Autopsy  4.1
Graphical digital forensics platform for The Sleuth Kit and other tools.
Classes | Public Member Functions | Static Public Member Functions | Static Private Member Functions | Private Attributes | Static Private Attributes | List of all members
org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule Class Reference

Inherits org.sleuthkit.autopsy.ingest.FileIngestModule.


class  IngestJobTotals

Public Member Functions

ProcessResult process (AbstractFile file)
void shutDown ()
void startUp (IngestJobContext context) throws IngestModuleException

Static Public Member Functions

static boolean isMimeTypeDetectable (String mimeType)

Static Private Member Functions

static synchronized void addToTotals (long jobId, long matchTimeInc)

Private Attributes

FileTypeDetector fileTypeDetector
long jobId

Static Private Attributes

static final Logger logger = Logger.getLogger(FileTypeIdIngestModule.class.getName())
static final IngestModuleReferenceCounter refCounter = new IngestModuleReferenceCounter()
static final HashMap< Long, IngestJobTotalstotalsForIngestJobs = new HashMap<>()

Detailed Description

Detects the type of a file based on signature (magic) values. Posts results to the blackboard.

Definition at line 40 of file

Member Function Documentation

static synchronized void org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.addToTotals ( long  jobId,
long  matchTimeInc 

Update the match time total and increment number of files processed for this ingest job.

jobIdThe ingest job identifier.
matchTimeIncAmount of time to add.

Definition at line 141 of file

static boolean org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.isMimeTypeDetectable ( String  mimeType)

Validate if a given mime type is in the detector's registry.

Use FileTypeDetector.mimeTypeIsDetectable(String mimeType) instead.
mimeTypeFull string of mime type, e.g. "text/html"
true if detectable

Definition at line 58 of file

References org.sleuthkit.autopsy.modules.filetypeid.FileTypeDetector.isDetectable().

ProcessResult org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.process ( AbstractFile  file)

Processes a file. Called between calls to startUp() and shutDown(). Will be called for each file in a data source.

fileThe file to analyze.
A result code indicating success or failure of the processing.

Attempt to detect the file type. Do it within an exception firewall, so that any issues with reading file content or complaints from tika do not take the module down.

Implements org.sleuthkit.autopsy.ingest.FileIngestModule.

Definition at line 86 of file

References org.sleuthkit.autopsy.ingest.IngestModule.ProcessResult.ERROR, org.sleuthkit.autopsy.modules.filetypeid.FileTypeDetector.getFileType(), and org.sleuthkit.autopsy.ingest.IngestModule.ProcessResult.OK.

void org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.shutDown ( )

Invoked by Autopsy when an ingest job is completed (either because the data has been analyzed or because the job was canceled - check IngestJobContext.fileIngestIsCancelled()), before the ingest module instance is discarded. The module should respond by doing things like releasing private resources, submitting final results, and posting a final ingest message.

If this is the instance of this module for this ingest job, post a summary message to the ingest messages box.

Implements org.sleuthkit.autopsy.ingest.FileIngestModule.

Definition at line 105 of file

References org.sleuthkit.autopsy.ingest.IngestMessage.createMessage(), org.sleuthkit.autopsy.ingest.IngestModuleReferenceCounter.decrementAndGet(), org.sleuthkit.autopsy.ingest.IngestServices.getInstance(), org.sleuthkit.autopsy.ingest.IngestMessage.MessageType.INFO, and org.sleuthkit.autopsy.ingest.IngestServices.postMessage().

void org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.startUp ( IngestJobContext  context) throws IngestModuleException

Invoked by Autopsy to allow an ingest module instance to set up any internal data structures and acquire any private resources it will need during an ingest job. If the module depends on loading any resources, it should do so in this method so that it can throw an exception in the case of an error and alert the user. Exceptions that are thrown from process() and shutDown() are logged, but do not stop processing of the data source.

contextProvides data and services specific to the ingest job and the ingest pipeline of which the module is a part.

Implements org.sleuthkit.autopsy.ingest.IngestModule.

Definition at line 75 of file

References org.sleuthkit.autopsy.ingest.IngestModuleReferenceCounter.incrementAndGet().

Member Data Documentation

FileTypeDetector org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.fileTypeDetector

Definition at line 46 of file

long org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.jobId

Definition at line 43 of file

final Logger org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.logger = Logger.getLogger(FileTypeIdIngestModule.class.getName())

Definition at line 42 of file

final IngestModuleReferenceCounter org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.refCounter = new IngestModuleReferenceCounter()

Definition at line 45 of file

final HashMap<Long, IngestJobTotals> org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.totalsForIngestJobs = new HashMap<>()

Definition at line 44 of file

The documentation for this class was generated from the following file:

Copyright © 2012-2016 Basis Technology. Generated on: Tue Oct 25 2016
This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.