19 package org.sleuthkit.autopsy.datamodel;
21 import java.beans.PropertyChangeEvent;
22 import java.beans.PropertyChangeListener;
23 import java.sql.ResultSet;
24 import java.sql.SQLException;
25 import java.util.ArrayList;
26 import java.util.Collections;
27 import java.util.HashMap;
28 import java.util.HashSet;
29 import java.util.LinkedHashMap;
30 import java.util.List;
32 import java.util.Observable;
33 import java.util.Observer;
35 import java.util.logging.Level;
36 import org.openide.nodes.ChildFactory;
37 import org.openide.nodes.Children;
38 import org.openide.nodes.Node;
39 import org.openide.nodes.Sheet;
40 import org.openide.util.NbBundle;
41 import org.openide.util.lookup.Lookups;
49 import org.
sleuthkit.datamodel.SleuthkitCase.CaseDbQuery;
55 .getMessage(
InterestingHits.class,
"InterestingHits.interestingItems.text");
63 interestingResults.
update();
72 List<String> setNames;
74 setNames =
new ArrayList<>(interestingItemsMap.keySet());
76 Collections.sort(setNames);
82 return interestingItemsMap.get(setName).get(typeName);
88 interestingItemsMap.clear();
90 loadArtifacts(BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_FILE_HIT);
91 loadArtifacts(BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_ARTIFACT_HIT);
100 @SuppressWarnings(
"deprecation")
102 if (skCase == null) {
106 int setNameId = BlackboardAttribute.ATTRIBUTE_TYPE.TSK_SET_NAME.getTypeID();
107 int artId = artType.getTypeID();
108 String query =
"SELECT value_text,blackboard_attributes.artifact_id,attribute_type_id "
109 +
"FROM blackboard_attributes,blackboard_artifacts WHERE "
110 +
"attribute_type_id=" + setNameId
111 +
" AND blackboard_attributes.artifact_id=blackboard_artifacts.artifact_id"
112 +
" AND blackboard_artifacts.artifact_type_id=" + artId;
114 try (CaseDbQuery dbQuery = skCase.executeQuery(query)) {
116 ResultSet resultSet = dbQuery.getResultSet();
117 while (resultSet.next()) {
118 String value = resultSet.getString(
"value_text");
119 long artifactId = resultSet.getLong(
"artifact_id");
120 if (!interestingItemsMap.containsKey(value)) {
121 interestingItemsMap.put(value,
new LinkedHashMap<>());
122 interestingItemsMap.get(value).put(BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_FILE_HIT.getDisplayName(),
new HashSet<>());
123 interestingItemsMap.get(value).put(BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_ARTIFACT_HIT.getDisplayName(),
new HashSet<>());
125 interestingItemsMap.get(value).get(artType.getDisplayName()).add(artifactId);
128 }
catch (TskCoreException | SQLException ex) {
129 logger.log(Level.WARNING,
"SQL Exception occurred: ", ex);
136 return v.
visit(
this);
145 super(Children.create(
new SetNameFactory(),
true), Lookups.singleton(DISPLAY_NAME));
146 super.setName(INTERESTING_ITEMS);
147 super.setDisplayName(DISPLAY_NAME);
148 this.setIconBaseWithExtension(
"org/sleuthkit/autopsy/images/interesting_item.png");
158 return v.
visit(
this);
163 Sheet s = super.createSheet();
164 Sheet.Set ss = s.get(Sheet.PROPERTIES);
166 ss = Sheet.createPropertiesSet();
170 ss.put(
new NodeProperty<>(NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.name"),
171 NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.displayName"),
172 NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.desc"),
180 return getClass().getName();
184 private class SetNameFactory extends ChildFactory.Detachable<String> implements Observer {
191 private final PropertyChangeListener
pcl =
new PropertyChangeListener() {
193 public void propertyChange(PropertyChangeEvent evt) {
194 String eventType = evt.getPropertyName();
211 if (null != eventData && (eventData.
getBlackboardArtifactType().getTypeID() == BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_ARTIFACT_HIT.getTypeID()
212 || eventData.
getBlackboardArtifactType().getTypeID() == BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_FILE_HIT.getTypeID())) {
213 interestingResults.
update();
215 }
catch (IllegalStateException notUsed) {
230 interestingResults.
update();
231 }
catch (IllegalStateException notUsed) {
238 if (evt.getNewValue() == null) {
251 interestingResults.
update();
252 interestingResults.addObserver(
this);
260 interestingResults.deleteObserver(
this);
275 public void update(Observable o, Object arg) {
285 super(Children.create(
new HitTypeFactory(setName),
true), Lookups.singleton(setName));
287 super.setName(setName);
289 this.setIconBaseWithExtension(
"org/sleuthkit/autopsy/images/interesting_item.png");
290 interestingResults.addObserver(
this);
294 int sizeOfSet = interestingResults.
