sleuthkit-users Mailing List for The Sleuth Kit (Page 2)
Brought to you by:
carrier
You can subscribe to this list here.
2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(6) |
Aug
|
Sep
(11) |
Oct
(5) |
Nov
(4) |
Dec
|
---|---|---|---|---|---|---|---|---|---|---|---|---|
2003 |
Jan
(1) |
Feb
(20) |
Mar
(60) |
Apr
(40) |
May
(24) |
Jun
(28) |
Jul
(18) |
Aug
(27) |
Sep
(6) |
Oct
(14) |
Nov
(15) |
Dec
(22) |
2004 |
Jan
(34) |
Feb
(13) |
Mar
(28) |
Apr
(23) |
May
(27) |
Jun
(26) |
Jul
(37) |
Aug
(19) |
Sep
(20) |
Oct
(39) |
Nov
(17) |
Dec
(9) |
2005 |
Jan
(45) |
Feb
(43) |
Mar
(66) |
Apr
(36) |
May
(19) |
Jun
(64) |
Jul
(10) |
Aug
(11) |
Sep
(35) |
Oct
(6) |
Nov
(4) |
Dec
(13) |
2006 |
Jan
(52) |
Feb
(34) |
Mar
(39) |
Apr
(39) |
May
(37) |
Jun
(15) |
Jul
(13) |
Aug
(48) |
Sep
(9) |
Oct
(10) |
Nov
(47) |
Dec
(13) |
2007 |
Jan
(25) |
Feb
(4) |
Mar
(2) |
Apr
(29) |
May
(11) |
Jun
(19) |
Jul
(13) |
Aug
(15) |
Sep
(30) |
Oct
(12) |
Nov
(10) |
Dec
(13) |
2008 |
Jan
(2) |
Feb
(54) |
Mar
(58) |
Apr
(43) |
May
(10) |
Jun
(27) |
Jul
(25) |
Aug
(27) |
Sep
(48) |
Oct
(69) |
Nov
(55) |
Dec
(43) |
2009 |
Jan
(26) |
Feb
(36) |
Mar
(28) |
Apr
(27) |
May
(55) |
Jun
(9) |
Jul
(19) |
Aug
(16) |
Sep
(15) |
Oct
(17) |
Nov
(70) |
Dec
(21) |
2010 |
Jan
(56) |
Feb
(59) |
Mar
(53) |
Apr
(32) |
May
(25) |
Jun
(31) |
Jul
(36) |
Aug
(11) |
Sep
(37) |
Oct
(19) |
Nov
(23) |
Dec
(6) |
2011 |
Jan
(21) |
Feb
(20) |
Mar
(30) |
Apr
(30) |
May
(74) |
Jun
(50) |
Jul
(34) |
Aug
(34) |
Sep
(12) |
Oct
(33) |
Nov
(10) |
Dec
(8) |
2012 |
Jan
(23) |
Feb
(57) |
Mar
(26) |
Apr
(14) |
May
(27) |
Jun
(27) |
Jul
(60) |
Aug
(88) |
Sep
(13) |
Oct
(36) |
Nov
(97) |
Dec
(85) |
2013 |
Jan
(60) |
Feb
(24) |
Mar
(43) |
Apr
(32) |
May
(22) |
Jun
(38) |
Jul
(51) |
Aug
(50) |
Sep
(76) |
Oct
(65) |
Nov
(25) |
Dec
(30) |
2014 |
Jan
(19) |
Feb
(41) |
Mar
(43) |
Apr
(28) |
May
(61) |
Jun
(12) |
Jul
(10) |
Aug
(37) |
Sep
(76) |
Oct
(31) |
Nov
(41) |
Dec
(12) |
2015 |
Jan
(33) |
Feb
(28) |
Mar
(53) |
Apr
(22) |
May
(29) |
Jun
(20) |
Jul
(15) |
Aug
(17) |
Sep
(52) |
Oct
(3) |
Nov
(18) |
Dec
(21) |
2016 |
Jan
(20) |
Feb
(8) |
Mar
(21) |
Apr
(7) |
May
(13) |
Jun
(35) |
Jul
(34) |
Aug
(11) |
Sep
(14) |
Oct
(22) |
Nov
(31) |
Dec
(23) |
2017 |
Jan
(20) |
Feb
(7) |
Mar
(5) |
Apr
(6) |
May
(6) |
Jun
(22) |
Jul
(11) |
Aug
(16) |
Sep
(8) |
Oct
(1) |
Nov
(1) |
Dec
(1) |
2018 |
Jan
|
Feb
|
Mar
(16) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(4) |
Oct
|
Nov
(16) |
Dec
(13) |
2019 |
Jan
|
Feb
(1) |
Mar
(25) |
Apr
(9) |
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2020 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
(1) |
Jun
(3) |
Jul
(2) |
Aug
|
Sep
|
Oct
(5) |
Nov
|
Dec
|
2021 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
2022 |
Jan
|
Feb
(2) |
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2023 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
2024 |
Jan
|
Feb
(3) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2025 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: <mas...@cy...> - 2020-10-30 08:22:53
|
Dear, you can use FTK Imager (free download from accessdata.com) to convert E01 in DD Bests from Italy MGX -- Massimiliano Graziani | Founder and CEO CYBERA SRL mas...@cy... -- IICFIP Certified Forensic Investigation Professional (CFIP) ACFE Certified Fraud Examiner (CFE) IISFA Certified Information Forensics Investigator (CIFI) ISECOM Osstmm Professional Security Analyst (OPSA) AccessData Certified Examiner (ACE) IICFIP Certified Digital Forensics Professional (CDFP) Bsi Lead Auditor BS7799-2:2002 (ISO 27001:2013) Tenable Certified Nessus User (TCNU) -- Member of: ACFE IISFA ISECOM OWASP CLUSIT IICFIP ONIF WREP - Web Reporters European Press tessera 9100 -- https://www.cybera.it it.linkedin.com/in/mgraziani -- +39 333 4180077 -- From: "Nilesh Pawar via sleuthkit-users" sle...@li... To: sle...@li... Cc: Date: Fri, 30 Oct 2020 12:19:23 +0530 (IST) Subject: [sleuthkit-users] E01 Image not uploading in Autopsy software. Dear Sir/Madam, Iam install autopsy software in my workstation to analyzing the data for forensic report but autopsy software not working properly, E01 image not uploaded on the system. sir please help me solve this issue. Thanks and regards Nilesh Pawar CCPA Cell Pune |
From: Nilesh P. <nil...@go...> - 2020-10-30 07:11:40
|
Dear Sir/Madam, Iam install autopsy software in my workstation to analyzing the data for forensic report but autopsy software not working properly, E01 image not uploaded on the system. sir please help me solve this issue. Thanks and regards Nilesh Pawar CCPA Cell Pune |
