@@ -29,6 +29,9 @@ import org.openide.util.Utilities;
|
||||
import org.openide.windows.WindowManager;
|
||||
import org.sleuthkit.autopsy.casemodule.Case;
|
||||
import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException;
|
||||
import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager;
|
||||
import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager.ContentViewerTag;
|
||||
import org.sleuthkit.autopsy.contentviewers.imagetagging.ImageTagRegion;
|
||||
import org.sleuthkit.autopsy.coreutils.Logger;
|
||||
import org.sleuthkit.datamodel.ContentTag;
|
||||
import org.sleuthkit.datamodel.TskCoreException;
|
||||
@@ -72,6 +75,12 @@ public class DeleteContentTagAction extends AbstractAction {
|
||||
new Thread(() -> {
|
||||
for (ContentTag tag : selectedTags) {
|
||||
try {
|
||||
// Check if there is an image tag before deleting the content tag.
|
||||
ContentViewerTag<ImageTagRegion> imageTag = ContentViewerTagManager.getTag(tag, ImageTagRegion.class);
|
||||
if(imageTag != null) {
|
||||
ContentViewerTagManager.deleteTag(imageTag);
|
||||
}
|
||||
|
||||
Case.getCurrentCaseThrows().getServices().getTagsManager().deleteContentTag(tag);
|
||||
} catch (TskCoreException | NoCurrentCaseException ex) {
|
||||
Logger.getLogger(DeleteContentTagAction.class.getName()).log(Level.SEVERE, "Error deleting tag", ex); //NON-NLS
|
||||
|
||||
@@ -39,6 +39,9 @@ import org.openide.util.actions.Presenter;
|
||||
import org.sleuthkit.autopsy.casemodule.Case;
|
||||
import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException;
|
||||
import org.sleuthkit.autopsy.casemodule.services.TagsManager;
|
||||
import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager;
|
||||
import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager.ContentViewerTag;
|
||||
import org.sleuthkit.autopsy.contentviewers.imagetagging.ImageTagRegion;
|
||||
import org.sleuthkit.autopsy.coreutils.Logger;
|
||||
import org.sleuthkit.autopsy.tags.TagUtils;
|
||||
import org.sleuthkit.datamodel.AbstractFile;
|
||||
@@ -123,6 +126,13 @@ public class DeleteFileContentTagAction extends AbstractAction implements Presen
|
||||
|
||||
try {
|
||||
logger.log(Level.INFO, "Removing tag {0} from {1}", new Object[]{tagName.getDisplayName(), contentTag.getContent().getName()}); //NON-NLS
|
||||
|
||||
// Check if there is an image tag before deleting the content tag.
|
||||
ContentViewerTag<ImageTagRegion> imageTag = ContentViewerTagManager.getTag(contentTag, ImageTagRegion.class);
|
||||
if(imageTag != null) {
|
||||
ContentViewerTagManager.deleteTag(imageTag);
|
||||
}
|
||||
|
||||
tagsManager.deleteContentTag(contentTag);
|
||||
} catch (TskCoreException tskCoreException) {
|
||||
logger.log(Level.SEVERE, "Error untagging file", tskCoreException); //NON-NLS
|
||||
|
||||
@@ -29,6 +29,9 @@ import org.openide.util.Utilities;
|
||||
import org.sleuthkit.autopsy.casemodule.Case;
|
||||
import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException;
|
||||
import org.sleuthkit.autopsy.casemodule.services.TagsManager;
|
||||
import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager;
|
||||
import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager.ContentViewerTag;
|
||||
import org.sleuthkit.autopsy.contentviewers.imagetagging.ImageTagRegion;
|
||||
import org.sleuthkit.autopsy.coreutils.Logger;
|
||||
import org.sleuthkit.datamodel.ContentTag;
|
||||
import org.sleuthkit.datamodel.TagName;
|
||||
@@ -83,9 +86,19 @@ public final class ReplaceContentTagAction extends ReplaceTagAction<ContentTag>
|
||||
try {
|
||||
logger.log(Level.INFO, "Replacing tag {0} with tag {1} for artifact {2}", new Object[]{oldTag.getName().getDisplayName(), newTagName.getDisplayName(), oldTag.getContent().getName()}); //NON-NLS
|
||||
|
||||
// Check if there is an image tag before deleting the content tag.
|
||||
ContentViewerTag<ImageTagRegion> imageTag = ContentViewerTagManager.getTag(oldTag, ImageTagRegion.class);
|
||||
if(imageTag != null) {
|
||||
ContentViewerTagManager.deleteTag(imageTag);
|
||||
}
|
||||
|
||||
tagsManager.deleteContentTag(oldTag);
|
||||
tagsManager.addContentTag(oldTag.getContent(), newTagName, newComment);
|
||||
|
||||
ContentTag newTag = tagsManager.addContentTag(oldTag.getContent(), newTagName, newComment);
|
||||
|
||||
// Resave the image tag if present.
