sleuthkit-users Mailing List for The Sleuth Kit (Page 40)
Brought to you by:
carrier
You can subscribe to this list here.
2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(6) |
Aug
|
Sep
(11) |
Oct
(5) |
Nov
(4) |
Dec
|
---|---|---|---|---|---|---|---|---|---|---|---|---|
2003 |
Jan
(1) |
Feb
(20) |
Mar
(60) |
Apr
(40) |
May
(24) |
Jun
(28) |
Jul
(18) |
Aug
(27) |
Sep
(6) |
Oct
(14) |
Nov
(15) |
Dec
(22) |
2004 |
Jan
(34) |
Feb
(13) |
Mar
(28) |
Apr
(23) |
May
(27) |
Jun
(26) |
Jul
(37) |
Aug
(19) |
Sep
(20) |
Oct
(39) |
Nov
(17) |
Dec
(9) |
2005 |
Jan
(45) |
Feb
(43) |
Mar
(66) |
Apr
(36) |
May
(19) |
Jun
(64) |
Jul
(10) |
Aug
(11) |
Sep
(35) |
Oct
(6) |
Nov
(4) |
Dec
(13) |
2006 |
Jan
(52) |
Feb
(34) |
Mar
(39) |
Apr
(39) |
May
(37) |
Jun
(15) |
Jul
(13) |
Aug
(48) |
Sep
(9) |
Oct
(10) |
Nov
(47) |
Dec
(13) |
2007 |
Jan
(25) |
Feb
(4) |
Mar
(2) |
Apr
(29) |
May
(11) |
Jun
(19) |
Jul
(13) |
Aug
(15) |
Sep
(30) |
Oct
(12) |
Nov
(10) |
Dec
(13) |
2008 |
Jan
(2) |
Feb
(54) |
Mar
(58) |
Apr
(43) |
May
(10) |
Jun
(27) |
Jul
(25) |
Aug
(27) |
Sep
(48) |
Oct
(69) |
Nov
(55) |
Dec
(43) |
2009 |
Jan
(26) |
Feb
(36) |
Mar
(28) |
Apr
(27) |
May
(55) |
Jun
(9) |
Jul
(19) |
Aug
(16) |
Sep
(15) |
Oct
(17) |
Nov
(70) |
Dec
(21) |
2010 |
Jan
(56) |
Feb
(59) |
Mar
(53) |
Apr
(32) |
May
(25) |
Jun
(31) |
Jul
(36) |
Aug
(11) |
Sep
(37) |
Oct
(19) |
Nov
(23) |
Dec
(6) |
2011 |
Jan
(21) |
Feb
(20) |
Mar
(30) |
Apr
(30) |
May
(74) |
Jun
(50) |
Jul
(34) |
Aug
(34) |
Sep
(12) |
Oct
(33) |
Nov
(10) |
Dec
(8) |
2012 |
Jan
(23) |
Feb
(57) |
Mar
(26) |
Apr
(14) |
May
(27) |
Jun
(27) |
Jul
(60) |
Aug
(88) |
Sep
(13) |
Oct
(36) |
Nov
(97) |
Dec
(85) |
2013 |
Jan
(60) |
Feb
(24) |
Mar
(43) |
Apr
(32) |
May
(22) |
Jun
(38) |
Jul
(51) |
Aug
(50) |
Sep
(76) |
Oct
(65) |
Nov
(25) |
Dec
(30) |
2014 |
Jan
(19) |
Feb
(41) |
Mar
(43) |
Apr
(28) |
May
(61) |
Jun
(12) |
Jul
(10) |
Aug
(37) |
Sep
(76) |
Oct
(31) |
Nov
(41) |
Dec
(12) |
2015 |
Jan
(33) |
Feb
(28) |
Mar
(53) |
Apr
(22) |
May
(29) |
Jun
(20) |
Jul
(15) |
Aug
(17) |
Sep
(52) |
Oct
(3) |
Nov
(18) |
Dec
(21) |
2016 |
Jan
(20) |
Feb
(8) |
Mar
(21) |
Apr
(7) |
May
(13) |
Jun
(35) |
Jul
(34) |
Aug
(11) |
Sep
(14) |
Oct
(22) |
Nov
(31) |
Dec
(23) |
2017 |
Jan
(20) |
Feb
(7) |
Mar
(5) |
Apr
(6) |
May
(6) |
Jun
(22) |
Jul
(11) |
Aug
(16) |
Sep
(8) |
Oct
(1) |
Nov
(1) |
Dec
(1) |
2018 |
Jan
|
Feb
|
Mar
(16) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(4) |
Oct
|
Nov
(16) |
Dec
(13) |
2019 |
Jan
|
Feb
(1) |
Mar
(25) |
Apr
(9) |
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2020 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
(1) |
Jun
(3) |
Jul
(2) |
Aug
|
Sep
|
Oct
(5) |
Nov
|
Dec
|
2021 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
2022 |
Jan
|
Feb
(2) |
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2023 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
2024 |
Jan
|
Feb
(3) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2025 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: Jason L. <jle...@ba...> - 2014-08-13 20:14:14
|
I just re-read your email and you are looking for the list. I would suggest tagging the files instead of extracting them, then you can make a report just with that tag Jason ------------------------------------------------ Jason Letourneau Product Manager, Digital Forensics Basis Technology jle...@ba... 617-386-2000 ext. 152 On Aug 13, 2014, at 4:06 PM, Jason Letourneau <jle...@ba...> wrote: > Hi Anthony - > > You can drill down to the day in question in the timeline, select all of the files that appear in the lower left panel (shift + click with the mouse), right-click and select extract files > > Jason > > > > > > > ------------------------------------------------ > > Jason Letourneau > Product Manager, Digital Forensics > Basis Technology > jle...@ba... > 617-386-2000 ext. 152 > > > > > On Aug 13, 2014, at 1:14 PM, anthony snow <ant...@gm...> wrote: > >> Good morning, >> >> I’m using 3.1 and understand the timeline functionality is in beta but is there a way to export the list of files from a particular day? >> >> >> Thank you >> ------------------------------------------------------------------------------ >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org > |
From: anthony s. <ant...@gm...> - 2014-08-13 17:14:51
|
Good morning, I’m using 3.1 and understand the timeline functionality is in beta but is there a way to export the list of files from a particular day? Thank you |
From: STEPHEN M. (PHL) <Ste...@us...> - 2014-08-09 15:33:34
|
Having a hard time reading the Reg Ripper results - anyone have a best practice? Specifically looking for malware delivery methods... Thanks, Stephen Morrow Special Agent United States Secret Service Philadelphia Field Office 215-510-2629 215-861-3300 All e-mail to/from this account is subject to official review and is for official use only. Action may be taken in response to any inappropriate use of the Secret Service's e-mail system. This e-mail may contain information that is privileged, law enforcement sensitive, or subject to other disclosure limitations. Such information is loaned to you and should not be further disseminated without the permission of the Secret Service. If you have received this e-mail in error, do not keep, use, disclose, or copy it; notify the sender immediately and delete it. |