From: Jose M. S. <jm...@ho...> - 2020-07-21 15:43:08
|
Hi team, I've been struggling for days looking for the way of get results for many expressions like Kel* AND Kapl* Kell* AND kk...@do... I've been totally unable to translate them to regex in a way to get the expected results... Any help? |
From: 김형찬 <hj1...@aj...> - 2020-07-15 08:03:38
|
I am a researcher at ICS Lab, Ajou University in South Korea. I'm publishing papers with dfrws for forensic research for 2019 and 2020 and I'm interested in using tsk. I am currently testing APFS, and I have a question on how to create a pool type image. I tried to create an APFS file system using two methods and then create an image using the dd command. The first method is to create a partition using macOS's basic disk utility, add a volume to the partition, and then use the dd command. The second method used the dd command after creating the volume using macOS' basic disk utility. However, these methods output an error message that the file system type error cannot be determined. I want to see how to create a pool type image to test TSK-APFS. I am waiting for answer. |
From: Derrick K. <dk...@gm...> - 2020-06-24 17:05:34
|
Hi Ben. It seems like you are still missing the Sleuth Kit Java Bindings (JNI) or that Autopsy can't find them. Did you need to adjust PKGBUILD as well? https://github.com/sleuthkit/autopsy/issues/3829 Derrick On Tue, Jun 23, 2020 at 1:46 PM Findlay, Benjamin <B.F...@te...> wrote: > Update and some additional information…I tried a rebuild from scratch so I > could copy all of the text of the error messages (after the first time one > appeared, it didn’t come up again): > > > > When running the bin/autopsy command to launch Autopsy for the first time, > I get these messages in Terminal: > > > > user@host:~/autopsy/autopsy-4.15.0 $ bin/autopsy > > Library not found in jar (libtsk_jni) > > SleuthkitJNI: failed to load libtsk_jni > > > > Then a dialog box appears in the GUI, with the following error: > > > > org.netbeans.InvalidException: StandardModule:org.sleuthkit.autopsy.core > jarFile: > /home/pi/autopsy/autopsy-4.15.0/autopsy/modules/org-sleuthkit-autopsy-core.jar: > java.lang.UnsatisfiedLinkError: > org.sleuthkit.datamodel.SleuthkitJNI.getVersionNat()Ljava/lang/String; > > > > This gives me the option to “Disable Modules and Continue” or “Exit” > > > > Anyone have any ideas? > > > > Thanks, > > > > Ben > > > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |
From: Findlay, B. <B.F...@te...> - 2020-06-23 19:45:10
|
Update and some additional information…I tried a rebuild from scratch so I could copy all of the text of the error messages (after the first time one appeared, it didn’t come up again): When running the bin/autopsy command to launch Autopsy for the first time, I get these messages in Terminal: user@host:~/autopsy/autopsy-4.15.0 $ bin/autopsy Library not found in jar (libtsk_jni) SleuthkitJNI: failed to load libtsk_jni Then a dialog box appears in the GUI, with the following error: org.netbeans.InvalidException: StandardModule:org.sleuthkit.autopsy.core jarFile: /home/pi/autopsy/autopsy-4.15.0/autopsy/modules/org-sleuthkit-autopsy-core.jar: java.lang.UnsatisfiedLinkError: org.sleuthkit.datamodel.SleuthkitJNI.getVersionNat()Ljava/lang/String; This gives me the option to “Disable Modules and Continue” or “Exit” Anyone have any ideas? Thanks, Ben |
From: Findlay, B. <B.F...@te...> - 2020-06-22 16:21:45
|
Hi there, As a little project and as a test, I’m looking to build Autopsy on ARM64 architecture, with a view to creating a portable low-powered device for triage use at scene. I’ve been using the Linux instructions but have hit an issue with the bellsoft Java and sleuthkit java bindings (I think)... there is no bellsoft-java8-full package for ARM. Is there an alternative to this package at all? I’ve managed to get Autopsy built, but it won’t open properly (I assume because of the use of the bellsoft-java8 package and not the FULL one). The autopsy-core plugin won’t activate and the screen in pretty much blank. Thanks, Ben www.tees.ac.uk<http://www.tees.ac.uk/> Ben Findlay BSc (Hons) MSc PgCLTHE FHEA MBCS MCSFS MIScT MCIIS Course Leader Computer and Digital Forensics T: 01642 384668<tel:01642%20384668> School of Health & Life Sciences |
From: CiberSeguridad UK <sch...@gm...> - 2020-05-26 14:59:07
|
