Autopsy  4.16.0
Graphical digital forensics platform for The Sleuth Kit and other tools.
org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule Class Reference

Inherits org.sleuthkit.autopsy.ingest.FileIngestModule.


class  FindInHashsetsResult
class  IngestJobTotals

Public Member Functions

ProcessResult process (AbstractFile file)
void shutDown ()
void startUp (org.sleuthkit.autopsy.ingest.IngestJobContext context) throws IngestModuleException

Private Member Functions

boolean createArtifactIfNotExists (String hashSetName, AbstractFile file, String comment, HashDb db)
FindInHashsetsResult findInHashsets (AbstractFile file, AtomicLong totalCount, AtomicLong totalLookupTime, List< HashDb > hashSets, TskData.FileKnown statusIfFound, Function< AbstractFile, String > lookupErrorMessage)
String generateComment (HashHitInfo hashInfo)
String getHash (AbstractFile file, IngestJobTotals totals)
void initializeHashsets (List< HashDb > allHashSets)
void postHashSetHitToBlackboard (AbstractFile abstractFile, String md5Hash, String hashSetName, String comment, boolean showInboxMessage)
void reportLookupError (TskException ex, AbstractFile file, Function< AbstractFile, String > lookupErrorMessage)
boolean shouldSkip (AbstractFile file)

Static Private Member Functions

static synchronized IngestJobTotals getTotalsForIngestJobs (long ingestJobId)
static synchronized void postSummary (long jobId, List< HashDb > knownBadHashSets, List< HashDb > noChangeHashSets, List< HashDb > knownHashSets)

Private Attributes

Blackboard blackboard
final HashDbManager hashDbManager = HashDbManager.getInstance()
long jobId
final List< HashDbknownBadHashSets = new ArrayList<>()
final Function< AbstractFile, String > knownBadLookupError = (file) -> Bundle.HashDbIngestModule_lookingUpKnownBadHashValueErr(file.getName())
final List< HashDbknownHashSets = new ArrayList<>()
final Function< AbstractFile, String > knownLookupError = (file) -> Bundle.HashDbIngestModule_lookingUpKnownHashValueErr(file.getName())
final List< HashDbnoChangeHashSets = new ArrayList<>()
final Function< AbstractFile, String > noChangeLookupError = (file) -> Bundle.HashDbIngestModule_lookingUpNoChangeHashValueErr(file.getName())
final IngestServices services = IngestServices.getInstance()
final HashLookupModuleSettings settings
final SleuthkitCase skCase

Static Private Attributes

static final Logger logger = Logger.getLogger(HashDbIngestModule.class.getName())
static final int MAX_COMMENT_SIZE = 500
static final IngestModuleReferenceCounter refCounter = new IngestModuleReferenceCounter()
static final HashMap< Long, IngestJobTotalstotalsForIngestJobs = new HashMap<>()

Detailed Description

File ingest module to mark files based on hash values.

Definition at line 67 of file

Member Function Documentation

boolean org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.createArtifactIfNotExists ( String  hashSetName,
AbstractFile  file,
String  comment,
HashDb  db 

Creates a BlackboardArtifact if artifact does not already exist.

hashSetNameThe name of the hashset found.
fileThe file that had a hash hit.
commentThe comment to associate with this artifact.
dbthe database in which this file was found.
True if the operation occurred successfully and without error.

Definition at line 429 of file

References org.sleuthkit.autopsy.ingest.IngestMessage.createErrorMessage(), org.sleuthkit.autopsy.modules.hashdatabase.HashLookupModuleFactory.getModuleName(), org.sleuthkit.autopsy.modules.hashdatabase.HashDbManager.HashDb.getSendIngestMessages(), and org.sleuthkit.autopsy.ingest.IngestServices.postMessage().

FindInHashsetsResult org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.findInHashsets ( AbstractFile  file,
AtomicLong  totalCount,
AtomicLong  totalLookupTime,
List< HashDb hashSets,
TskData.FileKnown  statusIfFound,
Function< AbstractFile, String >  lookupErrorMessage 

Attempts to find an abstract file in a list of HashDB objects.

fileThe file to find.
totalCountThe total cound of files found in this type
totalLookupTimeThe counter tracking the total amount of run time for this operation.
hashSetsThe HashDB objects to cycle through looking for a hash hit.
statusIfFoundThe FileKnown status to set on the file if the file is found in the hashSets.
lookupErrorMessageThe function that generates a message should there be an error in looking up the file in the hashSets.
Whether or not the file was found and whether or not there was an error during the operation.

Definition at line 363 of file

String org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.generateComment ( HashHitInfo  hashInfo)

Generates a formatted comment.

hashInfoThe HashHitInfo.
The formatted comment.

Definition at line 402 of file

String org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.getHash ( AbstractFile  file,
IngestJobTotals  totals 
static synchronized IngestJobTotals org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.getTotalsForIngestJobs ( long  ingestJobId)

Definition at line 104 of file

void org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.initializeHashsets ( List< HashDb allHashSets)

Cycle through list of hashsets and place each HashDB in the appropriate list based on KnownFilesType.

allHashSetsList of all hashsets from DB manager

Definition at line 163 of file

void org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.postHashSetHitToBlackboard ( AbstractFile  abstractFile,
String  md5Hash,
String  hashSetName,
String  comment,
boolean  showInboxMessage 

Post a hash set hit to the blackboard.

abstractFileThe file to be processed.
md5HashThe MD5 hash value of the file.
hashSetNameThe name of the hash set with which to associate the hit.
commentA comment to be attached to the artifact.
showInboxMessageShow a message in the inbox?