getArtifactIds(setName, BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_ARTIFACT_HIT.getDisplayName()).size()
295 + interestingResults.
getArtifactIds(setName, BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_FILE_HIT.getDisplayName()).size();
296 super.setDisplayName(setName +
" (" + sizeOfSet +
")");
306 Sheet s = super.createSheet();
307 Sheet.Set ss = s.get(Sheet.PROPERTIES);
309 ss = Sheet.createPropertiesSet();
313 ss.put(
new NodeProperty<>(NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.name"),
314 NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.name"),
315 NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.desc"),
323 return v.
visit(
this);
327 public void update(Observable o, Object arg) {
337 return getClass().getName();
344 private final Map<Long, BlackboardArtifact>
artifactHits =
new HashMap<>();
349 interestingResults.addObserver(
this);
354 list.add(BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_FILE_HIT.getDisplayName());
355 list.add(BlackboardArtifact.ARTIFACT_TYPE.TSK_INTERESTING_ARTIFACT_HIT.getDisplayName());
365 public void update(Observable o, Object arg) {
376 super(Children.create(
new HitFactory(setName, typeName),
true), Lookups.singleton(setName));
379 super.setName(typeName);
381 this.setIconBaseWithExtension(
"org/sleuthkit/autopsy/images/interesting_item.png");
382 interestingResults.addObserver(
this);
386 super.setDisplayName(typeName +
" (" + interestingResults.
getArtifactIds(setName, typeName).size() +
")");
396 Sheet s = super.createSheet();
397 Sheet.Set ss = s.get(Sheet.PROPERTIES);
399 ss = Sheet.createPropertiesSet();
402 ss.put(
new NodeProperty<>(NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.name"),
403 NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.name"),
404 NbBundle.getMessage(
this.getClass(),
"InterestingHits.createSheet.name.desc"),
411 return v.
visit(
this);
415 public void update(Observable o, Object arg) {
425 return getClass().getName();
429 private class HitFactory extends ChildFactory<Long> implements Observer {
433 private final Map<Long, BlackboardArtifact>
artifactHits =
new HashMap<>();
439 interestingResults.addObserver(
this);
445 if (skCase == null) {
449 interestingResults.
getArtifactIds(setName, typeName).forEach((
id) -> {
451 if (!artifactHits.containsKey(
id)) {
452 BlackboardArtifact art = skCase.getBlackboardArtifact(
id);
453 artifactHits.put(
id, art);
456 }
catch (TskCoreException ex) {
457 logger.log(Level.SEVERE,
"TSK Exception occurred", ex);
465 BlackboardArtifact art = artifactHits.get(l);
470 public void update(Observable o, Object arg) {
static final String DISPLAY_NAME
BlackboardArtifact.Type getBlackboardArtifactType()
void removeIngestModuleEventListener(final PropertyChangeListener listener)
static final String INTERESTING_ITEMS
HitTypeFactory(String setName)
static synchronized IngestManager getInstance()
boolean createKeys(List< String > list)
Node createNodeForKey(String key)
Node createNodeForKey(Long l)
static void removePropertyChangeListener(PropertyChangeListener listener)
void loadArtifacts(BlackboardArtifact.ARTIFACT_TYPE artType)
void update(Observable o, Object arg)
boolean createKeys(List< String > list)
boolean createKeys(List< Long > list)
List< String > getSetNames()
HitFactory(String setName, String typeName)
T visit(DataSourcesNode in)
void removeIngestJobEventListener(final PropertyChangeListener listener)
final PropertyChangeListener pcl
void update(Observable o, Object arg)
SetNameNode(String setName)
void addIngestJobEventListener(final PropertyChangeListener listener)
Set< Long > getArtifactIds(String setName, String typeName)
void update(Observable o, Object arg)
static void addPropertyChangeListener(PropertyChangeListener listener)
void update(Observable o, Object arg)
final Map< Long, BlackboardArtifact > artifactHits
void addIngestModuleEventListener(final PropertyChangeListener listener)
Node createNodeForKey(String key)
InterestingItemTypeNode(String setName, String typeName)
static Case getCurrentCase()
synchronized static Logger getLogger(String name)
InterestingHits(SleuthkitCase skCase)
final Map< Long, BlackboardArtifact > artifactHits
final InterestingResults interestingResults
final Map< String, Map< String, Set< Long > > > interestingItemsMap
void update(Observable o, Object arg)
static final Logger logger