19 package org.sleuthkit.autopsy.datamodel;
21 import java.beans.PropertyChangeEvent;
22 import java.beans.PropertyChangeListener;
23 import java.sql.ResultSet;
24 import java.sql.SQLException;
25 import java.util.ArrayList;
26 import java.util.Collections;
27 import java.util.HashSet;
28 import java.util.LinkedHashMap;
29 import java.util.List;
31 import java.util.Observable;
32 import java.util.Observer;
34 import java.util.logging.Level;
35 import org.openide.nodes.ChildFactory;
36 import org.openide.nodes.Children;
37 import org.openide.nodes.Node;
38 import org.openide.nodes.Sheet;
39 import org.openide.util.NbBundle;
40 import org.openide.util.lookup.Lookups;
48 import org.
sleuthkit.datamodel.SleuthkitCase.CaseDbQuery;
54 .getMessage(
InterestingHits.class,
"InterestingHits.interestingItems.text");
62 interestingResults.
update();
70 List<String> setNames =
new ArrayList<>(interestingItemsMap.keySet());
71 Collections.sort(setNames);
76 return interestingItemsMap.get(setName);
80 interestingItemsMap.clear();
81 loadArtifacts(BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_FILE_HIT);
82 loadArtifacts(BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_ARTIFACT_HIT);
91 @SuppressWarnings(
"deprecation")
97 int setNameId = BlackboardAttribute.ATTRIBUTE_TYPE.TSK_SET_NAME.getTypeID();
98 int artId = artType.getTypeID();
99 String query =
"SELECT value_text,blackboard_attributes.artifact_id,attribute_type_id "
100 +
"FROM blackboard_attributes,blackboard_artifacts WHERE "
101 +
"attribute_type_id=" + setNameId
102 +
" AND blackboard_attributes.artifact_id=blackboard_artifacts.artifact_id"
103 +
" AND blackboard_artifacts.artifact_type_id=" + artId;
105 try (CaseDbQuery dbQuery = skCase.executeQuery(query)) {
106 ResultSet resultSet = dbQuery.getResultSet();
107 while (resultSet.next()) {
108 String value = resultSet.getString(
"value_text");
109 long artifactId = resultSet.getLong(
"artifact_id");
110 if (!interestingItemsMap.containsKey(value)) {
111 interestingItemsMap.put(value,
new HashSet<>());
113 interestingItemsMap.get(value).add(artifactId);
115 }
catch (TskCoreException | SQLException ex) {
116 logger.log(Level.WARNING,
"SQL Exception occurred: ", ex);
122 public <T> T accept(AutopsyItemVisitor<T> v) {
123 return v.visit(
this);
132 super(Children.create(
new SetNameFactory(),
true), Lookups.singleton(DISPLAY_NAME));
133 super.setName(INTERESTING_ITEMS);
134 super.setDisplayName(DISPLAY_NAME);
135 this.setIconBaseWithExtension(
"org/sleuthkit/autopsy/images/interesting_item.png");
145 return v.
visit(
this);
150 Sheet s = super.createSheet();
151 Sheet.Set ss = s.get(Sheet.PROPERTIES);
153 ss = Sheet.createPropertiesSet();
157 ss.put(
new NodeProperty<>(NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.name"),
158 NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.displayName"),
159 NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.desc"),
176 private class SetNameFactory extends ChildFactory.Detachable<String> implements Observer {
183 private final PropertyChangeListener
pcl =
new PropertyChangeListener() {
185 public void propertyChange(PropertyChangeEvent evt) {
186 String eventType = evt.getPropertyName();
203 if (null != eventData && (eventData.
getBlackboardArtifactType().getTypeID() == BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_ARTIFACT_HIT.getTypeID()
204 || eventData.
getBlackboardArtifactType().getTypeID() == BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_FILE_HIT.getTypeID())) {
205 interestingResults.
update();
207 }
catch (IllegalStateException notUsed) {
222 interestingResults.
update();
223 }
catch (IllegalStateException notUsed) {
230 if (evt.getNewValue() == null) {
243 interestingResults.
update();
244 interestingResults.addObserver(
this);
252 interestingResults.deleteObserver(
this);
267 public void update(Observable o, Object arg) {
277 super(Children.create(
new HitFactory(setName),
true), Lookups.singleton(setName));
279 super.setName(setName);
281 this.setIconBaseWithExtension(
"org/sleuthkit/autopsy/images/interesting_item.png");
282 interestingResults.addObserver(
this);
286 super.setDisplayName(setName +
" (" + interestingResults.
getArtifactIds(setName).size() +
")");
296 Sheet s = super.createSheet();
297 Sheet.Set ss = s.get(Sheet.PROPERTIES);
299 ss = Sheet.createPropertiesSet();
303 ss.put(
new NodeProperty<>(NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.name"),
304 NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.name"),
305 NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.desc"),
313 return v.
visit(
this);
317 public void update(Observable o, Object arg) {
332 private class HitFactory extends ChildFactory<Long> implements Observer {
339 interestingResults.addObserver(
this);
352 if (skCase == null) {
357 }
catch (TskCoreException ex) {
358 logger.log(Level.SEVERE,
"Error creating new Blackboard Artifact node", ex);
364 public void update(Observable o, Object arg) {
static final String DISPLAY_NAME
BlackboardArtifact.Type getBlackboardArtifactType()
void removeIngestModuleEventListener(final PropertyChangeListener listener)
static final String INTERESTING_ITEMS
static synchronized IngestManager getInstance()
Node createNodeForKey(Long l)
void loadArtifacts(BlackboardArtifact.ARTIFACT_TYPE artType)
void update(Observable o, Object arg)
boolean createKeys(List< String > list)
boolean createKeys(List< Long > list)
List< String > getSetNames()
T visit(DataSourcesNode in)
void removeIngestJobEventListener(final PropertyChangeListener listener)
final PropertyChangeListener pcl
SetNameNode(String setName)
Set< Long > getArtifactIds(String setName)
void addIngestJobEventListener(final PropertyChangeListener listener)
void update(Observable o, Object arg)
void update(Observable o, Object arg)
static synchronized void removePropertyChangeListener(PropertyChangeListener listener)
HitFactory(String setName)
void addIngestModuleEventListener(final PropertyChangeListener listener)
final Map< String, Set< Long > > interestingItemsMap
static synchronized void addPropertyChangeListener(PropertyChangeListener listener)
Node createNodeForKey(String key)
static Case getCurrentCase()
synchronized static Logger getLogger(String name)
InterestingHits(SleuthkitCase skCase)
final InterestingResults interestingResults
static final Logger logger