diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/ArtifactTypeNode.java b/Core/src/org/sleuthkit/autopsy/datamodel/ArtifactTypeNode.java index c5d347ae6e..5b6ac9c950 100644 --- a/Core/src/org/sleuthkit/autopsy/datamodel/ArtifactTypeNode.java +++ b/Core/src/org/sleuthkit/autopsy/datamodel/ArtifactTypeNode.java @@ -124,6 +124,8 @@ public class ArtifactTypeNode extends DisplayableItemNode { return "gps-search.png"; case TSK_SERVICE_ACCOUNT: return "account-icon-16.png"; + case TSK_ENCRYPTED_FILE: + return "encrypted-file.png"; } return "artifact-icon.png"; } diff --git a/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java b/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java index 27caebc469..3bd1989365 100644 --- a/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java +++ b/Core/src/org/sleuthkit/autopsy/datamodel/BlackboardArtifactNode.java @@ -329,6 +329,8 @@ public class BlackboardArtifactNode extends DisplayableItemNode { return "gps-search.png"; case TSK_SERVICE_ACCOUNT: return "account-icon-16.png"; + case TSK_ENCRYPTED_FILE: + return "encrypted-file.png"; } return "artifact-icon.png"; diff --git a/Core/src/org/sleuthkit/autopsy/images/encrypted-file.png b/Core/src/org/sleuthkit/autopsy/images/encrypted-file.png new file mode 100755 index 0000000000..d6626cb09e Binary files /dev/null and b/Core/src/org/sleuthkit/autopsy/images/encrypted-file.png differ diff --git a/Core/src/org/sleuthkit/autopsy/report/ReportGenerator.java b/Core/src/org/sleuthkit/autopsy/report/ReportGenerator.java index e0a8c486fe..c47068fbd9 100644 --- a/Core/src/org/sleuthkit/autopsy/report/ReportGenerator.java +++ b/Core/src/org/sleuthkit/autopsy/report/ReportGenerator.java @@ -904,6 +904,9 @@ public class ReportGenerator { case TSK_TOOL_OUTPUT: columnHeaders = new ArrayList<>(Arrays.asList(new String[] {"Program Name", "Text", "Source File"})); break; + case TSK_ENCRYPTED_FILE: + columnHeaders = new ArrayList<>(Arrays.asList(new String[] {"Program Name", "Entropy", "Encryption Type", "Source File"})); + break; default: return null; } @@ -1210,6 +1213,13 @@ public class ReportGenerator { row.add(attributes.get(ATTRIBUTE_TYPE.TSK_TEXT.getTypeID())); row.add(getFileUniquePath(artifactData.getObjectID())); return row; + case TSK_ENCRYPTED_FILE: + List encryptedFile = new ArrayList<>(); + encryptedFile.add(attributes.get(ATTRIBUTE_TYPE.TSK_PROG_NAME.getTypeID())); + encryptedFile.add(attributes.get(ATTRIBUTE_TYPE.TSK_ENTROPY.getTypeID())); + encryptedFile.add(attributes.get(ATTRIBUTE_TYPE.TSK_ENCRYPTION_DETECTED.getTypeID())); + encryptedFile.add(getFileUniquePath(artifactData.getObjectID())); + return encryptedFile; } return null; } diff --git a/SevenZip/src/org/sleuthkit/autopsy/sevenzip/SevenZipIngestModule.java b/SevenZip/src/org/sleuthkit/autopsy/sevenzip/SevenZipIngestModule.java index 322f7c669f..9e08e53691 100644 --- a/SevenZip/src/org/sleuthkit/autopsy/sevenzip/SevenZipIngestModule.java +++ b/SevenZip/src/org/sleuthkit/autopsy/sevenzip/SevenZipIngestModule.java @@ -51,6 +51,7 @@ import org.sleuthkit.autopsy.ingest.PipelineContext; import org.sleuthkit.autopsy.ingest.IngestMessage; import org.sleuthkit.autopsy.ingest.IngestMonitor; import org.sleuthkit.autopsy.ingest.ModuleContentEvent; +import org.sleuthkit.autopsy.ingest.ModuleDataEvent; import org.sleuthkit.datamodel.BlackboardArtifact; import org.sleuthkit.datamodel.BlackboardAttribute; import org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE; @@ -553,11 +554,13 @@ public final class SevenZipIngestModule extends IngestModuleAbstractFile { if (hasEncrypted) { String encryptionType = fullEncryption ? ENCRYPTION_FULL : ENCRYPTION_FILE_LEVEL; try { - BlackboardArtifact generalInfo = archiveFile.getGenInfoArtifact(); - generalInfo.addAttribute(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_ENCRYPTION_DETECTED.getTypeID(), + BlackboardArtifact artifact = archiveFile.newArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_ENCRYPTED_FILE); + artifact.addAttribute(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_ENCRYPTION_DETECTED.getTypeID(), MODULE_NAME, encryptionType)); + //artifact.addAttribute(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME.getTypeID(), MODULE_NAME, ...); + //artifact.addAttribute(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_ENTROPY.getTypeID(), MODULE_NAME, ...); //@@@ We don't fire here because GEN_INFO isn't displayed in the tree.... Need to address how these should be displayed - //services.fireModuleDataEvent(new ModuleDataEvent(MODULE_NAME, BlackboardArtifact.ARTIFACT_TYPE.TSK_METADATA_EXIF)); + services.fireModuleDataEvent(new ModuleDataEvent(MODULE_NAME, BlackboardArtifact.ARTIFACT_TYPE.TSK_ENCRYPTED_FILE)); } catch (TskCoreException ex) { logger.log(Level.SEVERE, "Error creating blackboard artifact for encryption detected for file: " + archiveFile, ex); }