Autopsy  4.5.0
Graphical digital forensics platform for The Sleuth Kit and other tools.
Classes | Public Member Functions | Static Public Member Functions | Private Member Functions | Static Private Member Functions | Private Attributes | Static Private Attributes | List of all members
org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule Class Reference

Inherits org.sleuthkit.autopsy.ingest.FileIngestModule.


class  IngestJobTotals

Public Member Functions

ProcessResult process (AbstractFile file)
void shutDown ()
void startUp (IngestJobContext context) throws IngestModuleException

Static Public Member Functions

static boolean isMimeTypeDetectable (String mimeType)

Private Member Functions

void createInterestingFileHit (AbstractFile file, FileType fileType)
FileType detectUserDefinedFileType (AbstractFile file) throws CustomFileTypesManager.CustomFileTypesException

Static Private Member Functions

static synchronized void addToTotals (long jobId, long matchTimeInc)

Private Attributes

FileTypeDetector fileTypeDetector
long jobId

Static Private Attributes

static final Logger logger = Logger.getLogger(FileTypeIdIngestModule.class.getName())
static final IngestModuleReferenceCounter refCounter = new IngestModuleReferenceCounter()
static final HashMap< Long, IngestJobTotalstotalsForIngestJobs = new HashMap<>()

Detailed Description

Detects the type of a file based on signature (magic) values. Posts results to the blackboard.

Definition at line 48 of file

Member Function Documentation

static synchronized void org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.addToTotals ( long  jobId,
long  matchTimeInc 

Update the match time total and increment number of files processed for this ingest job.

jobIdThe ingest job identifier.
matchTimeIncAmount of time to add.

Definition at line 204 of file

void org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.createInterestingFileHit ( AbstractFile  file,
FileType  fileType 

Create an Interesting File hit using the specified file type rule.

fileThe file from which to generate an artifact.
fileTypeThe file type rule for categorizing the hit.

Definition at line 147 of file

References, org.sleuthkit.autopsy.casemodule.Case.getCurrentCase(), org.sleuthkit.autopsy.casemodule.Case.getServices(), and

FileType org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.detectUserDefinedFileType ( AbstractFile  file) throws CustomFileTypesManager.CustomFileTypesException

Determines whether or not a file matches a user-defined custom file type.

fileThe file to test.
The file type if a match is found; otherwise null.
CustomFileTypesExceptionIf there is an issue getting an instance of CustomFileTypesManager.

Definition at line 126 of file

static boolean org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.isMimeTypeDetectable ( String  mimeType)

Validate if a given mime type is in the detector's registry.

Use FileTypeDetector.mimeTypeIsDetectable(String mimeType) instead.
mimeTypeFull string of mime type, e.g. "text/html"
true if detectable

Definition at line 66 of file

References org.sleuthkit.autopsy.modules.filetypeid.FileTypeDetector.isDetectable().

ProcessResult org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.process ( AbstractFile  file)

Processes a file. Called between calls to startUp() and shutDown(). Will be called for each file in a data source.

fileThe file to analyze.
A result code indicating success or failure of the processing.

Attempt to detect the file type. Do it within an exception firewall, so that any issues with reading file content or complaints from tika do not take the module down.

Implements org.sleuthkit.autopsy.ingest.FileIngestModule.

Definition at line 94 of file

References org.sleuthkit.autopsy.ingest.IngestModule.ProcessResult.ERROR, org.sleuthkit.autopsy.modules.filetypeid.FileTypeDetector.getMIMEType(), and org.sleuthkit.autopsy.ingest.IngestModule.ProcessResult.OK.

void org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.shutDown ( )

Invoked by Autopsy when an ingest job is completed (either because the data has been analyzed or because the job was canceled - check IngestJobContext.fileIngestIsCancelled()), before the ingest module instance is discarded. The module should respond by doing things like releasing private resources, submitting final results, and posting a final ingest message.

If this is the instance of this module for this ingest job, post a summary message to the ingest messages box.

Implements org.sleuthkit.autopsy.ingest.FileIngestModule.

Definition at line 168 of file

References org.sleuthkit.autopsy.ingest.IngestMessage.createMessage(), org.sleuthkit.autopsy.ingest.IngestModuleReferenceCounter.decrementAndGet(), org.sleuthkit.autopsy.ingest.IngestServices.getInstance(), org.sleuthkit.autopsy.ingest.IngestMessage.MessageType.INFO, and org.sleuthkit.autopsy.ingest.IngestServices.postMessage().

void org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.startUp ( IngestJobContext  context) throws IngestModuleException

Invoked by Autopsy to allow an ingest module instance to set up any internal data structures and acquire any private resources it will need during an ingest job. If the module depends on loading any resources, it should do so in this method so that it can throw an exception in the case of an error and alert the user. Exceptions that are thrown from process() and shutDown() are logged, but do not stop processing of the data source.

contextProvides data and services specific to the ingest job and the ingest pipeline of which the module is a part.

Implements org.sleuthkit.autopsy.ingest.IngestModule.

Definition at line 83 of file

References org.sleuthkit.autopsy.ingest.IngestModuleReferenceCounter.incrementAndGet().

Member Data Documentation

FileTypeDetector org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.fileTypeDetector

Definition at line 54 of file

long org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.jobId

Definition at line 51 of file

final Logger org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.logger = Logger.getLogger(FileTypeIdIngestModule.class.getName())

Definition at line 50 of file

final IngestModuleReferenceCounter org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.refCounter = new IngestModuleReferenceCounter()

Definition at line 53 of file

final HashMap<Long, IngestJobTotals> org.sleuthkit.autopsy.modules.filetypeid.FileTypeIdIngestModule.totalsForIngestJobs = new HashMap<>()

Definition at line 52 of file

The documentation for this class was generated from the following file:

Copyright © 2012-2016 Basis Technology. Generated on: Tue Feb 20 2018
This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.