From: Brian C. <ca...@sl...> - 2014-08-08 19:15:27
|
[This message is targeted at students of digital forensics courses and teachers. If you aren't one of them, you can stop reading.] Basis Technology is again sponsoring a challenge for students to write Autopsy modules as part of their course work and projects. At the end of the semester, the winners will get cash prizes. The requirements are fairly simple and you essentially need to be a student and release a forensics-related module as open source. Full details can be found here: http://www.basistech.com/digital-forensics/autopsy/autopsy-for-educators/student-development-contest/ We expect that Python support will be released in September, which may enable more students to get involved. The benefit of writing Autopsy modules is that it handles lots of the data processing for you. It deals with disk images, logical files, etc. and the student can then focus on things like parsing file formats and detecting steg. Note that this is different from the module writing challenge associated with OSDFCon, which is not limited to student involvement (and has bigger prizes). http://www.basistech.com/osdfcon-contest/ brian |
From: Jason L. <jle...@ba...> - 2014-08-08 13:54:18
|
Hi Joachim - The 3.1 beta has some API changes that makes the current release versions of those modules incompatible with the new 3.1 release. The Video Triage module will be updated when the final 3.1 release is available so that it is compatible, but other module developers will need to update their modules as well. Jason ------------------------------------------------ Jason Letourneau Product Manager, Digital Forensics Basis Technology jle...@ba... 617-386-2000 ext. 152 On Aug 8, 2014, at 8:05 AM, HADER Consulting <in...@ha...> wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Hi there, > I have a problem with following third-party-products: > > com-williballenthin-autopsy-wrim-3.0.7-20131001.nbm > com-williballenthin-autopsy-wrcv-3.0.7-20131001.nbm > > When trying to insert the two files as ingest modules the files are > not recognized and there is no display for installation. > > In addition I tried to install video triage. It is recognized, but > there is an error message: > > Some plugins require plugin Autopsy-Core to be installed. > The plugin Autopsy-Core is requested in version >= 7.0 (release > version 9) but only 10.0.11 (of release version different from 9) was > found. The following plugin is affected: Video Triage > > My Autospy-Version: > Product Version: Autopsy 3.1.0_Beta2 (DEVELOPMENT) Sleuth Kit Version: > 4.1.3 Netbeans RCP Build: 201306052037 Java: 1.8.0_05; Java > HotSpot(TM) Client VM 25.5-b02 System: Windows XP version 5.1 running > on x86; Cp1252; de_DE (autopsy) > > Thanks for help > Joachim > - -- > HADER Consulting > Dipl. Ing. (FH) Joachim A. Hader > Sachverständiger für EDV und Digitale Forensik > Externer Datenschutzbeauftragter und Datenschutzberater > > Moststraße 7 | 91799 Langenaltheim | Tel: 0151 53872750 > Email: in...@ha... |WWW: http://www.hader-consulting.de > > Vertraulichkeit, Neutralität, Objektivität sind mein oberstes Gebot > > Mitglied der Gesellschaft für Datenschutz und Datensicherheit e.V. > Mitglied des Verbands Europäischer Gutachter und Sachverständiger e.V. > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1 > > iQEcBAEBAgAGBQJT5L0XAAoJEBkXzuy9JFgmRawH/AmFGVy6368IuHznDC5t6bCA > Iwd0LwNc6NwISCf/j7asje0a0jtxodw+BCZetPFK8CTnmFQ3gDLFkY3iRt5H4tqd > VkrHAmq4ky88q3esuePJyjlHXtPHmhL3YmSnziZFmCdUB60wnsq7RU8QSzmzEu1U > zNf+A+LiEweNXFVLay6BFTGOVfpJlVBIpJRfqTz5v/qSv/NZkRRfTJpclnc3k0KE > WnMTptqy6e6w98Ht1E5BO/v0GTaub93MJs/HKcMpzDModezfpA9r9/vgRHEEP3v6 > 8QVkGbRo1DC10p7BUcCugMrfHm+Ux2rE3QK7ucCFihpP7u8PYgnZfm0lcjbLQbI= > =GmH3 > -----END PGP SIGNATURE----- > > ------------------------------------------------------------------------------ > Want fast and easy access to all the code in your enterprise? Index and > search up to 200,000 lines of code with a free copy of Black Duck > Code Sight - the same software that powers the world's largest code > search on Ohloh, the Black Duck Open Hub! Try it now. > http://p.sf.net/sfu/bds > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Brian C. <ca...@sl...> - 2014-08-08 13:50:22
|