|
||||
if(imageTag != null) {
|
||||
ContentViewerTagManager.saveTag(newTag, imageTag.getDetails());
|
||||
}
|
||||
} catch (TskCoreException tskCoreException) {
|
||||
logger.log(Level.SEVERE, "Error replacing artifact tag", tskCoreException); //NON-NLS
|
||||
Platform.runLater(()
|
||||
|
||||
@@ -433,7 +433,7 @@ public class HashDbManager implements PropertyChangeListener {
|
||||
|
||||
void save() throws HashDbManagerException {
|
||||
try {
|
||||
if (!HashLookupSettings.writeSettings(new HashLookupSettings(HashLookupSettings.convertHashSetList(getNonOfficialHashSets())))) {
|
||||
if (!HashLookupSettings.writeSettings(new HashLookupSettings(HashLookupSettings.convertHashSetList(this.hashSets)))) {
|
||||
throw new HashDbManagerException(NbBundle.getMessage(this.getClass(), "HashDbManager.saveErrorExceptionMsg"));
|
||||
}
|
||||
} catch (HashLookupSettings.HashLookupSettingsException ex) {
|
||||
@@ -492,13 +492,6 @@ public class HashDbManager implements PropertyChangeListener {
|
||||
return getUpdateableHashSets(getAllHashSets());
|
||||
}
|
||||
|
||||
private List<HashDb> getNonOfficialHashSets() {
|
||||
return getAllHashSets()
|
||||
.stream()
|
||||
.filter((HashDb db) -> (db instanceof SleuthkitHashSet && ((SleuthkitHashSet) db).isOfficialSet()) ? false : true)
|
||||
.collect(Collectors.toList());
|
||||
}
|
||||
|
||||
private List<HashDb> getUpdateableHashSets(List<HashDb> hashDbs) {
|
||||
return hashDbs
|
||||
.stream()
|
||||
@@ -539,7 +532,7 @@ public class HashDbManager implements PropertyChangeListener {
|
||||
* cancellation of configuration panels.
|
||||
*/
|
||||
public synchronized void loadLastSavedConfiguration() {
|
||||
closeHashDatabases(getAllHashSets());
|
||||
closeHashDatabases(this.hashSets);
|
||||
hashSetNames.clear();
|
||||
hashSetPaths.clear();
|
||||
|
||||
@@ -765,7 +758,7 @@ public class HashDbManager implements PropertyChangeListener {
|
||||
*/
|
||||
if (!allDatabasesLoadedCorrectly && RuntimeProperties.runningWithGUI()) {
|
||||
try {
|
||||
HashLookupSettings.writeSettings(new HashLookupSettings(HashLookupSettings.convertHashSetList(getNonOfficialHashSets())));
|
||||
HashLookupSettings.writeSettings(new HashLookupSettings(HashLookupSettings.convertHashSetList(this.hashSets)));
|
||||
allDatabasesLoadedCorrectly = true;
|
||||
} catch (HashLookupSettings.HashLookupSettingsException ex) {
|
||||
allDatabasesLoadedCorrectly = false;
|
||||
@@ -839,7 +832,7 @@ public class HashDbManager implements PropertyChangeListener {
|
||||
}
|
||||
|
||||
private boolean hashDbInfoIsNew(HashDbInfo dbInfo) {
|
||||
for (HashDb db : getAllHashSets()) {
|
||||
for (HashDb db : this.hashSets) {
|
||||
if (dbInfo.matches(db)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
@@ -19,7 +19,7 @@ ReportProgressIndicator.switchToIndeterminateMessage=Report generation progress
|
||||
ReportWizardDataSourceSelectionPanel.confirmEmptySelection=Are you sure you want to proceed with no selections?
|
||||
ReportWizardDataSourceSelectionPanel.finishButton.text=Finish
|
||||
ReportWizardDataSourceSelectionPanel.nextButton.text=Next
|
||||
ReportWizardDataSourceSelectionPanel.title=Select which datasource(s) to include
|
||||
ReportWizardDataSourceSelectionPanel.title=Select which data source(s) to include
|
||||
ReportWizardFileOptionsVisualPanel.jLabel1.text=Select items to include in File Report:
|
||||
ReportWizardFileOptionsVisualPanel.deselectAllButton.text=Deselect All
|
||||
ReportWizardFileOptionsVisualPanel.selectAllButton.text=Select All
|
||||
|
||||
@@ -87,7 +87,7 @@ public class ReportWizardDataSourceSelectionPanel implements WizardDescriptor.Fi
|
||||
}
|
||||
|
||||
@NbBundle.Messages({
|
||||
"ReportWizardDataSourceSelectionPanel.title=Select which datasource(s) to include"
|
||||
"ReportWizardDataSourceSelectionPanel.title=Select which data source(s) to include"
|
||||
})
|
||||
@Override
|
||||
public CheckBoxListPanel<Long> getComponent() {
|
||||
|
||||
@@ -218,12 +218,6 @@ the Case -> Case Properties menu.
