dox
similarity index 100%
rename from Case/src/org/sleuthkit/autopsy/casemodule/package.dox
rename to Core/src/org/sleuthkit/autopsy/casemodule/package.dox
diff --git a/Core/src/org/sleuthkit/autopsy/casemodule/welcome_logo.png b/Core/src/org/sleuthkit/autopsy/casemodule/welcome_logo.png
new file mode 100644
index 0000000000..e7a17e0815
Binary files /dev/null and b/Core/src/org/sleuthkit/autopsy/casemodule/welcome_logo.png differ
diff --git a/Core/src/org/sleuthkit/autopsy/core/Bundle.properties b/Core/src/org/sleuthkit/autopsy/core/Bundle.properties
new file mode 100644
index 0000000000..ecbba6baf8
--- /dev/null
+++ b/Core/src/org/sleuthkit/autopsy/core/Bundle.properties
@@ -0,0 +1,130 @@
+OpenIDE-Module-Name=Core
+
+CTL_AddImage=Add Image...
+CTL_AddImageButton=Add Image
+CTL_CaseAction=Case
+CTL_CaseCloseAct=Close Case
+CTL_CaseNewAction=New Case...
+#CTL_CaseOpenActionOld=Open Case(old)...
+CTL_CasePropertiesAction=Case Properties...
+CTL_CaseTopComponent=Case Window
+#CTL_NewCaseAct=New Case(Old)...
+CTL_OpenAction=Open Case...
+CTL_RecentCases=Recent Cases
+CTL_CaseDeleteAction=Delete Case
+CTL_SaveCaseAction=Save Case
+CTL_testAction=test
+CTL_testTopComponent=test Window
+HINT_CaseTopComponent=This is a Case window
+HINT_testTopComponent=This is a test window
+Menu/File/org-sleuthkit-autopsy-casemodule-CaseCloseAct.shadow=
+Menu/File/org-sleuthkit-autopsy-casemodule-OpenAction.shadow=Open Case
+CaseVisualPanel1.jLabel1.text=Name
+CaseVisualPanel1.jLabel2.text=Image Path:
+CaseVisualPanel1.jLabel3.text=Database Path:
+CaseTopComponent.jLabel1.text=Name
+CaseVisualPanel1.NameField.text=
+CaseVisualPanel1.ImgPath.text=
+CaseVisualPanel1.DbPath.text=
+CaseTopComponent.jLabel2.text=Image Path
+CaseTopComponent.jLabel3.text=DB Path
+CaseVisualPanel1.ImgPathBrowserButton.text=Browse
+CaseVisualPanel1.DbPathBrowserButton.text=Browse
+NewCaseVisualPanel1.jLabel1.text=Name
+NewCaseVisualPanel1.jTextField1.text=
+NewCaseVisualPanel1.jLabel2.text=Image Type:
+NewCaseVisualPanel1.jRadioButton1.text=Raw Single .img .dd
+NewCaseVisualPanel1.jRadioButton2.text=Raw Split .001 .002 etc
+NewCaseVisualPanel1.jRadioButton3.text=Encase .e01
+NewCaseVisualPanel1.nameLabel.text_1=Name
+NewCaseVisualPanel1.NameField.text_1=
+NewCaseVisualPanel1.TypeLabel.text_1=Image Type:
+NewCaseVisualPanel1.rawSingleRadio.text_1=Raw Single .img .dd
+NewCaseVisualPanel1.rawSplitRadio.text_1=Raw Split .001 .002 etc
+NewCaseVisualPanel1.encaseRadio.text_1=EnCase .e01
+NewCaseVisualPanel2.jLabel1.text=Image Path:
+NewCaseVisualPanel2.jLabel2.text=DataBase Path:
+NewCaseVisualPanel2.descriptionText.text=variable text
+NewCaseVisualPanel2.ImgBrowserButton.text=Browse
+NewCaseVisualPanel2.DcBrowserButton.text=Browse
+NewCaseVisualPanel2.ImagePathField.text=
+NewCaseVisualPanel2.DbPathField.text=
+CaseVisualPanel1.jLabel4.text=Image Type:
+CaseVisualPanel1.rawSingle.text=Raw Single .img .dd
+CaseVisualPanel1.rawSplit.text=Raw Split .001 .002 etc
+CaseVisualPanel1.encase.text=EnCase .e01 .e02 etc