Hi Joachim, That archaic error message is because the modules do not work with Autopsy 3.1. We (Basis) will be releasing a new video triage module when Autopsy 3.1.0 is officially released (next week). I wish the error message was more clear. It comes from the framework that we use. When we do major updates from 3.0 to 3.1, there will likely be internal API changes and new releases of the modules will be needed. thanks, brian On Aug 8, 2014, at 8:05 AM, HADER Consulting <in...@ha...> wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Hi there, > I have a problem with following third-party-products: > > com-williballenthin-autopsy-wrim-3.0.7-20131001.nbm > com-williballenthin-autopsy-wrcv-3.0.7-20131001.nbm > > When trying to insert the two files as ingest modules the files are > not recognized and there is no display for installation. > > In addition I tried to install video triage. It is recognized, but > there is an error message: > > Some plugins require plugin Autopsy-Core to be installed. > The plugin Autopsy-Core is requested in version >= 7.0 (release > version 9) but only 10.0.11 (of release version different from 9) was > found. The following plugin is affected: Video Triage > > My Autospy-Version: > Product Version: Autopsy 3.1.0_Beta2 (DEVELOPMENT) Sleuth Kit Version: > 4.1.3 Netbeans RCP Build: 201306052037 Java: 1.8.0_05; Java > HotSpot(TM) Client VM 25.5-b02 System: Windows XP version 5.1 running > on x86; Cp1252; de_DE (autopsy) > > Thanks for help > Joachim > - -- > HADER Consulting > Dipl. Ing. (FH) Joachim A. Hader > Sachverständiger für EDV und Digitale Forensik > Externer Datenschutzbeauftragter und Datenschutzberater > > Moststraße 7 | 91799 Langenaltheim | Tel: 0151 53872750 > Email: in...@ha... |WWW: http://www.hader-consulting.de > > Vertraulichkeit, Neutralität, Objektivität sind mein oberstes Gebot > > Mitglied der Gesellschaft für Datenschutz und Datensicherheit e.V. > Mitglied des Verbands Europäischer Gutachter und Sachverständiger e.V. > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1 > > iQEcBAEBAgAGBQJT5L0XAAoJEBkXzuy9JFgmRawH/AmFGVy6368IuHznDC5t6bCA > Iwd0LwNc6NwISCf/j7asje0a0jtxodw+BCZetPFK8CTnmFQ3gDLFkY3iRt5H4tqd > VkrHAmq4ky88q3esuePJyjlHXtPHmhL3YmSnziZFmCdUB60wnsq7RU8QSzmzEu1U > zNf+A+LiEweNXFVLay6BFTGOVfpJlVBIpJRfqTz5v/qSv/NZkRRfTJpclnc3k0KE > WnMTptqy6e6w98Ht1E5BO/v0GTaub93MJs/HKcMpzDModezfpA9r9/vgRHEEP3v6 > 8QVkGbRo1DC10p7BUcCugMrfHm+Ux2rE3QK7ucCFihpP7u8PYgnZfm0lcjbLQbI= > =GmH3 > -----END PGP SIGNATURE----- > > ------------------------------------------------------------------------------ > Want fast and easy access to all the code in your enterprise? Index and > search up to 200,000 lines of code with a free copy of Black Duck > Code Sight - the same software that powers the world's largest code > search on Ohloh, the Black Duck Open Hub! Try it now. > http://p.sf.net/sfu/bds > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: HADER C. <in...@ha...> - 2014-08-08 12:43:34
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi there, why are MD5 hashes of files not displayed in "Views", while they are displayed in "Data Source"? Thanks for help Joachim > My Autospy-Version: Product Version: Autopsy 3.1.0_Beta2 > (DEVELOPMENT) Sleuth Kit Version: 4.1.3 Netbeans RCP Build: > 201306052037 Java: 1.8.0_05; Java HotSpot(TM) Client VM 25.5-b02 > System: Windows XP version 5.1 running on x86; Cp1252; de_DE > (autopsy) HADER Consulting Dipl. Ing. (FH) Joachim A. Hader Sachverständiger für EDV und Digitale Forensik Externer Datenschutzbeauftragter und Datenschutzberater Moststraße 7 | 91799 Langenaltheim | Tel: 0151 53872750 Email: in...@ha... |WWW: http://www.hader-consulting.de Vertraulichkeit, Neutralität, Objektivität sind mein oberstes Gebot Mitglied der Gesellschaft für Datenschutz und Datensicherheit e.V. Mitglied des Verbands Europäischer Gutachter und Sachverständiger e.V. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQEcBAEBAgAGBQJT5MXuAAoJEBkXzuy9JFgmEjkH/3sodsw7mmGCBizC6M0bEcmw u9x0sBA64VGk4i+XZNnBJpMJ6B5p37hhk7RLak9ZnCuqn3dKmqOQZA+TOPGhJQh5 hpR7kSdg90yQ+Wi9rDdp4M88s6P/6W3Ocxy7RQafPgKkAKTCD7Qf2W5cdHW8nPL1 G/b/vbkf0QfS7+zKwfl8AWrrtoRel0hW5z/kyzfb3fSrlGPXjvGxW8BNPGc/JF87 555YKRl9s2ucMHGtR2wcNgsc1vGbtqFpTZFKZGLdaZumn+aoVFH+QxgJpT+KUs3e tm+2zB98DYiAjFDzJMUpH0HjuS0cuTNceoiHWg2Vb2crb7S0dmEDn0nCtyApEvc= =75f6 -----END PGP SIGNATURE----- |
From: HADER C. <in...@ha...> - 2014-08-08 12:18:56
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi there, I have a problem with following third-party-products: com-williballenthin-autopsy-wrim-3.0.7-20131001.nbm com-williballenthin-autopsy-wrcv-3.0.7-20131001.nbm When trying to insert the two files as ingest modules the files are not recognized and there is no display for installation. In addition I tried to install video triage. It is recognized, but there is an error message: Some plugins require plugin Autopsy-Core to be installed. The plugin Autopsy-Core is requested in version >= 7.0 (release version 9) but only 10.0.11 (of release version different from 9) was found. The following plugin is affected: Video Triage My Autospy-Version: Product Version: Autopsy 3.1.0_Beta2 (DEVELOPMENT) Sleuth Kit Version: 4.1.3 Netbeans RCP Build: 201306052037 Java: 1.8.0_05; Java HotSpot(TM) Client VM 25.5-b02 System: Windows XP version 5.1 running on x86; Cp1252; de_DE (autopsy) Thanks for help Joachim - -- HADER Consulting Dipl. Ing. (FH) Joachim A. Hader Sachverständiger für EDV und Digitale Forensik Externer Datenschutzbeauftragter und Datenschutzberater Moststraße 7 | 91799 Langenaltheim | Tel: 0151 53872750 Email: in...