New Journal: Journal of Cyber Forensics and Advanced Threat Investigations Dear Cybersecurity Researcher, Red || Yellow || Blue Practitioner, The Journal of Cyber Forensics and Advanced Threat Investigations is an international open-access journal that publishes original research, practical and review articles related to all areas of cybersecurity, digital forensics, incident response, and threat investigations. The scope includes the measures that governments or organization should follow to protect the online information & critical infrastructure, the impacts of cyber-crime & cyber-attacks in organizations and/or individuals, malware/ransomware, analysis & reversing, hardware/software security testing, zero-day attacks & exploits, large-scale digital investigations, unconventional penetration testing tactics, techniques & tools, social engineering & human hacking, anti-forensics & anti-anti-forensics, identity theft & protection, relevant case studies in cybersecurity, digital forensics, incident response, & threat investigations, and proficient strategies for tackling the various types of cyber-attacks and cyber-crimes. The journal is pleased to welcome manuscript submissions from you. Please browse through the journal website to find out more information about the focus and scope of the journal and the author's guidelines. Journal Website: https://conceptechint.net/index.php/CFATI We welcome three kinds of submissions: * Research Articles, * Practical Articles, * Review Articles. All submissions will be rigorously peer-reviewed. For more details, see https://conceptechint.net/index.php/CFATI/index All accepted papers will be published under the Creative Commons CC-BY-NC. Each Accepted article will have a unique identifier and will be abstracted and indexed in 7 different international databases accessible for all academic and research communities of forensics to secure high visibility. The journal is open access to the world and does not charge authors publication fees or article processing fees. Contact All questions about submissions should be emailed to cf...@co... Sincerely, Editorial Office International Journal of Cyber Forensics and Advanced Threat Investigations |
From: Luís F. N. <lfc...@gm...> - 2020-03-27 20:24:27
|
Hello everyone! Is it safe to assume obj_id of tsk_files table in sqlite generated by tsk_loaddb don't change between different runs of tsk_loaddb when comparing the same artifacts? Thank you, Luis Nassif |
From: Ann P. <apr...@ba...> - 2020-01-30 12:47:04
|
On the command line you'll need to run pstat to get the block numbers of any APFS volumes. You're looking for the line " APSB Block Number". I'll paste in the full process below. $ ./mmls.exe apfs_one_vol.dmg GUID Partition Table (EFI) Offset Sector: 0 Units are in 512-byte sectors Slot Start End Length Description 000: Meta 0000000000 0000000000 0000000001 Safety Table 001: ------- 0000000000 0000000039 0000000040 Unallocated 002: Meta 0000000001 0000000001 0000000001 GPT Header 003: Meta 0000000002 0000000033 0000000032 Partition Table 004: 000 0000000040 0000097663 0000097624 disk image 005: ------- 0000097664 0000097696 0000000033 Unallocated $ ./pstat.exe -o 40 apfs_one_vol.dmg POOL CONTAINER INFORMATION -------------------------------------------- Container cb1365d5-76ab-4559-be83-77f389c254e2 ============================================== Type: APFS NX Block Number: 0 NX oid: 1 NX xid: 12 Checkpoint Descriptor Block: 7 Capacity Ceiling (Size): 49983488 B Capacity In Use: 1724416 B Capacity Available: 48259072 B Block Size: 4096 B Number of Blocks: 12203 Number of Free Blocks: 11782 | +-> Volume 8f8dda38-0894-49f6-a943-da1401ddd148 | =========================================== | APSB Block Number: 418 | APSB oid: 1026 | APSB xid: 12 | Name (Role): Test APFS 1 (No specific role) | Capacity Consumed: 737280 B | Capacity Reserved: None | Capacity Quota: None | Case Sensitive: No | Encrypted: No | Formatted by: newfs_apfs (945.260.7) | | Created: 2019-07-23 14:40:48.754498461 (ric) | Changed: 2019-07-23 14:44:42.771863706 (ric) | | Unmount Logs | ------------ | Timestamp Log String | 2019-07-23 14:44:42.848757968 (ric) apfs_kext (945.260.7) | | Root Files | ------------- | [ 23] file1.txt | [ 19] .DS_Store | [ 16] .fseventsd | [ 18] folder1 | +-> Unallocated Container Blocks | ============================ | 0x000001a5-0x00002faa $ ./fls.exe -o 40 -B 418 apfs_one_vol.dmg r/r 23: file1.txt r/r 19: .DS_Store d/d 16: .fseventsd d/d 18: folder1 On Thu, Jan 30, 2020 at 6:49 AM Jake Jackson 46059480 < Jak...