From 8cbe47bd3ea47b22763697ae1b79dd889b9dea0f Mon Sep 17 00:00:00 2001 From: Brian Carrier Date: Wed, 19 Sep 2018 00:29:06 -0400 Subject: [PATCH 1/3] fix resolving bug and always go lower case. Progress update --- .../modules/plaso/PlasoIngestModule.java | 24 ++++++++++++------- .../autopsy/timeline/FilteredEventsModel.java | 2 +- .../autopsy/timeline/ui/EventTypeUtils.java | 2 +- .../ui/countsview/EventCountsChart.java | 2 +- .../netbeans/core/startup/Bundle.properties | 2 +- .../core/windows/view/ui/Bundle.properties | 2 +- 6 files changed, 21 insertions(+), 13 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/modules/plaso/PlasoIngestModule.java b/Core/src/org/sleuthkit/autopsy/modules/plaso/PlasoIngestModule.java index 76d1a5202f..b5dbf5f94c 100644 --- a/Core/src/org/sleuthkit/autopsy/modules/plaso/PlasoIngestModule.java +++ b/Core/src/org/sleuthkit/autopsy/modules/plaso/PlasoIngestModule.java @@ -118,7 +118,7 @@ public class PlasoIngestModule implements DataSourceIngestModule { "PlasoIngestModule_has_run=Plaso Plugin has been run."}) @Override public ProcessResult process(Content dataSource, DataSourceIngestModuleProgress statusHelper) { - statusHelper.switchToIndeterminate(); + statusHelper.switchToDeterminate(100); if (!(dataSource instanceof Image)) { logger.log(Level.SEVERE, Bundle.PlasoIngestModule_dataSource_not_an_image()); @@ -142,7 +142,8 @@ public class PlasoIngestModule implements DataSourceIngestModule { logger.log(Level.INFO, Bundle.PlasoIngestModule_startUp_message()); //NON-NLS try { - statusHelper.progress(Bundle.PlasoIngestModule_running_log2timeline()); + // Run log2timeline + statusHelper.progress(Bundle.PlasoIngestModule_running_log2timeline(), 0); ExecUtil.execute(log2TimeLineCommand, new DataSourceIngestModuleProcessTerminator(context)); if (context.dataSourceIngestIsCancelled()) { logger.log(Level.INFO, Bundle.PlasoIngestModule_log2timeline_cancelled()); //NON-NLS @@ -155,7 +156,9 @@ public class PlasoIngestModule implements DataSourceIngestModule { MessageNotifyUtil.Message.info(Bundle.PlasoIngestModule_error_running_log2timeline()); return ProcessResult.OK; } - statusHelper.progress(Bundle.PlasoIngestModule_running_psort()); + + // sort the output + statusHelper.progress(Bundle.PlasoIngestModule_running_psort(), 33); ExecUtil.execute(psortCommand, new DataSourceIngestModuleProcessTerminator(context)); if (context.dataSourceIngestIsCancelled()) { logger.log(Level.INFO, Bundle.PlasoIngestModule_psort_cancelled()); //NON-NLS @@ -168,8 +171,9 @@ public class PlasoIngestModule implements DataSourceIngestModule { MessageNotifyUtil.Message.info(Bundle.PlasoIngestModule_error_running_psort()); return ProcessResult.OK; } - String plasoDb = moduleOutputPath + File.separator + "plasodb.db3"; - createPlasoArtifacts(plasoDb, statusHelper); + + // parse the output and make artifacts + createPlasoArtifacts(plasoFile.getAbsolutePath(), statusHelper); } catch (IOException ex) { logger.log(Level.SEVERE, Bundle.PlasoIngestModule_error_running(), ex); @@ -275,6 +279,7 @@ public class PlasoIngestModule implements DataSourceIngestModule { try (SQLiteDBConnect tempdbconnect = new SQLiteDBConnect("org.sqlite.JDBC", connectionString); //NON-NLS ResultSet resultSet = tempdbconnect.executeQry(sqlStatement)) { + while (resultSet.next()) { if (context.dataSourceIngestIsCancelled()) { logger.log(Level.INFO, Bundle.PlasoIngestModule_create_artifacts_cancelled()); //NON-NLS @@ -291,13 +296,15 @@ public class PlasoIngestModule implements DataSourceIngestModule { continue; } - statusHelper.progress(resultSet.getString("filename")); + String currentFile = resultSet.getString("filename"); + statusHelper.progress("Adding events to case: " + currentFile, 66); - Content resolvedFile = getAbstractFile(resultSet.getString("filename")); + Content resolvedFile = getAbstractFile(currentFile); if (resolvedFile == null) { logger.log(Level.INFO, "File from Plaso output not found. Associating with data source instead: {0}", resultSet.getString("filename")); resolvedFile = image; } + long eventType = findEventSubtype(resultSet.getString("source"), resultSet.getString("filename"), resultSet.getString("type"), resultSet.getString("description"), resultSet.getString("sourcetype")); Collection bbattributes = Arrays.asList( new BlackboardAttribute( @@ -356,7 +363,8 @@ public class PlasoIngestModule implements DataSourceIngestModule { return abstractFiles.get(0); } for (AbstractFile resolvedFile : abstractFiles) { - if (filePath.matches(resolvedFile.getParentPath().toLowerCase())) { + // double check its an exact match + if (filePath.toLowerCase().matches(resolvedFile.getParentPath().toLowerCase())) { // cache it for next time previousFile = resolvedFile; return resolvedFile; diff --git a/Core/src/org/sleuthkit/autopsy/timeline/FilteredEventsModel.java b/Core/src/org/sleuthkit/autopsy/timeline/FilteredEventsModel.java index d19ccf138c..057f44c2ad 100644 --- a/Core/src/org/sleuthkit/autopsy/timeline/FilteredEventsModel.java +++ b/Core/src/org/sleuthkit/autopsy/timeline/FilteredEventsModel.java @@ -367,7 +367,7 @@ public final class FilteredEventsModel { tagsFilter, hashHitsFilter, new TextFilter(), - new TypeFilter(EventType.ROOT_EVEN_TYPE), + new TypeFilter(EventType.ROOT_EVENT_TYPE), dataSourcesFilter, Collections.emptySet())); } diff --git a/Core/src/org/sleuthkit/autopsy/timeline/ui/EventTypeUtils.java b/Core/src/org/sleuthkit/autopsy/timeline/ui/EventTypeUtils.java index 99798354a9..fb7c94eb13 100644 --- a/Core/src/org/sleuthkit/autopsy/timeline/ui/EventTypeUtils.java +++ b/Core/src/org/sleuthkit/autopsy/timeline/ui/EventTypeUtils.java @@ -93,7 +93,7 @@ final public class EventTypeUtils { } public static Color getColor(EventType type) { - if (type.equals(EventType.ROOT_EVEN_TYPE)) { + if (type.equals(EventType.ROOT_EVENT_TYPE)) { return Color.hsb(359, .9, .9, 0); } diff --git a/Core/src/org/sleuthkit/autopsy/timeline/ui/countsview/EventCountsChart.java b/Core/src/org/sleuthkit/autopsy/timeline/ui/countsview/EventCountsChart.java index e99e5b3dfe..0cc073b4af 100644 --- a/Core/src/org/sleuthkit/autopsy/timeline/ui/countsview/EventCountsChart.java +++ b/Core/src/org/sleuthkit/autopsy/timeline/ui/countsview/EventCountsChart.java @@ -317,7 +317,7 @@ final class EventCountsChart extends StackedBarChart implements super(Bundle.Timeline_ui_countsview_menuItem_selectTimeRange()); setEventHandler(action -> { try { - controller.selectTimeAndType(interval, EventType.ROOT_EVEN_TYPE); + controller.selectTimeAndType(interval, EventType.ROOT_EVENT_TYPE); } catch (TskCoreException ex) { Notifications.create().owner(getScene().getWindow()) diff --git a/branding/core/core.jar/org/netbeans/core/startup/Bundle.properties b/branding/core/core.jar/org/netbeans/core/startup/Bundle.properties index 21c4fbf529..deeb62c835 100644 --- a/branding/core/core.jar/org/netbeans/core/startup/Bundle.properties +++ b/branding/core/core.jar/org/netbeans/core/startup/Bundle.properties @@ -1,5 +1,5 @@ #Updated by build script -#Mon, 03 Sep 2018 17:29:44 +0200 +#Tue, 18 Sep 2018 23:44:53 -0400 LBL_splash_window_title=Starting Autopsy SPLASH_HEIGHT=314 SPLASH_WIDTH=538 diff --git a/branding/modules/org-netbeans-core-windows.jar/org/netbeans/core/windows/view/ui/Bundle.properties b/branding/modules/org-netbeans-core-windows.jar/org/netbeans/core/windows/view/ui/Bundle.properties index a730d6a65b..9c55939ab9 100644 --- a/branding/modules/org-netbeans-core-windows.jar/org/netbeans/core/windows/view/ui/Bundle.properties +++ b/branding/modules/org-netbeans-core-windows.jar/org/netbeans/core/windows/view/ui/Bundle.properties @@ -1,4 +1,4 @@ #Updated by build script -#Mon, 03 Sep 2018 17:29:44 +0200 +#Tue, 18 Sep 2018 23:44:53 -0400 CTL_MainWindow_Title=Autopsy 4.8.0 CTL_MainWindow_Title_No_Project=Autopsy 4.8.0 From ec12f00f4e496b9402dfa2c79e531ff23b6cd22f Mon Sep 17 00:00:00 2001 From: Brian Carrier Date: Wed, 19 Sep 2018 08:43:18 -0400 Subject: [PATCH 2/3] changed to equalsIgnoreCase() --- .../org/sleuthkit/autopsy/modules/plaso/PlasoIngestModule.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Core/src/org/sleuthkit/autopsy/modules/plaso/PlasoIngestModule.java b/Core/src/org/sleuthkit/autopsy/modules/plaso/PlasoIngestModule.java index b5dbf5f94c..3a03793a3d 100644 --- a/Core/src/org/sleuthkit/autopsy/modules/plaso/PlasoIngestModule.java +++ b/Core/src/org/sleuthkit/autopsy/modules/plaso/PlasoIngestModule.java @@ -364,7 +364,7 @@ public class PlasoIngestModule implements DataSourceIngestModule { } for (AbstractFile resolvedFile : abstractFiles) { // double check its an exact match - if (filePath.toLowerCase().matches(resolvedFile.getParentPath().toLowerCase())) { + if (filePath.equalsIgnoreCase(resolvedFile.getParentPath())) { // cache it for next time previousFile = resolvedFile; return resolvedFile; From bf5435eb1cc0e06f74df32cb574179c1cbd60263 Mon Sep 17 00:00:00 2001 From: millmanorama Date: Wed, 19 Sep 2018 15:14:52 +0200 Subject: [PATCH 3/3] update SQL in timeline for new schema --- .../ui/detailview/datamodel/DetailsViewModel.java | 6 +++--- .../timeline/ui/listvew/datamodel/ListViewModel.java | 8 ++++---- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/timeline/ui/detailview/datamodel/DetailsViewModel.java b/Core/src/org/sleuthkit/autopsy/timeline/ui/detailview/datamodel/DetailsViewModel.java index b1d1ebb92a..91e2b66520 100644 --- a/Core/src/org/sleuthkit/autopsy/timeline/ui/detailview/datamodel/DetailsViewModel.java +++ b/Core/src/org/sleuthkit/autopsy/timeline/ui/detailview/datamodel/DetailsViewModel.java @@ -161,9 +161,9 @@ final public class DetailsViewModel { final boolean