@ha... |WWW: http://www.hader-consulting.de Vertraulichkeit, Neutralität, Objektivität sind mein oberstes Gebot Mitglied der Gesellschaft für Datenschutz und Datensicherheit e.V. Mitglied des Verbands Europäischer Gutachter und Sachverständiger e.V. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQEcBAEBAgAGBQJT5L0XAAoJEBkXzuy9JFgmRawH/AmFGVy6368IuHznDC5t6bCA Iwd0LwNc6NwISCf/j7asje0a0jtxodw+BCZetPFK8CTnmFQ3gDLFkY3iRt5H4tqd VkrHAmq4ky88q3esuePJyjlHXtPHmhL3YmSnziZFmCdUB60wnsq7RU8QSzmzEu1U zNf+A+LiEweNXFVLay6BFTGOVfpJlVBIpJRfqTz5v/qSv/NZkRRfTJpclnc3k0KE WnMTptqy6e6w98Ht1E5BO/v0GTaub93MJs/HKcMpzDModezfpA9r9/vgRHEEP3v6 8QVkGbRo1DC10p7BUcCugMrfHm+Ux2rE3QK7ucCFihpP7u8PYgnZfm0lcjbLQbI= =GmH3 -----END PGP SIGNATURE----- |
From: Brian C. <ca...@sl...> - 2014-08-04 17:19:32
|
We've been talking about giving Hash the Hound a face lift for Autopsy and updating him because he hasn't changed in a LONG time. We solicited some ideas from 99designs.com and are looking for feedback. Here is what you can do to get your voice heard: - Review https://99designs.com/logo-design/vote-ftqi1n - Mark the 'stars' on the submission accordingly. - If you want to keep the current hash then don't mark either with stars and add a comment of "Don't Change" to the first one. Please vote by end of day tomorrow (Tue). thanks, brian |
From: Brian C. <ca...@sl...> - 2014-07-30 21:31:24
|
As previously mentioned, the UI was less responsive with the 3.1.0 beta versus previous 3.0 releases. Richard found the problem and a new beta is available. Full disclosure: It was my fault. When I was fixing something in one area, I introduced the slowness in another area. Sorry. New beta is available here: http://sourceforge.net/projects/autopsy/files/autopsy/3.1.0%20Beta%202/ Nothing else major is in the release. brian |
From: <net...@ti...> - 2014-07-25 08:52:50
|
Hi, I am sorry for my newbbie question but when I start Ingest Modules I get duplicate entry of each module 2 entry of "Recent Activity" 2 entry of "hash lookup" 2 entry of "Archiver Extractor" and so on but only one is selected by default. is it correct to have double entry? how to choose one instead the other? Thanks Netexperss Scopri istella, il nuovo motore per il web italiano. Istella garantisce risultati di qualità e la possibilità di condividere, in modo semplice e veloce, documenti, immagini, audio e video. Usa istella, vai su http://www.istella.it?wtk=amc138614816829636 |
From: Eric H. <eri...@gm...> - 2014-07-22 12:57:51
|
Team, We have a position open out of our Jersey City, NJ office for a network investigator. The job announcement is posted below. This is a great opportunity to work with a growing high-performance team doing some very challenging work. I'm not the hiring manager, but this team is part of the larger team I work on. https://jpmchase.taleo.net/careersection/2/moresearch.ftl?lang=en&jobNumberSearch=130024673&location=1223 Eric Huber AFoD Blog www.ericjhuber.com http://www.linkedin.com/in/ericjhuber |
From: Luís F. N. <lfc...@gm...> - 2014-07-21 20:16:08
|
Hi, I would like to announce the MultiContentViewer Autopsy module. Information about the module below: MultiContentViewer 1.0-beta Site: https://github.com/lfcnassif/MultiContentViewer NBM: https://github.com/lfcnassif/MultiContentViewer/releases Minimum Autopsy version: 3.1 License: LGPL 3 Description: Data content viewer module for Autopsy 3.1. Enables the preview of dozens of file types: html, pdf, eml, emlx, rtf, doc, docx, xls, xlsx, ppt, pptx, odt, ods, odp, wps, wpd, sxw, eps, dbf, csv, tif, emf, wmf, odg, pcx, pbm, svg, pict, vsd, psd, cdr, dxf, and more. The module renders files based on signatures, if they were processed by File Type Identification module. Also enable navigating through keyword search hits into the rendered preview, improving the Autopsy keyword search feature. ATTENTION: It is strongly recomended to disable Internet connection before using this module, because currently it may access and download external server resources while rendering html files. Supported and tested on Windows and Linux machines. The module contains all necessary software and libraries to run on Windows. On Linux, you must have LibreOffice 4 installed to enable MultiContentViewer full file format support. Hope it will be useful! Regards, Luis Nassif |
From: Brian C. <ca...@sl...> - 2014-07-21 14:07:12
|
