Autopsy  4.1
Graphical digital forensics platform for The Sleuth Kit and other tools.
Classes | Public Member Functions | Private Member Functions | Static Private Member Functions | Private Attributes | Static Private Attributes | List of all members
org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule Class Reference

Inherits org.sleuthkit.autopsy.ingest.FileIngestModule.


class  IngestJobTotals

Public Member Functions

ProcessResult process (AbstractFile file)
void shutDown ()
void startUp (org.sleuthkit.autopsy.ingest.IngestJobContext context) throws IngestModuleException

Private Member Functions

void postHashSetHitToBlackboard (AbstractFile abstractFile, String md5Hash, String hashSetName, String comment, boolean showInboxMessage)
void updateEnabledHashSets (List< HashDb > allHashSets, List< HashDb > enabledHashSets)

Static Private Member Functions

static synchronized IngestJobTotals getTotalsForIngestJobs (long ingestJobId)
static synchronized void postSummary (long jobId, List< HashDb > knownBadHashSets, List< HashDb > knownHashSets)

Private Attributes

Blackboard blackboard
final HashDbManager hashDbManager = HashDbManager.getInstance()
long jobId
List< HashDbknownBadHashSets = new ArrayList<>()
List< HashDbknownHashSets = new ArrayList<>()
final IngestServices services = IngestServices.getInstance()
final HashLookupModuleSettings settings
final SleuthkitCase skCase = Case.getCurrentCase().getSleuthkitCase()

Static Private Attributes

static final Logger logger = Logger.getLogger(HashDbIngestModule.class.getName())
static final int MAX_COMMENT_SIZE = 500
static final IngestModuleReferenceCounter refCounter = new IngestModuleReferenceCounter()
static final HashMap< Long, IngestJobTotalstotalsForIngestJobs = new HashMap<>()

Detailed Description

Definition at line 58 of file

Member Function Documentation

static synchronized IngestJobTotals org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.getTotalsForIngestJobs ( long  ingestJobId)

Definition at line 80 of file

void org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.postHashSetHitToBlackboard ( AbstractFile  abstractFile,
String  md5Hash,
String  hashSetName,
String  comment,
boolean  showInboxMessage 
static synchronized void org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.postSummary ( long  jobId,
List< HashDb knownBadHashSets,
List< HashDb knownHashSets 
ProcessResult org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.process ( AbstractFile  file)
void org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.shutDown ( )

Invoked by Autopsy when an ingest job is completed (either because the data has been analyzed or because the job was canceled - check IngestJobContext.fileIngestIsCancelled()), before the ingest module instance is discarded. The module should respond by doing things like releasing private resources, submitting final results, and posting a final ingest message.

Implements org.sleuthkit.autopsy.ingest.FileIngestModule.

Definition at line 402 of file

References org.sleuthkit.autopsy.ingest.IngestModuleReferenceCounter.decrementAndGet().

void org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.startUp ( org.sleuthkit.autopsy.ingest.IngestJobContext  context) throws IngestModuleException

Invoked by Autopsy to allow an ingest module instance to set up any internal data structures and acquire any private resources it will need during an ingest job. If the module depends on loading any resources, it should do so in this method so that it can throw an exception in the case of an error and alert the user. Exceptions that are thrown from process() and shutDown() are logged, but do not stop processing of the data source.

contextProvides data and services specific to the ingest job and the ingest pipeline of which the module is a part.

Implements org.sleuthkit.autopsy.ingest.IngestModule.

Definition at line 94 of file

References org.sleuthkit.autopsy.ingest.IngestMessage.createWarningMessage(), org.sleuthkit.autopsy.modules.hashdatabase.HashDbManager.getKnownBadFileHashSets(), org.sleuthkit.autopsy.modules.hashdatabase.HashDbManager.getKnownFileHashSets(), org.sleuthkit.autopsy.ingest.IngestModuleReferenceCounter.incrementAndGet(), and org.sleuthkit.autopsy.ingest.IngestServices.postMessage().

void org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.updateEnabledHashSets ( List< HashDb allHashSets,
List< HashDb enabledHashSets 

Cycle through list of hashsets and return the subset that is enabled.

allHashSetsList of all hashsets from DB manager
enabledHashSetsList of enabled ones to return.

Definition at line 129 of file

Member Data Documentation

Blackboard org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.blackboard

Definition at line 71 of file

final HashDbManager org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.hashDbManager = HashDbManager.getInstance()

Definition at line 64 of file

long org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.jobId

Definition at line 68 of file

List<HashDb> org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.knownBadHashSets = new ArrayList<>()

Definition at line 66 of file

List<HashDb> org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.knownHashSets = new ArrayList<>()

Definition at line 67 of file

final Logger org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.logger = Logger.getLogger(HashDbIngestModule.class.getName())

Definition at line 60 of file

final int org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.MAX_COMMENT_SIZE = 500

Definition at line 61 of file

final IngestModuleReferenceCounter org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.refCounter = new IngestModuleReferenceCounter()

Definition at line 70 of file

final IngestServices = IngestServices.getInstance()

Definition at line 62 of file

final HashLookupModuleSettings org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.settings

Definition at line 65 of file

final SleuthkitCase org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.skCase = Case.getCurrentCase().getSleuthkitCase()

Definition at line 63 of file

final HashMap<Long, IngestJobTotals> org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.totalsForIngestJobs = new HashMap<>()

Definition at line 69 of file

The documentation for this class was generated from the following file:

Copyright © 2012-2016 Basis Technology. Generated on: Tue Oct 25 2016
This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.