+CaseVisualPanel1.multipleSelectLabel.text=Single Image: Multiple Select Disabled
+CaseVisualPanel1.jLabel5.text=If a database has not already been loaded / created for the chosen image use this button: (could take a few minutes)
+CaseVisualPanel1.ProgressLabel.text=
+CaseVisualPanel1.createDbButton.text=Create Database
+NewCaseVisualPanel1.jLabel1.text_1=Enter New Case Information:
+NewCaseVisualPanel1.caseNameLabel.text_1=Case Name:
+NewCaseVisualPanel1.caseDirLabel.text=Base Directory:
+NewCaseVisualPanel1.caseDirBrowseButton.text=Browse
+NewCaseVisualPanel1.caseNameTextField.text_1=
+NewCaseVisualPanel1.jLabel2.text_1=Case data will be stored in the following directory:
+NewCaseVisualPanel1.caseParentDirTextField.text=
+NewCaseVisualPanel1.caseDirTextField.text_1=
+CasePropertiesForm.caseDirLabel.text=Case Directory:
+CasePropertiesForm.crDateLabel.text=Created Date:
+CasePropertiesForm.caseNameLabel.text=Case Name:
+CasePropertiesForm.crDateTextField.text=
+CasePropertiesForm.caseNameTextField.text=
+CasePropertiesForm.updateCaseNameButton.text=Update
+CasePropertiesForm.casePropLabel.text=Case Information
+CasePropertiesForm.genInfoLabel.text=General Information
+CasePropertiesForm.imgInfoLabel.text=Images Information
+CasePropertiesForm.OKButton.text=OK
+CasePropertiesForm.deleteCaseButton.text=Delete Case
+CueBannerPanel.autopsyLogo.text=
+CueBannerPanel.createNewLabel.text=Create New Case
+CueBannerPanel.autopsyLabel.text=Autopsy
+CueBannerPanel.welcomeLabel.text=Welcome to
+CueBannerPanel.openLabel.text=Open Existing Case
+CueBannerPanel.closeButton.text=Close
+CueBannerPanel.openRecentLabel.text=Open Recent Case
+CueBannerPanel.newCaseButton.text=
+CueBannerPanel.openCaseButton.text=
+CueBannerPanel.openRecentButton.text=
+OpenRecentCasePanel.cancelButton.text=Cancel
+OpenRecentCasePanel.jLabel1.text=Recent Cases
+AddImageVisualPanel1.imgInfoLabel.text=Enter Disk Image Information:
+AddImageVisualPanel2.crDbLabel.text=Adding Image
+AddImageVisualPanel2.jLabel5.text=Processing Image and Adding to Database :
+AddImageVisualPanel2.jLabel1.text= We are now analyzing the disk image to extract volume and file system data and populate a local database.
+AddImageVisualPanel1.timeZoneLabel.text=Please select the image timezone:
+AddImageVisualPanel1.imgPathTextField.text=
+AddImageVisualPanel1.imgPathLabel.text=Image Path:
+AddImageVisualPanel1.imgPathBrowserButton.text=Browse
+NewJPanel.jLabel1.text=
+NewJPanel.jLabel2.text=NSRL Index
+NewJPanel.jLabel5.text=The NSRL index is used to idenify "known" files.
+NewJPanel.jFormattedTextField1.text=jFormattedTextField1
+NewJPanel.jButton1.text=Rename
+NewJPanel.jLabel4.text=Database:
+AddImageVisualPanel2.indexImageCheckBox.text=Index image for keyword search
+AddImageVisualPanel1.jLabel2.text= Press 'Next' to analyze the disk image to extract volume and file system data and populate a local database.
+AddImageVisualPanel4.jLabel1.text=Image was successfully added to the case and is being processed.