I wanted to send out a message to cover a few things that have come up offline as part of the 3.1 beta. 1) UI Responsiveness: We and others have noticed that the UI is much less responsive to points and clicks when the disk image is being ingested. The reason seems to be because we have more modules running in the background and they are fighting with the UI for access to the SQLite database. So, the UI has to wait until it gets access to the DB before it can display results. We're working on a solution to this and will have it fixed before the non-beta 3.1.0 release. 2) 3rd party modules that used to work with 3.0 will not work with 3.1. In general, this will always be the case. Major version upgrades (3.0 to 3.1) will likely always need a new version of the 3rd party modules. Modules should work during minor upgrades of 3.1.0 to 3.1.1. thanks, brian |
From: Brian C. <ca...@sl...> - 2014-07-15 20:41:59
|
Hi Luis, We still haven't gotten a chance to fix all of the memory leaks in scalpel, so it is still disabled and therefore not visible fin the ingest module list. The fact that you can still see it behind the scenes is because it is there, just hidden so that we can more easily test it when we try to fix the leaks. At some point, we may decide to simply write the unallocated space files to disk and carve them. In which case the memory leaks will not be as obvious. We are trying to run scalpel as a library inside of Autopsy. Although, we've heard that people may rather want PhotoRec instead of scalpel if we do that approach. PhotoRec is GPL, which means we can use it as a stand-alone command line tool, but we can't incorporate it as a library. brian On Jul 14, 2014, at 3:52 PM, Luís Filipe Nassif <lfc...@gm...> wrote: > Hi, > > Congratulations for the very important Autopsy new features! I started to test the new 3.1-beta release. The ScalpelCarver module is correctly listed as a installed plugin, but it does not appear in the "Configure Ingest Modules" step. This behavior also occurs with version 3.0.10. I need to configure something to enable ScalpelCarver? > > Thanks, > Luis Nassif > > > 2014-07-14 11:48 GMT-03:00 Brian Carrier <ca...@sl...>: > The long-awaited 3.1.0 beta is available. It has been a long time coming and has several new things, including: > > - Multi-threaded pipelines > - File type ingest module > - File extension mismatch ingest module > - Android ingest module > - KML report module > - Tags can be deleted > - Hash databases can be created and maintained > - ExFAT support > - ..... > > The official website is not fully updated yet, but you can get the windows installers from source forge: > > http://sourceforge.net/projects/autopsy/files/autopsy/3.1.0%20Beta%201/ > > brian > > > > > > > ------------------------------------------------------------------------------ > Want fast and easy access to all the code in your enterprise? Index and > search up to 200,000 lines of code with a free copy of Black Duck® > Code Sight™ - the same software that powers the world's largest code > search on Ohloh, the Black Duck Open Hub! Try it now. > http://p.sf.net/sfu/bds > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > ------------------------------------------------------------------------------ > Want fast and easy access to all the code in your enterprise? Index and > search up to 200,000 lines of code with a free copy of Black Duck® > Code Sight™ - the same software that powers the world's largest code > search on Ohloh, the Black Duck Open Hub! Try it now. > http://p.sf.net/sfu/bds_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Luís F. N. <lfc...@gm...> - 2014-07-14 19:52:39
|
Hi, Congratulations for the very important Autopsy new features! I started to test the new 3.1-beta release. The ScalpelCarver module is correctly listed as a installed plugin, but it does not appear in the "Configure Ingest Modules" step. This behavior also occurs with version 3.0.10. I need to configure something to enable ScalpelCarver? Thanks, Luis Nassif 2014-07-14 11:48 GMT-03:00 Brian Carrier <ca...@sl...>: > The long-awaited 3.1.0 beta is available. It has been a long time coming > and has several new things, including: > > - Multi-threaded pipelines > - File type ingest module > - File extension mismatch ingest module > - Android ingest module > - KML report module > - Tags can be deleted > - Hash databases can be created and maintained > - ExFAT support > - ..... > > The official website is not fully updated yet, but you can get the windows > installers from source forge: > > > http://sourceforge.net/projects/autopsy/files/autopsy/3.1.0%20Beta%201/ > > brian > > > > > > > > ------------------------------------------------------------------------------ > Want fast and easy access to all the code in your enterprise? Index and > search up to 200,000 lines of code with a free copy of Black Duck® > Code Sight™ - the same software that powers the world's largest code > search on Ohloh, the Black Duck Open Hub! Try it now. > http://p.sf.net/sfu/bds > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |
From: Brian C. <ca...@sl...> - 2014-07-14 14:48:47
|
The long-awaited 3.1.0 beta is available. It has been a long time coming and has several new things, including: - Multi-threaded pipelines - File type ingest module - File extension mismatch ingest module - Android ingest module - KML report module - Tags can be deleted - Hash databases can be created and maintained - ExFAT support - ..... The official website is not fully updated yet, but you can get the windows installers from source forge: http://sourceforge.net/projects/autopsy/files/autopsy/3.1.0%20Beta%201/ brian |
From: 趙 暁豪 <ch...@og...> - 2014-07-03 07:11:48
|
Hello sir I used Autopsy3.0 to make the timeline. But it didn’t show the “deleted” or “deleted-realloc”. How can I make it to show that? Best regards Zhao |
From: Brian C. <ca...@sl...> - 2014-06-24 19:38:53
|
It's time to vote for what talks you want to see at OSDFCon in November. The form is here: http://www.basistech.com/osdfcon/osdfcon-vote-for-presentations/ Like last year, the criteria are: +1: You’ll get to the talk early to make sure you have a good seat. 0: You’ll probably find this talk interesting. -1: You’ll likely end up checking e-mail during most of the talk There are 2 weeks to vote (due by July 7) and then we'll publish the final program. The Open Source Digital Forensics Conference (OSDFCon) will be Nov 5 in Herndon, VA. It's a day packed of talks all about using and developing open source digital forensics tools. Registration is already open for those of you who don't need to see the program to know that the fifth year of the conference will be even better than the last four (http://www.basistech.com/osdfcon/). brian |
From: moitshepi d. <dik...@gm...> - 2014-06-24 09:16:34
|
Hi Ehsan, Do you think the existing projects covers everything? Is there anything that you feel is lacking or can be improved? Look into those and see if you can make it any better or enhance what's available provided you are interested in the subject. Hope it helps. Regards, On 24 Jun 2014 10:11, "Enkidu Mo Shiri" <vol...@gm...> wrote: > Sorry guys if its off topic. i started my project as investigation of > crypto currency client side wallets to find forensic evidences. > more u study, more i find journals which have already worked on it . > any of u guys have any new unique idea which i can work on as a project? > thank you > *Ehsan Moshiri (Enkidu)* > *Digital Forensic Student* > *H/P:+96164953954 , +961124249769* > > *Linkedin: http://my.linkedin.com/pub/enkidu-moshiri/59/baa/90b/ > <http://my.linkedin.com/pub/enkidu-moshiri/59/baa/90b/> * > *Facebook: Enkidu Mo Shi Ri* > *wechat: Enkidu-Moshiri* > *Line: Enkidu.Moshiri* > > > ------------------------------------------------------------------------------ > Open source business process management suite built on Java and Eclipse > Turn processes into business applications with Bonita BPM Community Edition > Quickly connect people, data, and systems into organized workflows > Winner of BOSSIE, CODIE, OW2 and Gartner awards > http://p.sf.net/sfu/Bonitasoft > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: Enkidu Mo S. <vol...@gm...> - 2014-06-24 09:08:24
|
Sorry guys if its off topic. i started my project as investigation of crypto currency client side wallets to find forensic evidences. more u study, more i find journals which have already worked on it . any of u guys have any new unique idea which i can work on as a project? thank you *Ehsan Moshiri (Enkidu)* *Digital Forensic Student* *H/P:+96164953954 , +961124249769* *Linkedin: http://my.linkedin.com/pub/enkidu-moshiri/59/baa/90b/ <http://my.linkedin.com/pub/enkidu-moshiri/59/baa/90b/>* *Facebook: Enkidu Mo Shi Ri* *wechat: Enkidu-Moshiri* *Line: Enkidu.Moshiri* |
From: Sonnekus, M. <MSo...@fn...> - 2014-06-22 16:33:08
|
Hi Jason Thank you for the advise and guidance. Kind Regards Michael Sent from my LG Mobile ------ Original message------ From: Jason Wright Date: Sun, 22 Jun 2014 16:48 To: Sonnekus, Michael; Cc: sle...@li...; Subject:Re: [sleuthkit-users] Windows 7 Recognised as XP MIke, The version information in the file system details is not the version of the operating system. The file system isn't going to tell you anything about the operating system that's built on the volume. The OEM Name and version are based on the OS or application that formatted the file system. Check out "File System Forensic Analysis" by Brian Carrier if you really want to get into the nitty gritty details of the bytes in the Volume Boot Record. The OS details of the Windows system are going to be found in the Registry. R/ Jason On Sun, Jun 22, 2014 at 7:55 AM, Sonnekus, Michael <MSo...@fn...<mailto:MSo...@fn...