Definition at line 513 of file

References org.sleuthkit.autopsy.ingest.IngestMessage.createDataMessage(), org.sleuthkit.autopsy.coreutils.MessageNotifyUtil.Notify.error(), org.sleuthkit.autopsy.modules.hashdatabase.HashLookupModuleFactory.getModuleName(), and org.sleuthkit.autopsy.ingest.IngestServices.postMessage().

static synchronized void org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.postSummary ( long  jobId,
List< HashDb knownBadHashSets,
List< HashDb noChangeHashSets,
List< HashDb knownHashSets 
ProcessResult org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.process ( AbstractFile  file)
void org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.reportLookupError ( TskException  ex,
AbstractFile  file,
Function< AbstractFile, String >  lookupErrorMessage 

Reports an error when an issue is encountered looking up a file.

exThe exception thrown in the error.
fileThe file for which this error applies.
lookupErrorMessageThe function that generates an error message specific to which piece of the ingest processing failed.

Definition at line 302 of file

References org.sleuthkit.autopsy.ingest.IngestMessage.createErrorMessage(), org.sleuthkit.autopsy.modules.hashdatabase.HashLookupModuleFactory.getModuleName(), and org.sleuthkit.autopsy.ingest.IngestServices.postMessage().

boolean org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.shouldSkip ( AbstractFile  file)

Returns true if this file should be skipped for processing.

fileThe file to potentially skip.
True if this file should be skipped.

Definition at line 268 of file

void org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.shutDown ( )

Invoked by Autopsy when an ingest job is completed (either because the data has been analyzed or because the job was canceled - check IngestJobContext.fileIngestIsCancelled()), before the ingest module instance is discarded. The module should respond by doing things like releasing private resources, submitting final results, and posting a final ingest message.

Implements org.sleuthkit.autopsy.ingest.FileIngestModule.

Definition at line 628 of file

References org.sleuthkit.autopsy.ingest.IngestModuleReferenceCounter.decrementAndGet().

void org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.startUp ( org.sleuthkit.autopsy.ingest.IngestJobContext  context) throws IngestModuleException

Invoked by Autopsy to allow an ingest module instance to set up any internal data structures and acquire any private resources it will need during an ingest job. If the module depends on loading any resources, it should do so in this method so that it can throw an exception in the case of an error and alert the user. Exceptions that are thrown from process() and shutDown() are logged, but do not stop processing of the data source.

contextProvides data and services specific to the ingest job and the ingest pipeline of which the module is a part.

Implements org.sleuthkit.autopsy.ingest.IngestModule.

Definition at line 128 of file

References org.sleuthkit.autopsy.ingest.IngestMessage.createWarningMessage(), org.sleuthkit.autopsy.modules.hashdatabase.HashDbManager.getAllHashSets(), org.sleuthkit.autopsy.modules.hashdatabase.HashLookupModuleFactory.getModuleName(), org.sleuthkit.autopsy.ingest.IngestModuleReferenceCounter.incrementAndGet(), and org.sleuthkit.autopsy.ingest.IngestServices.postMessage().

Member Data Documentation

Blackboard org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.blackboard

Definition at line 91 of file

final HashDbManager org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.hashDbManager = HashDbManager.getInstance()

Definition at line 83 of file

long org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.jobId

Definition at line 88 of file

final List<HashDb> org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.knownBadHashSets = new ArrayList<>()

Definition at line 85 of file

final Function<AbstractFile, String> org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.knownBadLookupError = (file) -> Bundle.HashDbIngestModule_lookingUpKnownBadHashValueErr(file.getName())

Definition at line 72 of file

final List<HashDb> org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.knownHashSets = new ArrayList<>()

Definition at line 86 of file

final Function<AbstractFile, String> org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.knownLookupError = (file) -> Bundle.HashDbIngestModule_lookingUpKnownHashValueErr(file.getName())

Definition at line 78 of file

final Logger org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.logger = Logger.getLogger(HashDbIngestModule.class.getName())

Definition at line 69 of file

final int org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.MAX_COMMENT_SIZE = 500

Definition at line 80 of file

final List<HashDb> org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.noChangeHashSets = new ArrayList<>()

Definition at line 87 of file

final Function<AbstractFile, String> org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.noChangeLookupError = (file) -> Bundle.HashDbIngestModule_lookingUpNoChangeHashValueErr(file.getName())

Definition at line 75 of file

final IngestModuleReferenceCounter org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.refCounter = new IngestModuleReferenceCounter()

Definition at line 90 of file

final IngestServices = IngestServices.getInstance()

Definition at line 81 of file

final HashLookupModuleSettings org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.settings

Definition at line 84 of file

final SleuthkitCase org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.skCase

Definition at line 82 of file

final HashMap<Long, IngestJobTotals> org.sleuthkit.autopsy.modules.hashdatabase.HashDbIngestModule.totalsForIngestJobs = new HashMap<>()

Definition at line 89 of file

The documentation for this class was generated from the following file:

