Autopsy  4.21.0
Graphical digital forensics platform for The Sleuth Kit and other tools.
Public Member Functions | Protected Member Functions | Private Member Functions | Private Attributes | Static Private Attributes | List of all members
org.sleuthkit.autopsy.modules.yara.YaraIngestModule Class Reference

Inherits org.sleuthkit.autopsy.ingest.FileIngestModuleAdapter.

Public Member Functions

ProcessResult process (AbstractFile file)
void shutDown ()
void startUp (IngestJobContext context) throws IngestModuleException

Protected Member Functions

File createLocalCopy (AbstractFile file) throws IngestModuleException, IOException

Private Member Functions

synchronized Path getTempDirectory (long jobId) throws IngestModuleException

Private Attributes

IngestJobContext context = null
Long jobId
final YaraIngestJobSettings settings

Static Private Attributes

static final int FILE_SIZE_THRESHOLD_BYTE = FILE_SIZE_THRESHOLD_MB * 1024 * 1024
static final int FILE_SIZE_THRESHOLD_MB = 100
static final Logger logger = Logger.getLogger(YaraIngestModule.class.getName())
static final Map< Long, Path > pathsByJobId = new ConcurrentHashMap<>()
static final IngestModuleReferenceCounter refCounter = new IngestModuleReferenceCounter()
static final String RULESET_DIR = "RuleSets"
static final String YARA_DIR = "yara"
static final int YARA_SCAN_TIMEOUT_SEC = 30 * 60 * 60

Detailed Description

An ingest module that runs the yara against the given files.

Definition at line 53 of file

Member Function Documentation

File org.sleuthkit.autopsy.modules.yara.YaraIngestModule.createLocalCopy ( AbstractFile  file) throws IngestModuleException, IOException

Create a local copy of the given AbstractFile.

fileAbstractFile to make a copy of.
A File object representation of the local copy.

Definition at line 223 of file

References org.sleuthkit.autopsy.ingest.IngestJobContext.getJobId(), org.sleuthkit.autopsy.modules.yara.YaraIngestModule.getTempDirectory(), and org.sleuthkit.autopsy.datamodel.ContentUtils.writeToFile().

Referenced by org.sleuthkit.autopsy.modules.yara.YaraIngestModule.process().

synchronized Path org.sleuthkit.autopsy.modules.yara.YaraIngestModule.getTempDirectory ( long  jobId) throws IngestModuleException
ProcessResult org.sleuthkit.autopsy.modules.yara.YaraIngestModule.process ( AbstractFile  file)

Processes a file. Called between calls to startUp() and shutDown(). Will be called for each file in a data source.

IMPORTANT: In addition to returning ProcessResult.OK or ProcessResult.ERROR, modules should log all errors using methods provided by the org.sleuthkit.autopsy.coreutils.Logger class. Log messages should include the name and object ID of the data being processed and any other information that would be useful for debugging. If an exception has been caught by the module, the exception should be sent to the logger along with the log message so that a stack trace will appear in the application log.

fileThe file to analyze.
A result code indicating success or failure of the processing.

Implements org.sleuthkit.autopsy.ingest.FileIngestModule.

Definition at line 121 of file

References org.sleuthkit.autopsy.modules.yara.YaraIngestModule.createLocalCopy(), org.sleuthkit.autopsy.ingest.IngestModule.ProcessResult.ERROR, org.sleuthkit.autopsy.modules.yara.YaraIngestModule.FILE_SIZE_THRESHOLD_BYTE, org.sleuthkit.autopsy.casemodule.Case.getCurrentCaseThrows(), org.sleuthkit.autopsy.ingest.IngestJobContext.getJobId(), org.sleuthkit.autopsy.casemodule.Case.getSleuthkitCase(), org.sleuthkit.autopsy.modules.yara.YaraIngestModule.getTempDirectory(), org.sleuthkit.autopsy.ingest.IngestModule.ProcessResult.OK, and org.sleuthkit.autopsy.modules.yara.YaraIngestJobSettings.onlyExecutableFiles.

void org.sleuthkit.autopsy.modules.yara.YaraIngestModule.shutDown ( )

Invoked by Autopsy when an ingest job is completed (either because the data has been analyzed or because the job was cancelled), before the ingest module instance is discarded. The module should respond by doing things like releasing private resources, submitting final results, and posting a final ingest message.