>> wrote: Hi I am using Autopsy 2.24 on a SIFT 3.0 Workstation. I imported a dd image which I created using Paladin. The operating system of the drive imaged is Windows 7. When loading the image into Autopsy, the file system is correctly recognized as ntfs but the Version is detected Windows XP. I created an E01 image of the same drive using Paladin again and ran fsstat against the image. I received the same result – that the operating system on the image is XP. The fsstat output is below: sansforensics@siftworkstation:~/Windows_OS_Deleted$ fsstat -i ewf Windows_Paladin_Deleted_Image.E01 FILE SYSTEM INFORMATION -------------------------------------------- File System Type: NTFS Volume Serial Number: EAFE6DC5FE6D8B21 OEM Name: NTFS Version: Windows XP METADATA INFORMATION -------------------------------------------- First Cluster of MFT: 786432 First Cluster of MFT Mirror: 2 Size of MFT Entries: 1024 bytes Size of Index Records: 4096 bytes Range: 0 - 55040 Root Directory: 5 CONTENT INFORMATION -------------------------------------------- Sector Size: 512 Cluster Size: 4096 Total Cluster Range: 0 - 3669502 Total Sector Range: 0 - 29356030 $AttrDef Attribute Values: $STANDARD_INFORMATION (16) Size: 48-72 Flags: Resident $ATTRIBUTE_LIST (32) Size: No Limit Flags: Non-resident $FILE_NAME (48) Size: 68-578 Flags: Resident,Index $OBJECT_ID (64) Size: 0-256 Flags: Resident $SECURITY_DESCRIPTOR (80) Size: No Limit Flags: Non-resident $VOLUME_NAME (96) Size: 2-256 Flags: Resident $VOLUME_INFORMATION (112) Size: 12-12 Flags: Resident $DATA (128) Size: No Limit Flags: $INDEX_ROOT (144) Size: No Limit Flags: Resident $INDEX_ALLOCATION (160) Size: No Limit Flags: Non-resident $BITMAP (176) Size: No Limit Flags: Non-resident $REPARSE_POINT (192) Size: 0-16384 Flags: Non-resident $EA_INFORMATION (208) Size: 8-8 Flags: Resident $EA (224) Size: 0-65536 Flags: $LOGGED_UTILITY_STREAM (256) Size: 0-65536 Flags: Non-resident sansforensics@siftworkstation:~/Windows_OS_Deleted$ Could someone please shed some light on the reason for this? Thanks Mike To read FirstRand Bank's Disclaimer for this email click on the following address or copy into your Internet browser: https://www.fnb.co.za/disclaimer.html If you are unable to access the Disclaimer, send a blank e-mail to fir...@fn...<mailto:fir...@fn...> and we will send you a copy of the Disclaimer. ------------------------------------------------------------------------------ HPCC Systems Open Source Big Data Platform from LexisNexis Risk Solutions Find What Matters Most in Your Big Data with HPCC Systems Open Source. Fast. Scalable. Simple. Ideal for Dirty Data. Leverages Graph Analysis for Fast Processing & Easy Data Exploration http://p.sf.net/sfu/hpccsystems _______________________________________________ sleuthkit-users mailing list https://lists.sourceforge.net/lists/listinfo/sleuthkit-users http://www.sleuthkit.org To read FirstRand Bank's Disclaimer for this email click on the following address or copy into your Internet browser: https://www.fnb.co.za/disclaimer.html If you are unable to access the Disclaimer, send a blank e-mail to fir...@fn... and we will send you a copy of the Disclaimer. |
From: Jason W. <jwr...@gm...> - 2014-06-22 14:48:53
|
MIke, The version information in the file system details is not the version of the operating system. The file system isn't going to tell you anything about the operating system that's built on the volume. The OEM Name and version are based on the OS or application that formatted the file system. Check out "File System Forensic Analysis" by Brian Carrier if you really want to get into the nitty gritty details of the bytes in the Volume Boot Record. The OS details of the Windows system are going to be found in the Registry. R/ Jason On Sun, Jun 22, 2014 at 7:55 AM, Sonnekus, Michael <MSo...@fn...> wrote: > Hi > > > > I am using Autopsy 2.24 on a SIFT 3.0 Workstation. I imported a dd image > which I created using Paladin. The operating system of the drive imaged is > Windows 7. When loading the image into Autopsy, the file system is > correctly recognized as ntfs but the Version is detected Windows XP. > > > > I created an E01 image of the same drive using Paladin again and ran > fsstat against the image. I received the same result – that the operating > system on the image is XP. The fsstat output is below: > > > > sansforensics@siftworkstation:~/Windows_OS_Deleted$ fsstat -i ewf > Windows_Paladin_Deleted_Image.E01 > > FILE SYSTEM INFORMATION > > -------------------------------------------- > > File System Type: NTFS > > Volume Serial Number: EAFE6DC5FE6D8B21 > > OEM Name: NTFS > > Version: Windows XP > > > > METADATA INFORMATION > > -------------------------------------------- > > First Cluster of MFT: 786432 > > First Cluster of MFT Mirror: 2 > > Size of MFT Entries: 1024 bytes > > Size of Index Records: 4096 bytes > > Range: 0 - 55040 > > Root Directory: 5 > > > > CONTENT INFORMATION > > -------------------------------------------- > > Sector Size: 512 > > Cluster Size: 4096 > > Total Cluster Range: 0 - 3669502 > > Total