23 package org.sleuthkit.autopsy.recentactivity;
26 import java.nio.file.Paths;
27 import java.util.ArrayList;
28 import java.util.List;
29 import java.util.logging.Level;
30 import org.openide.util.NbBundle;
49 private final List<Extract>
extractors =
new ArrayList<>();
65 iexplore =
new ExtractIE();
66 edge =
new ExtractEdge();
71 Extract registry =
new ExtractRegistry();
72 Extract recentDocuments =
new RecentDocumentsByLnk();
73 Extract chrome =
new Chrome();
74 Extract firefox =
new Firefox();
75 Extract SEUQA =
new SearchEngineURLQueryAnalyzer();
76 Extract osExtract =
new ExtractOs();
77 Extract dataSourceAnalyzer =
new DataSourceUsageAnalyzer();
78 Extract safari =
new ExtractSafari();
79 Extract zoneInfo =
new ExtractZoneIdentifier();
80 Extract recycleBin =
new ExtractRecycleBin();
82 extractors.add(chrome);
83 extractors.add(firefox);
84 extractors.add(iexplore);
86 extractors.add(safari);
87 extractors.add(recentDocuments);
88 extractors.add(SEUQA);
89 extractors.add(registry);
90 extractors.add(osExtract);
91 extractors.add(dataSourceAnalyzer);
92 extractors.add(zoneInfo);
93 extractors.add(recycleBin);
95 browserExtractors.add(chrome);
96 browserExtractors.add(firefox);
97 browserExtractors.add(iexplore);
98 browserExtractors.add(edge);
99 browserExtractors.add(safari);
101 for (Extract extractor : extractors) {
109 NbBundle.getMessage(this.getClass(),
110 "RAImageIngestModule.process.started",
111 dataSource.getName())));
115 ArrayList<String> errors =
new ArrayList<>();
117 for (
int i = 0; i < extractors.size(); i++) {
118 Extract extracter = extractors.get(i);
120 logger.log(Level.INFO,
"Recent Activity has been canceled, quitting before {0}", extracter.getName());
124 progressBar.
progress(extracter.getName(), i);
127 extracter.process(dataSource, context, progressBar);
128 }
catch (Exception ex) {
129 logger.log(Level.SEVERE,
"Exception occurred in " + extracter.getName(), ex);
130 subCompleted.append(NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.errModFailed",
131 extracter.getName()));
136 errors.addAll(extracter.getErrorMessages());
140 StringBuilder errorMessage =
new StringBuilder();
141 String errorMsgSubject;
143 if (errors.isEmpty() ==
false) {
146 NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.errMsg.errsEncountered"));
147 for (String msg : errors) {
148 errorMessage.append(
"<li>").append(msg).append(
"</li>\n");
150 errorMessage.append(
"</ul>\n");
152 if (errors.size() == 1) {
153 errorMsgSubject = NbBundle.getMessage(this.getClass(),
"RAImageIngestModule.process.errMsgSub.oneErr");
155 errorMsgSubject = NbBundle.getMessage(this.getClass(),
156 "RAImageIngestModule.process.errMsgSub.nErrs", errors.size());
159 errorMessage.append(NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.errMsg.noErrs"));
160 errorMsgSubject = NbBundle.getMessage(this.getClass(),
"RAImageIngestModule.process.errMsgSub.noErrs");
163 NbBundle.getMessage(this.getClass(),
164 "RAImageIngestModule.process.ingestMsg.finished",
165 dataSource.getName(), errorMsgSubject),
166 errorMessage.toString());
169 StringBuilder historyMsg =
new StringBuilder();
171 NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.histMsg.title", dataSource.getName()));
172 for (Extract module : browserExtractors) {
173 historyMsg.append(
"<li>").append(module.getName());
174 historyMsg.append(
": ").append((module.foundData()) ? NbBundle
175 .getMessage(this.getClass(),
"RAImageIngestModule.process.histMsg.found") : NbBundle
176 .getMessage(this.getClass(),
"RAImageIngestModule.process.histMsg.notFnd"));
177 historyMsg.append(
"</li>");
179 historyMsg.append(
"</ul>");
181 NbBundle.getMessage(this.getClass(),
182 "RAImageIngestModule.process.ingestMsg.results",
183 dataSource.getName()),
184 historyMsg.toString());
191 for (
int i = 0; i < extractors.size(); i++) {
192 Extract extracter = extractors.get(i);
194 extracter.complete();
195 }
catch (Exception ex) {
196 logger.log(Level.SEVERE,
"Exception occurred when completing " + extracter.getName(), ex);
197 subCompleted.append(NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.complete.errMsg.failed",
198 extracter.getName()));
216 String tmpDir = a_case.
getTempDirectory() + File.separator +
"RecentActivity" + File.separator + mod;
217 File dir =
new File(tmpDir);
218 if (dir.exists() ==
false) {
235 String tmpDir = a_case.
getModuleDirectory() + File.separator +
"RecentActivity" + File.separator + mod;
236 File dir =
new File(tmpDir);
237 if (dir.exists() ==
false) {
251 "RecentActivity").normalize().toString() ;
String getModuleOutputDirectoryRelativePath()
final List< Extract > extractors
static final Logger logger
String getTempDirectory()
static String getRATempPath(Case a_case, String mod)
StringBuilder subCompleted
static IngestMessage createMessage(MessageType messageType, String source, String subject, String detailsHtml)
ProcessResult process(Content dataSource, DataSourceIngestModuleProgress progressBar)
static String getRAOutputPath(Case a_case, String mod)
void postMessage(final IngestMessage message)
String getModuleDirectory()
void startUp(IngestJobContext context)
boolean dataSourceIngestIsCancelled()
final List< Extract > browserExtractors
void switchToDeterminate(int workUnits)
synchronized static Logger getLogger(String name)
static Case getCurrentCaseThrows()
void progress(int workUnits)
static synchronized IngestServices getInstance()