19 package org.sleuthkit.autopsy.modules.interestingitems;
21 import java.util.ArrayList;
22 import java.util.Collections;
23 import java.util.List;
25 import java.util.concurrent.ConcurrentHashMap;
26 import java.util.logging.Level;
27 import org.openide.util.Exceptions;
28 import org.openide.util.NbBundle;
29 import org.openide.util.NbBundle.Messages;
48 final class FilesIdentifierIngestModule
implements FileIngestModule {
50 "FilesIdentifierIngestModule.getFilesError=Error getting interesting files sets from file."
53 private static final Object sharedResourcesLock =
new Object();
54 private static final Logger logger = Logger.getLogger(FilesIdentifierIngestModule.class.getName());
55 private static final IngestModuleReferenceCounter refCounter =
new IngestModuleReferenceCounter();
56 private static final Map<Long, List<FilesSet>> interestingFileSetsByJob =
new ConcurrentHashMap<>();
57 private final FilesIdentifierIngestJobSettings settings;
58 private IngestJobContext context;
59 private Blackboard blackboard;
67 FilesIdentifierIngestModule(FilesIdentifierIngestJobSettings settings) {
68 this.settings = settings;
75 public void startUp(IngestJobContext context)
throws IngestModuleException {
76 this.context = context;
77 synchronized (FilesIdentifierIngestModule.sharedResourcesLock) {
78 if (FilesIdentifierIngestModule.refCounter.incrementAndGet(context.getJobId()) == 1) {
84 List<FilesSet> filesSets =
new ArrayList<>();
86 for (FilesSet set : InterestingItemDefsManager.getInstance().getInterestingFilesSets().values()) {
87 if (settings.interestingFilesSetIsEnabled(set.getName())) {
91 }
catch (InterestingItemDefsManager.InterestingItemDefsManagerException ex) {
92 throw new IngestModuleException(Bundle.FilesIdentifierIngestModule_getFilesError(), ex);
94 FilesIdentifierIngestModule.interestingFileSetsByJob.put(context.getJobId(), filesSets);
103 public ProcessResult process(AbstractFile file) {
104 blackboard = Case.getCurrentCase().getServices().getBlackboard();
107 List<FilesSet> filesSets = FilesIdentifierIngestModule.interestingFileSetsByJob.get(this.context.getJobId());
108 for (FilesSet filesSet : filesSets) {
109 String ruleSatisfied = filesSet.fileIsMemberOf(file);
110 if (ruleSatisfied != null) {
114 String moduleName = InterestingItemsIngestModuleFactory.getModuleName();
115 BlackboardArtifact artifact = file.newArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_FILE_HIT);
122 BlackboardAttribute setNameAttribute =
new BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_SET_NAME, moduleName, filesSet.getName());
123 artifact.addAttribute(setNameAttribute);
127 BlackboardAttribute ruleNameAttribute =
new BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_CATEGORY, moduleName, ruleSatisfied);
128 artifact.addAttribute(ruleNameAttribute);
132 blackboard.indexArtifact(artifact);
133 }
catch (Blackboard.BlackboardException ex) {
134 logger.log(Level.SEVERE, NbBundle.getMessage(Blackboard.class,
"Blackboard.unableToIndexArtifact.error.msg", artifact.getDisplayName()), ex);
135 MessageNotifyUtil.Notify.error(
136 NbBundle.getMessage(Blackboard.class,
"Blackboard.unableToIndexArtifact.exception.msg"), artifact.getDisplayName());
139 IngestServices.getInstance().fireModuleDataEvent(
new ModuleDataEvent(moduleName, BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_FILE_HIT, Collections.singletonList(artifact)));
141 }
catch (TskCoreException ex) {
142 FilesIdentifierIngestModule.logger.log(Level.SEVERE,
"Error posting to the blackboard", ex);
146 return ProcessResult.OK;
153 public void shutDown() {
154 if (context != null) {
155 if (refCounter.decrementAndGet(
this.context.getJobId()) == 0) {
159 FilesIdentifierIngestModule.interestingFileSetsByJob.remove(this.context.getJobId());