needsHashSets = filterState.hasActiveHashFilters(); TimelineDBUtils dbUtils = new TimelineDBUtils(sleuthkitCase); String querySql = "SELECT " + formatTimeFunctionHelper(rangeInfo.getPeriodSize().toChronoUnit(), timeZone) + " AS interval, " // NON-NLS - + dbUtils.csvAggFunction("events.event_id") + " as event_ids, " //NON-NLS - + dbUtils.csvAggFunction("CASE WHEN hash_hit = 1 THEN events.event_id ELSE NULL END") + " as hash_hits, " //NON-NLS - + dbUtils.csvAggFunction("CASE WHEN tagged = 1 THEN events.event_id ELSE NULL END") + " as taggeds, " //NON-NLS + + dbUtils.csvAggFunction("tsk_events.event_id") + " as event_ids, " //NON-NLS + + dbUtils.csvAggFunction("CASE WHEN hash_hit = 1 THEN tsk_events.event_id ELSE NULL END") + " as hash_hits, " //NON-NLS + + dbUtils.csvAggFunction("CASE WHEN tagged = 1 THEN tsk_events.event_id ELSE NULL END") + " as taggeds, " //NON-NLS + " min(time) AS minTime, max(time) AS maxTime, " + typeColumn + ", " + descriptionColumn // NON-NLS + " FROM " + TimelineManager.getAugmentedEventsTablesSQL(needsTags, needsHashSets) // NON-NLS + " WHERE time >= " + start + " AND time < " + end + " AND " + eventManager.getSQLWhere(filterState.getActiveFilter()) // NON-NLS diff --git a/Core/src/org/sleuthkit/autopsy/timeline/ui/listvew/datamodel/ListViewModel.java b/Core/src/org/sleuthkit/autopsy/timeline/ui/listvew/datamodel/ListViewModel.java index 388da66664..203db0994c 100644 --- a/Core/src/org/sleuthkit/autopsy/timeline/ui/listvew/datamodel/ListViewModel.java +++ b/Core/src/org/sleuthkit/autopsy/timeline/ui/listvew/datamodel/ListViewModel.java @@ -88,12 +88,12 @@ public class ListViewModel { final boolean needsTags = filterState.hasActiveTagsFilters(); final boolean needsHashSets = filterState.hasActiveHashFilters(); TimelineDBUtils dbUtils = new TimelineDBUtils(sleuthkitCase); - final String querySql = "SELECT full_description, time, file_id, " - + dbUtils.csvAggFunction("CAST(events.event_id AS VARCHAR)") + " AS eventIDs, " + final String querySql = "SELECT full_description, time, file_obj_id, " + + dbUtils.csvAggFunction("CAST(tsk_events.event_id AS VARCHAR)") + " AS eventIDs, " + dbUtils.csvAggFunction("CAST(sub_type AS VARCHAR)") + " AS eventTypes" + " FROM " + TimelineManager.getAugmentedEventsTablesSQL(needsTags, needsHashSets) + " WHERE time >= " + startTime + " AND time <" + endTime + " AND " + eventManager.getSQLWhere(filterState.getActiveFilter()) - + " GROUP BY time, full_description, file_id ORDER BY time ASC, full_description"; + + " GROUP BY time, full_description, file_obj_id ORDER BY time ASC, full_description"; try (SleuthkitCase.CaseDbQuery dbQuery = sleuthkitCase.executeQuery(querySql); ResultSet resultSet = dbQuery.getResultSet();) { @@ -108,7 +108,7 @@ public class ListViewModel { for (int i = 0; i < eventIDs.size(); i++) { eventMap.put(eventTypes.get(i), eventIDs.get(i)); } - combinedEvents.add(new CombinedEvent(resultSet.getLong("time") * 1000, resultSet.getString("full_description"), resultSet.getLong("file_id"), eventMap)); + combinedEvents.add(new CombinedEvent(resultSet.getLong("time") * 1000, resultSet.getString("full_description"), resultSet.getLong("file_obj_id"), eventMap)); } } catch (SQLException sqlEx) {