23 package org.sleuthkit.autopsy.recentactivity;
26 import java.nio.file.Paths;
27 import java.util.ArrayList;
28 import java.util.List;
29 import java.util.logging.Level;
30 import org.openide.util.NbBundle;
49 private final List<Extract>
extractors =
new ArrayList<>();
65 iexplore =
new ExtractIE();
66 edge =
new ExtractEdge();
71 Extract registry =
new ExtractRegistry();
72 Extract recentDocuments =
new RecentDocumentsByLnk();
73 Extract chrome =
new Chromium();
74 Extract firefox =
new Firefox();
75 Extract SEUQA =
new SearchEngineURLQueryAnalyzer();
76 Extract osExtract =
new ExtractOs();
77 Extract dataSourceAnalyzer =
new DataSourceUsageAnalyzer();
78 Extract safari =
new ExtractSafari();
79 Extract zoneInfo =
new ExtractZoneIdentifier();
80 Extract recycleBin =
new ExtractRecycleBin();
81 Extract sru =
new ExtractSru();
82 Extract prefetch =
new ExtractPrefetch();
83 Extract webAccountType =
new ExtractWebAccountType();
85 extractors.add(chrome);
86 extractors.add(firefox);
87 extractors.add(iexplore);
89 extractors.add(safari);
90 extractors.add(recentDocuments);
91 extractors.add(SEUQA);
92 extractors.add(webAccountType);
93 extractors.add(registry);
94 extractors.add(osExtract);
95 extractors.add(dataSourceAnalyzer);
96 extractors.add(zoneInfo);
97 extractors.add(recycleBin);
99 extractors.add(prefetch);
101 browserExtractors.add(chrome);
102 browserExtractors.add(firefox);
103 browserExtractors.add(iexplore);
104 browserExtractors.add(edge);
105 browserExtractors.add(safari);
107 for (Extract extractor : extractors) {
115 NbBundle.getMessage(this.getClass(),
116 "RAImageIngestModule.process.started",
117 dataSource.getName())));
121 ArrayList<String> errors =
new ArrayList<>();
123 for (
int i = 0; i < extractors.size(); i++) {
124 Extract extracter = extractors.get(i);
126 logger.log(Level.INFO,
"Recent Activity has been canceled, quitting before {0}", extracter.getName());
130 progressBar.
progress(extracter.getName(), i);
133 extracter.process(dataSource, context, progressBar);
134 }
catch (Exception ex) {
135 logger.log(Level.SEVERE,
"Exception occurred in " + extracter.getName(), ex);
136 subCompleted.append(NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.errModFailed",
137 extracter.getName()));
142 errors.addAll(extracter.getErrorMessages());
146 StringBuilder errorMessage =
new StringBuilder();
147 String errorMsgSubject;
149 if (errors.isEmpty() ==
false) {
152 NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.errMsg.errsEncountered"));
153 for (String msg : errors) {
154 errorMessage.append(
"<li>").append(msg).append(
"</li>\n");
156 errorMessage.append(
"</ul>\n");
158 if (errors.size() == 1) {
159 errorMsgSubject = NbBundle.getMessage(this.getClass(),
"RAImageIngestModule.process.errMsgSub.oneErr");
161 errorMsgSubject = NbBundle.getMessage(this.getClass(),
162 "RAImageIngestModule.process.errMsgSub.nErrs", errors.size());
165 errorMessage.append(NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.errMsg.noErrs"));
166 errorMsgSubject = NbBundle.getMessage(this.getClass(),
"RAImageIngestModule.process.errMsgSub.noErrs");
169 NbBundle.getMessage(this.getClass(),
170 "RAImageIngestModule.process.ingestMsg.finished",
171 dataSource.getName(), errorMsgSubject),
172 errorMessage.toString());
175 StringBuilder historyMsg =
new StringBuilder();
177 NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.process.histMsg.title", dataSource.getName()));
178 for (Extract module : browserExtractors) {
179 historyMsg.append(
"<li>").append(module.getName());
180 historyMsg.append(
": ").append((module.foundData()) ? NbBundle
181 .getMessage(this.getClass(),
"RAImageIngestModule.process.histMsg.found") : NbBundle
182 .getMessage(this.getClass(),
"RAImageIngestModule.process.histMsg.notFnd"));
183 historyMsg.append(
"</li>");
185 historyMsg.append(
"</ul>");
187 NbBundle.getMessage(this.getClass(),
188 "RAImageIngestModule.process.ingestMsg.results",
189 dataSource.getName()),
190 historyMsg.toString());
197 for (
int i = 0; i < extractors.size(); i++) {
198 Extract extracter = extractors.get(i);
200 extracter.complete();
201 }
catch (Exception ex) {
202 logger.log(Level.SEVERE,
"Exception occurred when completing " + extracter.getName(), ex);
203 subCompleted.append(NbBundle.getMessage(
this.getClass(),
"RAImageIngestModule.complete.errMsg.failed",
204 extracter.getName()));
222 String tmpDir = a_case.
getTempDirectory() + File.separator +
"RecentActivity" + File.separator + mod;
223 File dir =
new File(tmpDir);
224 if (dir.exists() ==
false) {
241 String tmpDir = a_case.
getModuleDirectory() + File.separator +
"RecentActivity" + File.separator + mod;
242 File dir =
new File(tmpDir);
243 if (dir.exists() ==
false) {
257 "RecentActivity").normalize().toString() ;
String getModuleOutputDirectoryRelativePath()
final List< Extract > extractors
static final Logger logger
String getTempDirectory()
static String getRATempPath(Case a_case, String mod)
StringBuilder subCompleted
static IngestMessage createMessage(MessageType messageType, String source, String subject, String detailsHtml)
ProcessResult process(Content dataSource, DataSourceIngestModuleProgress progressBar)
static String getRAOutputPath(Case a_case, String mod)
void postMessage(final IngestMessage message)
String getModuleDirectory()
void startUp(IngestJobContext context)
boolean dataSourceIngestIsCancelled()
final List< Extract > browserExtractors
void switchToDeterminate(int workUnits)
synchronized static Logger getLogger(String name)
static Case getCurrentCaseThrows()
void progress(int workUnits)
static synchronized IngestServices getInstance()