@ke...> wrote: > Good afternoon, > > > > I am currently trying to use the Sleuthkit to be able to open .E01 files > containing APFS images and extracting certain files. In order to do this I > need to be able to calculate the starting APSB block of the volume in > question. When I load the image into Autopsy the number is automatically > determined, how is this done in Sleuthkit? > > > > Kind regards, > > > > Jake Jackson > This email and any other accompanying document(s) contain information from > Kent Police and/or Essex Police, which is confidential or privileged. The > information is intended to be for the exclusive use of the individual(s) or > bodies to whom it is addressed. The content, including any subsequent > replies, could be disclosable if relating to a criminal investigation or > civil proceedings. If you are not the intended recipient, be aware that any > disclosure, copying, distribution or other use of the contents of this > information is prohibited. If you have received this email in error, please > notify us immediately by contacting the sender or telephoning Kent Police > on 01622 690690 or Essex Police on 01245 491491, as appropriate. For > further information regarding Kent Police’s or Essex Police’s use of > personal data please go to https://www.kent.police.uk/hyg/privacy/ or > https://www.essex.police.uk/hyg/privacy/. Additionally for our Terms and > Conditions please go to https://www.kent.police.uk/hyg/terms-conditions/ > or https://www.essex.police.uk/hyg/terms-conditions/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |
From: Jake J. 4. <Jak...@ke...> - 2020-01-30 11:44:45
|
Good afternoon, I am currently trying to use the Sleuthkit to be able to open .E01 files containing APFS images and extracting certain files. In order to do this I need to be able to calculate the starting APSB block of the volume in question. When I load the image into Autopsy the number is automatically determined, how is this done in Sleuthkit? Kind regards, Jake Jackson This email and any other accompanying document(s) contain information from Kent Police and/or Essex Police, which is confidential or privileged. The information is intended to be for the exclusive use of the individual(s) or bodies to whom it is addressed. The content, including any subsequent replies, could be disclosable if relating to a criminal investigation or civil proceedings. If you are not the intended recipient, be aware that any disclosure, copying, distribution or other use of the contents of this information is prohibited. If you have received this email in error, please notify us immediately by contacting the sender or telephoning Kent Police on 01622 690690 or Essex Police on 01245 491491, as appropriate. For further information regarding Kent Police's or Essex Police's use of personal data please go to https://www.kent.police.uk/hyg/privacy/ or https://www.essex.police.uk/hyg/privacy/. Additionally for our Terms and Conditions please go to https://www.kent.police.uk/hyg/terms-conditions/ or https://www.essex.police.uk/hyg/terms-conditions/ |
From: Brian C. <ca...@sl...> - 2019-07-30 18:31:44
|
We are going to start incorporating in some of the most popular 3rd Party Autopsy modules. But, first we need to know which are the most popular. Please vote below for the modules you use most and we'll look into incorporating them. https://www.surveymonkey.com/r/QRTXDZ2 thanks, brian |
From: Brian C. <ca...@sl...> - 2019-06-25 18:23:08
|
One more day to vote for your favorite talks for OSDFCon: https://www.surveymonkey.com/r/osdfconvoting2019 <https://www.surveymonkey.com/r/osdfconvoting2019> OSDFCon will be held Oct 16 in Herndon, VA. The agenda is based on crowd sourced voting. brian |
From: Brian C. <ca...@sl...> - 2019-05-30 15:15:25
|
The CFP deadline is tomorrow for the 10th Annual Open Source Digital Forensics Conference (OSDFCon). The conference will be held on Oct 16, 2019. There are openings for: * 10-minute short talks * 35-minute in-person talks * 35-minute remote talks * 3-hour hands on workshops https://www.osdfcon.org/2019-event/2019-call-for-presentations/ Please submit your ideas about open source tools you've developed, used, or want to exist. The event is 1-day long with 400+ attendees. It's the biggest open source digital forensics event and the biggest DFIR event in the Metro DC region. All you need to submit is an abstract and then we'll crowd source the agenda. thanks, brian |
From: Nanni B. <dig...@gm...> - 2019-05-01 15:25:52
|
Hi all, I tried to re-ingest an old test-case for finding the new features of Autopsy 4.11, e.g. logon/logoff, but I got an error in recent activities ingesting: INFO: Writing Full RegRipper results to: D:\test\win8\ModuleOutput\RecentActivity\reg\SOFTWARE-regripper-198290-full.txt 2019-04-30 11:18:40.206 org.sleuthkit.autopsy.recentactivity.ExtractRegistry parseAutopsyPluginOutput WARNING: Failed to parse epoch time when parsing the registry. 2019-04-30 11:18:40.206 org.sleuthkit.autopsy.recentactivity.ExtractRegistry parseAutopsyPluginOutput SEVERE: RegRipper::Conversion on DateTime -> java.text.ParseException: Unparseable date: "Sat Dec 12 03:03:15 2015" java.text.DateFormat.parse(DateFormat.java:366) org.sleuthkit.autopsy.recentactivity.ExtractRegistry.parseAutopsyPluginOutput(ExtractRegistry.java:468) org.sleuthkit.autopsy.recentactivity.ExtractRegistry.analyzeRegistryFiles(ExtractRegistry.java:228) org.sleuthkit.autopsy.recentactivity.ExtractRegistry.process(ExtractRegistry.java:985) org.sleuthkit.autopsy.recentactivity.RAImageIngestModule.process(RAImageIngestModule.java:125) org.sleuthkit.autopsy.ingest.DataSourceIngestPipeline$PipelineModule.process(DataSourceIngestPipeline.java:206) org.sleuthkit.autopsy.ingest.DataSourceIngestPipeline.process(DataSourceIngestPipeline.java:113) org.sleuthkit.autopsy.ingest.DataSourceIngestJob.process(DataSourceIngestJob.java:743) org.sleuthkit.autopsy.ingest.DataSourceIngestTask.execute(DataSourceIngestTask.java:30) org.sleuthkit.autopsy.ingest.IngestManager$ExecuteIngestJobTasksTask.run(IngestManager.java:880) java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511) java.util.concurrent.FutureTask.run(FutureTask.java:266) java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) java.lang.Thread.run(Thread.java:748) 2019-04-30 11:18:40.251 org.sleuthkit.autopsy.recentactivity.ExtractRegistry parseAutopsyPluginOutput WARNING: Failed to parse epoch time for installed program artifact. 2019-04-30 11:18:40.251 org.sleuthkit.autopsy.recentactivity.RAImageIngestModule process SEVERE: Exception occurred in Registry java.lang.NullPointerException org.sleuthkit.autopsy.recentactivity.ExtractRegistry.parseAutopsyPluginOutput(ExtractRegistry.java:662) org.sleuthkit.autopsy.recentactivity.ExtractRegistry.analyzeRegistryFiles(ExtractRegistry.java:228) org.sleuthkit.autopsy.recentactivity.ExtractRegistry.process(ExtractRegistry.java:985) org.sleuthkit.autopsy.recentactivity.RAImageIngestModule.process(RAImageIngestModule.java:125) org.sleuthkit.autopsy.ingest.DataSourceIngestPipeline$PipelineModule.process(DataSourceIngestPipeline.java:206) org.sleuthkit.autopsy.ingest.DataSourceIngestPipeline.process(DataSourceIngestPipeline.java:113) org.sleuthkit.autopsy.ingest.DataSourceIngestJob.process(DataSourceIngestJob.java:743) org.sleuthkit.autopsy.ingest.DataSourceIngestTask.execute(DataSourceIngestTask.java:30) org.sleuthkit.autopsy.ingest.IngestManager$ExecuteIngestJobTasksTask.run(IngestManager.java:880) java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511) java.util.concurrent.FutureTask.run(FutureTask.java:266) java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) java.lang.Thread.run(Thread.java:748) -- Dott. Nanni Bassetti http://www.nannibassetti.com CAINE project manager - http://www.caine-live.net |
From: Brian C. <ca...@sl...> - 2019-04-29 19:52:56
|
You need to get an AbstractFile <https://github.com/sleuthkit/sleuthkit/blob/develop/bindings/java/src/org/sleuthkit/datamodel/AbstractFile.java> and then call getMd5Hash() and getMIMEType(). You can get them from FileManager. You might want to review the code in the Tagged Hash Report Module <https://github.com/sleuthkit/autopsy/blob/develop/Core/src/org/sleuthkit/autopsy/report/taggedhashes/AddTaggedHashesToHashDb.java> . On Fri, Apr 26, 2019 at 4:37 PM grzegorz.ginalski <grz...@o2...> wrote: > I am trying to write report module on python. How to get hash value and > mime type of tagged files ? > > Regards > Grzegorz > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |
From: grzegorz.ginalski <grz...@o2...> - 2019-04-26 20:37:27
|
I am trying to write report module on python. How to get hash value and mime type of tagged files ? Regards Grzegorz |
From: Brian C. <ca...@sl...> - 2019-04-23 03:33:08
|
I setup the new Discourse forum: https://sleuthkit.discourse.group/ I'll shutdown the existing forum.sleuthkit.org site. Thanks Discourse! |
From: Daniel O. <dan...@gm...> - 2019-04-22 14:41:27
|
Great News! Em seg, 22 de abr de 2019 às 10:31, Brian Carrier <ca...@sl...> escreveu: > To follow up on this, discourse created a forum for us. I need to finish > setting it up. > > thanks, > brian > > > On Sun, Mar 31, 2019 at 10:13 PM Brian Carrier <ca...@sl...> > wrote: > >> Thanks for all of the offers. I submitted a request for a free account >> on discourse.org. We'll see if they give us one. >> >> On Thu, Mar 28, 2019 at 8:11 AM Daniel Oliveira <dan...@gm...> >> wrote: >> >>> Hey Brian, >>> >>> i im up for helping moderate the forum, take a look at >>> https://www.discourse.org/ it's really good. >>> >>> Em qui, 28 de mar de 2019 às 06:33, Patrick Rary - Mazal.biz < >>> in...@ma...> escreveu: >>> >>>> Hi, >>>> >>>> If you need technical help on installing and maintaining a forum on >>>> your hosting, I’d like to help (much better than messy google groups) >>>> >>>> Bonne journée, >>>> Patrick Rary >>>> >>>> Le 28 mars 2019 à 08:45, Søren Berggreen <shb...@gm...> a >>>> écrit : >>>> >>>> Sure, I'd like to help. >>>> >>>> Best regards >>>> Soren Berggreen >>>> >>>> >>>> On Thu, Mar 28, 2019 at 4:24 AM Brian Carrier <ca...@sl...> >>>> wrote: >>>> >>>>> Hello, >>>>> >>>>> As many may know, forum.sleuthkit.org has not really been working for >>>>> a while. I'd like to do a test and setup a Q&A forum on Google Groups. >>>>> It's kind of like Stack Overflow and allows people to submit answers to >>>>> questions and vote on them so that the best answer is at the top. >>>>> >>>>> But, I need help. I am terrible at checking forums and would like some >>>>> volunteers who can serve as moderators on the group to make sure new >>>>> members are not sending SPAM and things are kept orderly. >>>>> >>>>> If you'd like to help out with that, let me know and I'll set you up. >>>>> >>>>> thanks, >>>>> brian >>>>> >>>>> _______________________________________________ >>>>> sleuthkit-users mailing list >>>>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>>>> http://www.sleuthkit.org >>>>> >>>> _______________________________________________ >>>> sleuthkit-users mailing list >>>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>>> http://www.sleuthkit.org >>>> >>>> _______________________________________________ >>>> sleuthkit-users mailing list >>>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>>> http://www.sleuthkit.org >>>> >>> >>> >>> -- >>> Daniel Oliveira >>> >> -- Daniel Oliveira |
From: Brian C. <ca...@sl...> - 2019-04-22 13:31:45
|
To follow up on this, discourse created a forum for us. I need to finish setting it up. thanks, brian On Sun, Mar 31, 2019 at 10:13 PM Brian Carrier <ca...@sl...> wrote: > Thanks for all of the offers. I submitted a request for a free account on > discourse.org. We'll see if they give us one. > > On Thu, Mar 28, 2019 at 8:11 AM Daniel Oliveira <dan...@gm...> > wrote: > >> Hey Brian, >> >> i im up for helping moderate the forum, take a look at >> https://www.discourse.org/ it's really good. >> >> Em qui, 28 de mar de 2019 às 06:33, Patrick Rary - Mazal.biz < >> in...@ma...> escreveu: >> >>> Hi, >>> >>> If you need technical help on installing and maintaining a forum on your >>> hosting, I’d like to help (much better than messy google groups) >>> >>> Bonne journée, >>> Patrick Rary >>> >>> Le 28 mars 2019 à 08:45, Søren Berggreen <shb...@gm...> a écrit : >>> >>> Sure, I'd like to help. >>> >>> Best regards >>> Soren Berggreen >>> >>> >>> On Thu, Mar 28, 2019 at 4:24 AM Brian Carrier <ca...@sl...> >>> wrote: >>> >>>> Hello, >>>> >>>> As many may know, forum.sleuthkit.org has not really been working for >>>> a while. I'd like to do a test and setup a Q&A forum on Google Groups. >>>> It's kind of like Stack Overflow and allows people to submit answers to >>>> questions and vote on them so that the best answer is at the top. >>>> >>>> But, I need help. I am terrible at checking forums and would like some >>>> volunteers who can serve as moderators on the group to make sure new >>>> members are not sending SPAM and things are kept orderly. >>>> >>>> If you'd like to help out with that, let me know and I'll set you up. >>>> >>>> thanks, >>>> brian >>>> >>>> _______________________________________________ >>>> sleuthkit-users mailing list >>>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>>> http://www.sleuthkit.org >>>> >>> _______________________________________________ >>> sleuthkit-users mailing list >>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>> http://www.sleuthkit.org >>> >>> _______________________________________________ >>> sleuthkit-users mailing list >>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>> http://www.sleuthkit.org >>> >> >> >> -- >> Daniel Oliveira >> > |
From: Lorna M. <lo...@d4...> - 2019-04-08 10:20:49
|
Hi Brian, I had to restart the whole analysis as the program froze. Thanks anyway for your help. By any chance you wouldn’t perhaps know of a software that can help detect the actual type of a orphan file to be able to extract it and open it? Regards, Lorna From: Brian Carrier <ca...@sl...> Sent: 05 April 2019 19:23 To: Lorna Micallef <lo...@d4...> Cc: sle...@li... Subject: Re: [sleuthkit-users] analysis of image progress stopped Hi Lorna, Not sure if it is too late to help at this point, but there is an ingest snapshot feature that shows what files are being analyzed and by which modules? You can get to it from the "Help" menu (I think). If you could send a picture of that, it would be helpful. thanks, brian On Thu, Apr 4, 2019 at 11:27 AM Lorna Micallef <lo...@d4...<mailto:lo...@d4...>> wrote: Hi, I’m currently using Autopsy 4.10.0 to analyse an image and the progress bar during the analysis has stopped at 68%. Also the program has start to freeze between checking of current retrieved data. Any suggestions of what to do as stopping it will result in starting all over again and the analysis has been running for more than 48hrs now. Regards, Lorna _______________________________________________ sleuthkit-users mailing list https://lists.sourceforge.net/lists/listinfo/sleuthkit-users http://www.sleuthkit.org |
From: Brian C. <ca...@sl...> - 2019-04-05 17:23:21
|
Hi Lorna, Not sure if it is too late to help at this point, but there is an ingest snapshot feature that shows what files are being analyzed and by which modules? You can get to it from the "Help" menu (I think). If you could send a picture of that, it would be helpful. thanks, brian On Thu, Apr 4, 2019 at 11:27 AM Lorna Micallef <lo...@d4...> wrote: > Hi, > > > > I’m currently using Autopsy 4.10.0 to analyse an image and the progress > bar during the analysis has stopped at 68%. > > > > Also the program has start to freeze between checking of current retrieved > data. > > > > Any suggestions of what to do as stopping it will result in starting all > over again and the analysis has been running for more than 48hrs now. > > > > Regards, > > > > Lorna > > > > > > > > > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |
From: Lorna M. <lo...@d4...> - 2019-04-04 15:27:01
|
Hi, I'm currently using Autopsy 4.10.0 to analyse an image and the progress bar during the analysis has stopped at 68%. Also the program has start to freeze between checking of current retrieved data. Any suggestions of what to do as stopping it will result in starting all over again and the analysis has been running for more than 48hrs now. Regards, Lorna |
From: Brian C. <ca...@sl...> - 2019-04-01 02:13:37
|
Thanks for all of the offers. I submitted a request for a free account on discourse.org. We'll see if they give us one. On Thu, Mar 28, 2019 at 8:11 AM Daniel Oliveira <dan...@gm...> wrote: > Hey Brian, > > i im up for helping moderate the forum, take a look at > https://www.discourse.org/ it's really good. > > Em qui, 28 de mar de 2019 às 06:33, Patrick Rary - Mazal.biz < > in...@ma...> escreveu: > >> Hi, >> >> If you need technical help on installing and maintaining a forum on your >> hosting, I’d like to help (much better than messy google groups) >> >> Bonne journée, >> Patrick Rary >> >> Le 28 mars 2019 à 08:45, Søren Berggreen <shb...@gm...> a écrit : >> >> Sure, I'd like to help. >> >> Best regards >> Soren Berggreen >> >> >> On Thu, Mar 28, 2019 at 4:24 AM Brian Carrier <ca...@sl...> >> wrote: >> >>> Hello, >>> >>> As many may know, forum.sleuthkit.org has not really been working for a >>> while. I'd like to do a test and setup a Q&A forum on Google Groups. It's >>> kind of like Stack Overflow and allows people to submit answers to >>> questions and vote on them so that the best answer is at the top. >>> >>> But, I need help. I am terrible at checking forums and would like some >>> volunteers who can serve as moderators on the group to make sure new >>> members are not sending SPAM and things are kept orderly. >>> >>> If you'd like to help out with that, let me know and I'll set you up. >>> >>> thanks, >>> brian >>> >>> _______________________________________________ >>> sleuthkit-users mailing list >>> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >>> http://www.sleuthkit.org >>> >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org >> >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org >> > > > -- > Daniel Oliveira > |
From: Stephen P. <st...@go...> - 2019-03-30 11:38:39
|
I think you are correct, the notice I received from Google states Google + ends tomorrow including all groups and collections. I assumed that meant groups but the tag for groups still exists in the more menu and there is no warning on its page so Groups may be fine. V/r Stephen From: MBR <mb...@ar...> Sent: Saturday, March 30, 2019 4:11 AM To: Stephen Pearson <st...@go...>; Brian Carrier <ca...@sl...>; sleuthkit-users <sle...@li...> Subject: Re: [sleuthkit-users] Forum Moderators Are you sure it's Google Groups that's ending? I thought it was Google Plus that's ending, not Google Groups. Mark Rosenthal On 3/28/19 5:49 AM, Stephen Pearson wrote: Brian, Google groups will end soon. I would be happy to help where I can. V/r Stephen From: Brian Carrier <ca...@sl...><mailto:ca...@sl...> Sent: Wednesday, March 27, 2019 10:58 PM To: sleuthkit-users <sle...@li...><mailto:sle...@li...> Subject: [sleuthkit-users] Forum Moderators Hello, As many may know, forum.sleuthkit.org<http://forum.sleuthkit.org> has not really been working for a while. I'd like to do a test and setup a Q&A forum on Google Groups. It's kind of like Stack Overflow and allows people to submit answers to questions and vote on them so that the best answer is at the top. But, I need help. I am terrible at checking forums and would like some volunteers who can serve as moderators on the group to make sure new members are not sending SPAM and things are kept orderly. If you'd like to help out with that, let me know and I'll set you up. thanks, brian HTCI offers Training Software and Consultation. See all of our latest tools at http://www.gohtci.com , training.gohtci.com , dart.gohtci.com, and maplink.gohtci.com High Tech Crime Institute is a Verified Service Disabled Veteran Owned Small Business. We are of the Troops and still serving the Troops CONFIDENTIALITY NOTICE: This message contains confidential information and is intended only for this email's recipient. If you are not the named addressee, you should not disseminate, distribute or copy this e-mail. Please notify tec...@go...<mailto:tec...@go...> immediately by e-mail if you have received this e-mail by mistake, delete this e-mail from your system. E-mail transmission cannot be guaranteed to be secure or error-free as information could be intercepted, corrupted, lost, destroyed, arrive late or incomplete or contain viruses. High Tech Crime Institute Inc therefore does not accept liability for any errors or omissions in the contents of this message, which arise as a result of e-mail transmission. If verification is required please request a hard-copy version. High Tech Crime Institute Group Inc., 695 Alderman Road Palm Harbor, FL 34683 _______________________________________________ sleuthkit-users mailing list https://lists.sourceforge.net/lists/listinfo/sleuthkit-users http://www.sleuthkit.org HTCI offers Training Software and Consultation. See all of our latest tools at http://www.gohtci.com , training.gohtci.com , dart.gohtci.com, and maplink.gohtci.com High Tech Crime Institute is a Verified Service Disabled Veteran Owned Small Business. We are of the Troops and still serving the Troops CONFIDENTIALITY NOTICE: This message contains confidential information and is intended only for this email's recipient. If you are not the named addressee, you should not disseminate, distribute or copy this e-mail. Please notify tec...@go... immediately by e-mail if you have received this e-mail by mistake, delete this e-mail from your system. E-mail transmission cannot be guaranteed to be secure or error-free as information could be intercepted, corrupted, lost, destroyed, arrive late or incomplete or contain viruses. High Tech Crime Institute Inc therefore does not accept liability for any errors or omissions in the contents of this message, which arise as a result of e-mail transmission. If verification is required please request a hard-copy version. High Tech Crime Institute Group Inc., 695 Alderman Road Palm Harbor, FL 34683 |