+AddImageVisualPanel4.crDbLabel.text=Image Added and Being Processed
+AddImageVisualPanel4.addImgButton.text=Add Another Image
+AddImageVisualPanel3.titleLabel.text=Configure Ingest Modules
+AddImageVisualPanel3.subtitleLabel.text=Image has been commited. You can configure and run ingest modules on the new image.
+CasePropertiesForm.caseNumberLabel.text=Case Number:
+CasePropertiesForm.examinerLabel.text=Examiner:
+CasePropertiesForm.caseNumberTextField.text=
+CasePropertiesForm.examinerTextField.text=
+NewCaseVisualPanel2.caseNumberTextField.text=
+NewCaseVisualPanel2.examinerLabel.text=Examiner:
+NewCaseVisualPanel2.caseNumberLabel.text=Case Number:
+NewCaseVisualPanel2.examinerTextField.text=
+NewCaseVisualPanel2.optionalLabel.text=Optional: Set Case Number and Examiner
+AddImageVisualPanel1.noFatOrphansCheckbox.toolTipText=
+AddImageVisualPanel1.noFatOrphansCheckbox.text=Ignore orphan files in FAT file systems
+AddImageVisualPanel1.optionsLabel1.text=Options to produce results faster (although some data will not be searched):
+AddImageErrorsDialog.title=Add Image Log
+AddImageErrorsDialog.copyButton.toolTipText=Copy errors to clipboard
+AddImageErrorsDialog.copyButton.text=Copy
+AddImageErrorsDialog.closeButton.toolTipText=Close this window
+AddImageErrorsDialog.closeButton.text=Close
+AddImageVisualPanel4.jLabel2.text=You can add another image or click Finish to return to the case and view results.
+
diff --git a/Core/src/org/sleuthkit/autopsy/core/layer.xml b/Core/src/org/sleuthkit/autopsy/core/layer.xml
new file mode 100644
index 0000000000..e3af281221
--- /dev/null
+++ b/Core/src/org/sleuthkit/autopsy/core/layer.xml
@@ -0,0 +1,166 @@
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/String_Content_Viewer.png b/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/String_Content_Viewer.png
index cb0b296174..7cdf01203e 100644
Binary files a/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/String_Content_Viewer.png and b/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/String_Content_Viewer.png differ
diff --git a/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/datacontent-about.html b/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/datacontent-about.html
index fe6fa34e69..a48d3afec7 100644
--- a/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/datacontent-about.html
+++ b/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/datacontent-about.html
@@ -8,7 +8,7 @@
Content Viewers
- The Content Viewer area is in the lower right area of the interface. This area is used to view a specific file in a variety of formats. There are different tabs for different viewers. Not all tabs support all file types, so only some of them will be enabled. To display data in this area, it must be selected from the Result Viewer window (upper right).
+ The Content Viewer area is in the lower right area of the interface. This area is used to view a specific file in a variety of formats. There are different tabs for different viewers. Not all tabs support all file types, so only some of them will be enabled. To display data in this area, a file must be selected from the Result Viewer window.
The Content Viewer area is part of a plug-in framework. You can install modules that will add more viewer types. This section describes the viewers that come by default with Autopsy.
diff --git a/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/dataexplorer-about.html b/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/dataexplorer-about.html
index 39cd795ab6..f5f2f62a95 100644
--- a/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/dataexplorer-about.html
+++ b/CoreComponents/javahelp/org/sleuthkit/autopsy/corecomponents/docs/dataexplorer-about.html
@@ -10,16 +10,16 @@ and open the template in the editor.
-
About Data Explorers
-
- The Data Explorer area of the Autopsy interface is the area in the left-hand side. It provides different methods for finding relevant data. It will publish its results to the upper-right Result Viewer area.
- In general, if you are looking for an 'analysis technique', then this is where you should look.
-
-
Some example Data Explorers include:
+
About the Data Explorer
+
The Data Explorer view in Autopsy is the directory tree node structure seen on the left hand side. It provides different methods for finding relevant data, such as:
Different extracted content types (bookmarks, web history, installed programs, etc.)
+
Keyword hits
+
File bookmarks
+
+
The Data Explorer will publish all relevant data to the Result Viewer when specific nodes are clicked. In general, if you are looking for an 'analysis technique', then this is where you should look.