Commit Graph
2623 Commits
Author SHA1 Message Date
Richard Cordovano 6b2b174c9d Merge pull request #1033 from sleuthkit/istat_output
Added istat output to metadata content viewer
2015-02-05 12:40:22 -05:00
Richard Cordovano 272208c345 Merge pull request #1029 from APriestman/stix
Adding STIX module code
2015-02-05 12:39:43 -05:00
Brian Carrier c2aa8838c6 Added istat output to metadata content viewer 2015-02-04 23:57:46 -05:00
Richard Cordovano b816e0fff4 Change copyright date of FleIngestTask.java 2015-02-04 14:50:26 -05:00
APriestman a19c36bc42 Merge remote-tracking branch 'upstream/develop' into stix 2015-02-04 11:34:56 -05:00
Richard Cordovano 5409901b4a Remove selected old TODO statements 2015-02-03 19:59:59 -05:00
Richard Cordovano 1729e4ca5b Fix deadlock potential in IngestJob/DataSourceIngestJob interactions 2015-02-03 19:21:20 -05:00
APriestman a4f887f368 Merge remote-tracking branch 'upstream/develop' into stix 2015-02-03 11:04:02 -05:00
APriestman 0eb8f6434e Added jar files for Stix module 2015-02-03 11:02:22 -05:00
APriestman 919d8a83f8 Added STIX module code to Autopsy. 2015-02-03 10:34:29 -05:00
Richard Cordovano 462fcb5413 Add cancellation data to data source ingest job snapshots 2015-02-02 20:02:13 -05:00
Richard Cordovano a0b3208ce1 Add cancellation data to data source ingest job snapshots 2015-02-02 19:56:04 -05:00
Richard Cordovano a1c4b8e25f Removed unused import from IngestJob class 2015-02-02 19:22:20 -05:00
Richard Cordovano 75315ed8da Add cancellation data to data source ingest job snapshots 2015-02-02 19:20:25 -05:00
Richard Cordovano 62aa807cea Add cancellation data to data source ingest job snapshots 2015-02-02 18:45:46 -05:00
Brian Carrier 8f1d6192e3 Merge branch 'develop' of github.com:sleuthkit/autopsy into develop 2015-02-02 00:02:03 -05:00
Brian Carrier 502e8f4612 minor cleanup to code that opens .aut file from double click 2015-02-02 00:01:38 -05:00
Richard Cordovano 4c46415709 Refactor file type detection 2015-01-30 18:54:58 -05:00
Richard Cordovano 209d8384eb Refactor file type detection 2015-01-30 18:15:20 -05:00
Richard Cordovano 78ead321bc Update some method comments in TikaFileTypeDetector class 2015-01-30 10:10:58 -05:00
Richard Cordovano bbfb0b1872 Make user-defined file type detection active for all clients 2015-01-30 10:05:03 -05:00
Richard Cordovano 7fb9edcf6c Merge pull request #1019 from esaunders/index_artifact_fix
Index artifact fix
2015-01-28 15:00:24 -05:00
Eamonn Saunders d0663d8fca - KeywordHit now contains a Content member instead of an AbstractFile and getFile() has been replaced by getContent().
- Updated KeywordSearchResultFactory, LuceneQuery and TermComponentQuery to use KeywordHit.getContent().
- Modified KeywordHits.java to not attempt to create MAC time columns for hits that do not have an AbstractFile.
- Updated SolrSearchService.indexArtifact() to get the underlying image id for artifacts that do not have an associated AbstractFile.
2015-01-28 14:49:25 -05:00
Richard Cordovano 6a4f98fcc0 Merge pull request #1018 from APriestman/stix
Added TSK_REMOTE_DRIVE artifacts to report.