|
||||
|
||||
This shows how common the selected file is. The value is the percentage of case/data source tuples that have the selected property.
|
||||
|
||||
\subsection central_repo_comment Add/Edit Comment
|
||||
|
||||
If you want instead to edit the comment of a node, it can be done by right clicking on the original item in the result viewer and selecting "Add/Edit Central Repository Comment".
|
||||
|
||||
\image html central_repo_comment_menu.png
|
||||
|
||||
\subsection cr_interesting_items Interesting Items
|
||||
|
||||
In the Results tree of an open case is an entry called Interesting Items. When this module is enabled, all of the enabled
|
||||
|
||||
|
Before Width: | Height: | Size: 18 KiB |
|
After Width: | Height: | Size: 11 KiB |
|
After Width: | Height: | Size: 15 KiB |
|
After Width: | Height: | Size: 168 KiB |
|
After Width: | Height: | Size: 148 KiB |
|
After Width: | Height: | Size: 77 KiB |
|
After Width: | Height: | Size: 6.6 KiB |
@@ -8,6 +8,10 @@ of any coordinates found to load into software like Google Earth.
|
||||
|
||||
\image html reports_select.png
|
||||
|
||||
Most report types will allow you to select which data sources to include in the report. Note that the names of excluded data sources may still be present in the report. For example, the \ref report_html will list all data sources in the case on the main page but will not contain results, tagged files, etc. from the excluded data source(s).
|
||||
|
||||
\image html reports_datasource_select.png
|
||||
|
||||
The different types of reports will be described below. The majority of the report modules will generate a report file which
|
||||
will be displayed in the case under the "Reports" node of the \ref tree_viewer_page.
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
/*! \page tagging_page Tagging
|
||||
/*! \page tagging_page Tagging and Commenting
|
||||
|
||||
Tagging (or Bookmarking) allows you to create a reference to a file or object and easily find it later or include it in a \ref reporting_page "report". Tagging is also used by the \ref central_repo_page "central repository" to mark items as notable.
|
||||
Tagging (or Bookmarking) allows you to create a reference to a file or object and easily find it later or include it in a \ref reporting_page "report". Tagging is also used by the \ref central_repo_page "central repository" to mark items as notable. You can add comments to files and results using tags or through the central repository.
|
||||
|
||||
\section tagging_items Tagging items
|
||||
|
||||
@@ -99,7 +99,7 @@ If using the central repository, changing the notable status will effect tagged
|
||||
- If "File A" is tagged with "Tag A", which is not notable, and then "Tag A" is switched to notable, "File A" will be marked as notable in the central repository
|
||||
- If "File B" is tagged with "Tag B", which is notable, and then "Tag B" is switched to non-notable, if there are no other notable tags on "File B" then its notable status in the central repository will be removed.
|
||||
|
||||
\section user_tags Hiding tags from other users
|
||||
\subsection user_tags Hiding tags from other users
|
||||
|
||||
Tags are associated with the account name of the user that tagged them. This information is visible through selecting items under the "Tags" section of the directory tree:
|
||||
|
||||
@@ -113,4 +113,26 @@ It is possible to hide all tagged files and results in the "Tags" area of the tr
|
||||
|
||||
\image html tagging_view_options.png
|
||||
|
||||
\section tagging_commenting Commenting
|
||||
|
||||
There are two methods to adding comments to files and results. The first method was discussed in the \ref tagging_items section. Right click on the file or result of interest, choose "Add File Tag" or "Add Result Tag" and then "Tag and Comment". This allows you to add a comment about the item. You can add multiple tags with comments to the same file or result.
|
||||
|
||||
\image html tagging_comment_context.png
|
||||
|
||||
If you have a \ref central_repo_page "central repository" enabled, you can also use it to save comments about files. Right click on the file and select "Add/Edit Central Repository Comment". If there was already a comment for this file it will appear in the dialog and can be changed - only one central repository comment can be stored at a time.
|
||||
|
||||
\image html tagging_cr_comment.png
|
||||
|
||||
If a file or result has a comment associated with it, you'll see a notepad icon in the "C" column of the result viewer. Hovering over it will tell you what type of comments are on the item.
|
||||
|
||||
\image html tagging_comment_icon.png
|
||||
|
||||
You can view comments associated with tags by going to the "Tags" section of the tree viewer and selecting one of your tags. Any comments will appear in the "Comment" column in the results viewer.
|
||||
|
||||
\image html tagging_comment_in_result_viewer.png
|
||||
|
||||
You can view all comments on an item through the "Annotation" tab in the content viewer.
|
||||
|
||||
\image html tagging_comment_anno.png
|
||||
|
||||
*/
|
||||
|
||||