Updated uses of new encryption artifact.

This commit is contained in:
Jeff Wallace
2013-12-04 15:58:54 -05:00
parent 4a6ac42282
commit e5e2c0fc2f
5 changed files with 20 additions and 3 deletions
@@ -124,6 +124,8 @@ public class ArtifactTypeNode extends DisplayableItemNode {
return "gps-search.png";
case TSK_SERVICE_ACCOUNT:
return "account-icon-16.png";
case TSK_ENCRYPTED_FILE:
return "encrypted-file.png";
}
return "artifact-icon.png";
}
@@ -329,6 +329,8 @@ public class BlackboardArtifactNode extends DisplayableItemNode {
return "gps-search.png";
case TSK_SERVICE_ACCOUNT:
return "account-icon-16.png";
case TSK_ENCRYPTED_FILE:
return "encrypted-file.png";
}
return "artifact-icon.png";
Binary file not shown.

After

Width:  |  Height:  |  Size: 801 B

@@ -904,6 +904,9 @@ public class ReportGenerator {
case TSK_TOOL_OUTPUT:
columnHeaders = new ArrayList<>(Arrays.asList(new String[] {"Program Name", "Text", "Source File"}));
break;
case TSK_ENCRYPTED_FILE:
columnHeaders = new ArrayList<>(Arrays.asList(new String[] {"Program Name", "Entropy", "Encryption Type", "Source File"}));
break;
default:
return null;
}
@@ -1210,6 +1213,13 @@ public class ReportGenerator {
row.add(attributes.get(ATTRIBUTE_TYPE.TSK_TEXT.getTypeID()));
row.add(getFileUniquePath(artifactData.getObjectID()));
return row;
case TSK_ENCRYPTED_FILE:
List<String> encryptedFile = new ArrayList<>();
encryptedFile.add(attributes.get(ATTRIBUTE_TYPE.TSK_PROG_NAME.getTypeID()));
encryptedFile.add(attributes.get(ATTRIBUTE_TYPE.TSK_ENTROPY.getTypeID()));
encryptedFile.add(attributes.get(ATTRIBUTE_TYPE.TSK_ENCRYPTION_DETECTED.getTypeID()));
encryptedFile.add(getFileUniquePath(artifactData.getObjectID()));
return encryptedFile;
}
return null;
}
@@ -51,6 +51,7 @@ import org.sleuthkit.autopsy.ingest.PipelineContext;
import org.sleuthkit.autopsy.ingest.IngestMessage;
import org.sleuthkit.autopsy.ingest.IngestMonitor;
import org.sleuthkit.autopsy.ingest.ModuleContentEvent;
import org.sleuthkit.autopsy.ingest.ModuleDataEvent;
import org.sleuthkit.datamodel.BlackboardArtifact;
import org.sleuthkit.datamodel.BlackboardAttribute;
import org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE;
@@ -553,11 +554,13 @@ public final class SevenZipIngestModule extends IngestModuleAbstractFile {
if (hasEncrypted) {
String encryptionType = fullEncryption ? ENCRYPTION_FULL : ENCRYPTION_FILE_LEVEL;
try {
BlackboardArtifact generalInfo = archiveFile.getGenInfoArtifact();
generalInfo.addAttribute(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_ENCRYPTION_DETECTED.getTypeID(),
BlackboardArtifact artifact = archiveFile.newArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_ENCRYPTED_FILE);
artifact.addAttribute(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_ENCRYPTION_DETECTED.getTypeID(),
MODULE_NAME, encryptionType));
//artifact.addAttribute(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME.getTypeID(), MODULE_NAME, ...);
//artifact.addAttribute(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_ENTROPY.getTypeID(), MODULE_NAME, ...);
//@@@ We don't fire here because GEN_INFO isn't displayed in the tree.... Need to address how these should be displayed
//services.fireModuleDataEvent(new ModuleDataEvent(MODULE_NAME, BlackboardArtifact.ARTIFACT_TYPE.TSK_METADATA_EXIF));
services.fireModuleDataEvent(new ModuleDataEvent(MODULE_NAME, BlackboardArtifact.ARTIFACT_TYPE.TSK_ENCRYPTED_FILE));
} catch (TskCoreException ex) {
logger.log(Level.SEVERE, "Error creating blackboard artifact for encryption detected for file: " + archiveFile, ex);
}