2015-01-27 13:39:35 -05:00
APriestman b520cb66b6 Added TSK_REMOTE_DRIVE artifacts to report. 2015-01-27 13:34:52 -05:00
Richard Cordovano 58b283276c Add dependency fro NetBeans command line parsing 2015-01-26 15:35:15 -05:00
Richard Cordovano 6eb83b2ced Merge pull request #737 from shahit2/develop
added double clicking to open .aut files
2015-01-24 14:57:15 -05:00
Eamonn Saunders 65e2246209 Removed Content parameter from TextMarkupLookup.createInstance() method. 2015-01-22 12:33:36 -05:00
Eamonn Saunders 40f5191c15 Data type and comment cleanup. 2015-01-16 12:25:24 -05:00
Eamonn Saunders ae63179745 Removed unused imports. 2015-01-16 11:38:35 -05:00
Eamonn Saunders 8973e8e16e Changed data type of objectId in HighlightedTextMarkup contructors from Long to long. 2015-01-16 11:31:12 -05:00
Eamonn Saunders 4756073248 Backed out artifact indexing code. 2015-01-16 11:30:23 -05:00
esaunders 491de990a1 Merge branch 'develop' of https://github.com/sleuthkit/autopsy into art_kws_integration 2015-01-15 16:06:46 -05:00
Eamonn Saunders 241b06c1a6 - Removed references to the artifact id mask (0x8000000000000000)
- Modified SolrSearchService.indexArtifacts() to ignore artifacts with an artifact_id > 0.
2015-01-15 16:04:54 -05:00
Eamonn Saunders 5aaf9f7363 Added comments for BlackboardArtifactNode.setDisplayName() 2015-01-14 16:36:53 -05:00
Eamonn Saunders d4663b5f62 Modified display name so that there is some indication in the UI when a keyword hit was on an artifact instead of a file. 2015-01-14 14:36:39 -05:00
Brian Carrier 25258717df Added comments to why dataresultviewertable drops first property. Made ImageNode name be more useful 2015-01-14 12:38:07 -05:00
Brian Carrier 3345c835af Merge branch 'develop' of github.com:sleuthkit/autopsy into develop 2015-01-14 10:19:01 -05:00
Brian Carrier 34bbdb1f57 Changed file extraction so that it replaces : with _ so that attributes are not hidden as ADS 2015-01-14 10:18:43 -05:00
Richard Cordovano ac1b6a8d8c Supply missing position attribute in top level registration of FileTypeIdOptionsPanelController 2015-01-13 11:47:37 -05:00
Richard Cordovano 76884f79c1 Remove KeywordSearchServiceFactory interface and Solr implementation 2015-01-09 15:19:49 -05:00
Eamonn Saunders 4a098b7694 Exported keywordsearchservice package. 2015-01-09 13:33:17 -05:00
Eamonn Saunders 11c2e2b71b Apply masking to associated artifact id. 2015-01-09 12:08:52 -05:00
Eamonn Saunders a9aacc1287 Merge artifact_content_viewer into art_kws_integration 2015-01-07 13:03:45 -05:00
Eamonn Saunders dba254a033 Merge index_artifacts into art_kws_integration 2015-01-07 13:01:56 -05:00
Eamonn Saunders 7c2a548dd8 Modifications to support displaying indexed artifact text in content viewer:
- Modified HighlightedTestMarkup constructor to take an object id instead of a Content object. The object id can either be for a file or an artifact. The highlighter uses the object id to get the indexed text from Solr.
- Modified RawTextMarkup constructor to take both a Content object and an object id. RawTextMarkup needs the Content object to display messages about whether the file was skipped (because it is a known file) or whether the file content has yet to be indexed.
- Added a method to ExtractedContentViewer to get the correct object id. If the node contains a keyword hit blackboard artifact that contains a TSK_ASSOCIATED_ARTIFACT attribute, the object id is the artifact id of the associated artifact. Otherwise the object id is obtained from the Content object.
2015-01-07 12:52:55 -05:00
Eamonn Saunders 6576d8c8c6 Initial version of blackboard artifact indexing:
- Added KeywordSearchService and KeywordSearchServiceFactory interfaces to Autopsy core.
- Modified Services.java to load a keyword search service provider and added the getKeywordSearchService() method.
- Added SolrSearchService and SolrSearchServiceFactory to keyword search module.
- Changed Ingester.ingest(ContentStream ...) from private to package scope.
- SolrSearchService.indexArtifact concatenates all attribute values into a single string, sets the document id to art-<artifact-id> and calls Ingester.ingest()
- Modified ExifParserFileIngestModule to pass EXIF artifacts to the artifact indexer.
2015-01-02 13:33:26 -05:00
Karl Mortensen e21acc818c close file handles appropriately 2015-01-02 11:51:26 -05:00
Richard Cordovano 1ce585e906 Add missing synchronized keyword to IngestJob method 2014-12-29 10:25:28 -05:00
Richard Cordovano 2ff68abd97 Rename UserDefinedFileTypeIdentifier 2014-12-23 10:01:16 -05:00