IMPORTANT: If the module instances must share resources, the modules are responsible for synchronizing access to the shared resources and doing reference counting as required to release those resources correctly. Also, more than one ingest job may be in progress at any given time. This must also be taken into consideration when sharing resources between module instances. See IngestModuleReferenceCounter.

Implements org.sleuthkit.autopsy.ingest.IngestModule.

Definition at line 109 of file

References org.sleuthkit.autopsy.ingest.IngestModuleReferenceCounter.decrementAndGet().

void org.sleuthkit.autopsy.modules.yara.YaraIngestModule.startUp ( IngestJobContext  context) throws IngestModuleException

Invoked by Autopsy to allow an ingest module instance to set up any internal data structures and acquire any private resources it will need during an ingest job. If the module depends on loading any resources, it should do so in this method so that it can throw an exception in the case of an error and alert the user. Exceptions that are thrown from startUp() are logged and stop processing of the data source.

IMPORTANT: If the module instances must share resources, the modules are responsible for synchronizing access to the shared resources and doing reference counting as required to release those resources correctly. Also, more than one ingest job may be in progress at any given time. This must also be taken into consideration when sharing resources between module instances. See IngestModuleReferenceCounter.

IMPORTANT: Start up IngestModuleException messages are displayed to the user, if a user is present. Therefore, an exception to the policy that exception messages are not localized is appropriate in this method. Also, the exception messages should be user-friendly.

contextProvides data and services specific to the ingest job and the ingest pipeline of which the module is a part.

Implements org.sleuthkit.autopsy.ingest.IngestModule.

Definition at line 84 of file

References org.sleuthkit.autopsy.modules.yara.YaraIngestModule.context, org.sleuthkit.autopsy.ingest.IngestJobContext.getJobId(), org.sleuthkit.autopsy.modules.yara.YaraIngestJobSettings.getSelectedRuleSetNames(), org.sleuthkit.autopsy.modules.yara.YaraIngestModule.getTempDirectory(), org.sleuthkit.autopsy.ingest.IngestModuleReferenceCounter.incrementAndGet(), org.sleuthkit.autopsy.coreutils.PlatformUtil.is64BitOS(), org.sleuthkit.autopsy.coreutils.PlatformUtil.isWindowsOS(), and org.sleuthkit.autopsy.modules.yara.YaraIngestModule.RULESET_DIR.

Member Data Documentation

IngestJobContext org.sleuthkit.autopsy.modules.yara.YaraIngestModule.context = null
final int org.sleuthkit.autopsy.modules.yara.YaraIngestModule.FILE_SIZE_THRESHOLD_BYTE = FILE_SIZE_THRESHOLD_MB * 1024 * 1024
final int org.sleuthkit.autopsy.modules.yara.YaraIngestModule.FILE_SIZE_THRESHOLD_MB = 100

Definition at line 56 of file

Long org.sleuthkit.autopsy.modules.yara.YaraIngestModule.jobId
final Logger org.sleuthkit.autopsy.modules.yara.YaraIngestModule.logger = Logger.getLogger(YaraIngestModule.class.getName())

Definition at line 61 of file

final Map<Long, Path> org.sleuthkit.autopsy.modules.yara.YaraIngestModule.pathsByJobId = new ConcurrentHashMap<>()

Definition at line 63 of file

final IngestModuleReferenceCounter org.sleuthkit.autopsy.modules.yara.YaraIngestModule.refCounter = new IngestModuleReferenceCounter()

Definition at line 60 of file

final String org.sleuthkit.autopsy.modules.yara.YaraIngestModule.RULESET_DIR = "RuleSets"
final YaraIngestJobSettings org.sleuthkit.autopsy.modules.yara.YaraIngestModule.settings

Definition at line 66 of file

final String org.sleuthkit.autopsy.modules.yara.YaraIngestModule.YARA_DIR = "yara"
final int org.sleuthkit.autopsy.modules.yara.YaraIngestModule.YARA_SCAN_TIMEOUT_SEC = 30 * 60 * 60

Definition at line 58 of file

The documentation for this class was generated from the following file:

Copyright © 2012-2022 Basis Technology. Generated on: Tue Feb 6 2024
This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.