23 package org.sleuthkit.autopsy.recentactivity;
26 import java.nio.file.Paths;
27 import java.util.ArrayList;
28 import java.util.List;
29 import java.util.logging.Level;
30 import org.openide.util.NbBundle;
49 private final List<Extract>
extractors =
new ArrayList<>();
65 iexplore =
new ExtractIE();
66 edge =
new ExtractEdge();
71 Extract registry =
new ExtractRegistry();
72 Extract recentDocuments =
new RecentDocumentsByLnk();
73 Extract chrome =
new Chrome();
74 Extract firefox =
new Firefox();
75 Extract SEUQA =
new SearchEngineURLQueryAnalyzer();
76 Extract osExtract =
new ExtractOs();
77 Extract dataSourceAnalyzer =
new DataSourceUsageAnalyzer();
78 Extract safari =
new ExtractSafari();
79 Extract zoneInfo =
new ExtractZoneIdentifier();
80 Extract recycleBin =
new ExtractRecycleBin();
81 Extract sru =
new ExtractSru();
82 Extract prefetch =
new ExtractPrefetch();
84 extractors.add(chrome);
85 extractors.add(firefox);
86 extractors.add(iexplore);
88 extractors.add(safari);
89 extractors.add(recentDocuments);
90 extractors.add(SEUQA);
91 extractors.add(registry);
92 extractors.add(osExtract);
93 extractors.add(dataSourceAnalyzer);
94 extractors.add(zoneInfo);
95 extractors.add(recycleBin);
97 extractors.add(prefetch);
99 browserExtractors.add(chrome);
100 browserExtractors.add(firefox);
101 browserExtractors.add(iexplore);
102 browserExtractors.add(edge);
103 browserExtractors.add(safari);
105 for (Extract extractor : extractors) {
113 NbBundle.getMessage(this.getClass(),
114 "RAImageIngestModule.process.started",
115 dataSource.getName())));
119 ArrayList<String> errors =
new ArrayList<>();
121 for (
int i = 0; i < extractors.size(); i++) {
122 Extract extracter = extractors.get(i);
124 logger.log(Level.INFO,
"Recent Activity has been canceled, quitting before {0}", extracter.getName());
128 progressBar.
progress(extracter.getName(), i);
131 extracter.process(dataSource, context, progressBar);
132 }
catch (Exception ex) {
133 logger.log(Level.SEVERE,
"Exception occurred in " + extracter.getName(), ex);
134 subCompleted.append(NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.errModFailed",
135 extracter.getName()));
140 errors.addAll(extracter.getErrorMessages());
144 StringBuilder errorMessage =
new StringBuilder();
145 String errorMsgSubject;
147 if (errors.isEmpty() ==
false) {
150 NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.errMsg.errsEncountered"));
151 for (String msg : errors) {
152 errorMessage.append(
"<li>").append(msg).append(
"</li>\n");
154 errorMessage.append(
"</ul>\n");
156 if (errors.size() == 1) {
157 errorMsgSubject = NbBundle.getMessage(this.getClass(),
"RAImageIngestModule.process.errMsgSub.oneErr");
159 errorMsgSubject = NbBundle.getMessage(this.getClass(),
160 "RAImageIngestModule.process.errMsgSub.nErrs", errors.size());
163 errorMessage.append(NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.errMsg.noErrs"));
164 errorMsgSubject = NbBundle.getMessage(this.getClass(),
"RAImageIngestModule.process.errMsgSub.noErrs");
167 NbBundle.getMessage(this.getClass(),
168 "RAImageIngestModule.process.ingestMsg.finished",
169 dataSource.getName(), errorMsgSubject),
170 errorMessage.toString());
173 StringBuilder historyMsg =
new StringBuilder();
175 NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.histMsg.title", dataSource.getName()));
176 for (Extract module : browserExtractors) {
177 historyMsg.append(
"<li>").append(module.getName());
178 historyMsg.append(
": ").append((module.foundData()) ? NbBundle
179 .getMessage(this.getClass(),
"RAImageIngestModule.process.histMsg.found") : NbBundle
180 .getMessage(this.getClass(),
"RAImageIngestModule.process.histMsg.notFnd"));
181 historyMsg.append(
"</li>");
183 historyMsg.append(
"</ul>");
185 NbBundle.getMessage(this.getClass(),
186 "RAImageIngestModule.process.ingestMsg.results",
187 dataSource.getName()),
188 historyMsg.toString());
195 for (
int i = 0; i < extractors.size(); i++) {
196 Extract extracter = extractors.get(i);
198 extracter.complete();
199 }
catch (Exception ex) {
200 logger.log(Level.SEVERE,
"Exception occurred when completing " + extracter.getName(), ex);
201 subCompleted.append(NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.complete.errMsg.failed",
202 extracter.getName()));
220 String tmpDir = a_case.
getTempDirectory() + File.separator +
"RecentActivity" + File.separator + mod;
221 File dir =
new File(tmpDir);
222 if (dir.exists() ==
false) {
239 String tmpDir = a_case.
getModuleDirectory() + File.separator +
"RecentActivity" + File.separator + mod;
240 File dir =
new File(tmpDir);
241 if (dir.exists() ==
false) {
255 "RecentActivity").normalize().toString() ;
String getModuleOutputDirectoryRelativePath()
final List< Extract > extractors
static final Logger logger
String getTempDirectory()
static String getRATempPath(Case a_case, String mod)
StringBuilder subCompleted
static IngestMessage createMessage(MessageType messageType, String source, String subject, String detailsHtml)
ProcessResult process(Content dataSource, DataSourceIngestModuleProgress progressBar)
static String getRAOutputPath(Case a_case, String mod)
void postMessage(final IngestMessage message)
String getModuleDirectory()
void startUp(IngestJobContext context)
boolean dataSourceIngestIsCancelled()
final List< Extract > browserExtractors
void switchToDeterminate(int workUnits)
synchronized static Logger getLogger(String name)
static Case getCurrentCaseThrows()
void progress(int workUnits)
static synchronized IngestServices getInstance()