Sector Range: 0 - 29356030 > > > > $AttrDef Attribute Values: > > $STANDARD_INFORMATION (16) Size: 48-72 Flags: Resident > > $ATTRIBUTE_LIST (32) Size: No Limit Flags: Non-resident > > $FILE_NAME (48) Size: 68-578 Flags: Resident,Index > > $OBJECT_ID (64) Size: 0-256 Flags: Resident > > $SECURITY_DESCRIPTOR (80) Size: No Limit Flags: Non-resident > > $VOLUME_NAME (96) Size: 2-256 Flags: Resident > > $VOLUME_INFORMATION (112) Size: 12-12 Flags: Resident > > $DATA (128) Size: No Limit Flags: > > $INDEX_ROOT (144) Size: No Limit Flags: Resident > > $INDEX_ALLOCATION (160) Size: No Limit Flags: Non-resident > > $BITMAP (176) Size: No Limit Flags: Non-resident > > $REPARSE_POINT (192) Size: 0-16384 Flags: Non-resident > > $EA_INFORMATION (208) Size: 8-8 Flags: Resident > > $EA (224) Size: 0-65536 Flags: > > $LOGGED_UTILITY_STREAM (256) Size: 0-65536 Flags: Non-resident > > sansforensics@siftworkstation:~/Windows_OS_Deleted$ > > > > > > Could someone please shed some light on the reason for this? > > > > Thanks > > > > Mike > > To read FirstRand Bank's Disclaimer for this email click on the following > address or copy into your Internet browser: > https://www.fnb.co.za/disclaimer.html > > If you are unable to access the Disclaimer, send a blank e-mail to > fir...@fn... and we will send you a copy of the > Disclaimer. > > > > ------------------------------------------------------------------------------ > HPCC Systems Open Source Big Data Platform from LexisNexis Risk Solutions > Find What Matters Most in Your Big Data with HPCC Systems > Open Source. Fast. Scalable. Simple. Ideal for Dirty Data. > Leverages Graph Analysis for Fast Processing & Easy Data Exploration > http://p.sf.net/sfu/hpccsystems > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: Sonnekus, M. <MSo...@fn...> - 2014-06-22 11:55:32
|
Hi I am using Autopsy 2.24 on a SIFT 3.0 Workstation. I imported a dd image which I created using Paladin. The operating system of the drive imaged is Windows 7. When loading the image into Autopsy, the file system is correctly recognized as ntfs but the Version is detected Windows XP. I created an E01 image of the same drive using Paladin again and ran fsstat against the image. I received the same result - that the operating system on the image is XP. The fsstat output is below: sansforensics@siftworkstation:~/Windows_OS_Deleted$ fsstat -i ewf Windows_Paladin_Deleted_Image.E01 FILE SYSTEM INFORMATION -------------------------------------------- File System Type: NTFS Volume Serial Number: EAFE6DC5FE6D8B21 OEM Name: NTFS Version: Windows XP METADATA INFORMATION -------------------------------------------- First Cluster of MFT: 786432 First Cluster of MFT Mirror: 2 Size of MFT Entries: 1024 bytes Size of Index Records: 4096 bytes Range: 0 - 55040 Root Directory: 5 CONTENT INFORMATION -------------------------------------------- Sector Size: 512 Cluster Size: 4096 Total Cluster Range: 0 - 3669502 Total Sector Range: 0 - 29356030 $AttrDef Attribute Values: $STANDARD_INFORMATION (16) Size: 48-72 Flags: Resident $ATTRIBUTE_LIST (32) Size: No Limit Flags: Non-resident $FILE_NAME (48) Size: 68-578 Flags: Resident,Index $OBJECT_ID (64) Size: 0-256 Flags: Resident $SECURITY_DESCRIPTOR (80) Size: No Limit Flags: Non-resident $VOLUME_NAME (96) Size: 2-256 Flags: Resident $VOLUME_INFORMATION (112) Size: 12-12 Flags: Resident $DATA (128) Size: No Limit Flags: $INDEX_ROOT (144) Size: No Limit Flags: Resident $INDEX_ALLOCATION (160) Size: No Limit Flags: Non-resident $BITMAP (176) Size: No Limit Flags: Non-resident $REPARSE_POINT (192) Size: 0-16384 Flags: Non-resident $EA_INFORMATION (208) Size: 8-8 Flags: Resident $EA (224) Size: 0-65536 Flags: $LOGGED_UTILITY_STREAM (256) Size: 0-65536 Flags: Non-resident sansforensics@siftworkstation:~/Windows_OS_Deleted$ Could someone please shed some light on the reason for this? Thanks Mike To read FirstRand Bank's Disclaimer for this email click on the following address or copy into your Internet browser: https://www.fnb.co.za/disclaimer.html If you are unable to access the Disclaimer, send a blank e-mail to fir...@fn... and we will send you a copy of the Disclaimer. |
From: Lion Th <li...@gm...> - 2014-06-20 10:59:41
|
Hi, Note: I am not an expert in "building" :-) I try to install sleuthkit on my mac air and it failed. Mac version 10.7.5 JDK 7 ( i installed 8 and it didnt work so I uninstalled and install 7 instead) sleuthkit-4.1.3.tar.gz Steps I took. =========== 1. Download and unzip sleuthkit-4.1.3.tar.gz 2. ./configure Complete with no errors 3. sudo make After running for a while it stop with errors. It seems that it cannot find the file "sqlite-jdbc-3.8.0-SNAPSHOT.jar" Is there anyway to go around it .. to download it manually and put it in it right place? Bellow you can find the end of the log with the error. Thank you, Lio Buildfile: /sleuthkit-4.1.3/bindings/java/build.xml testTSKLibs: check-native-build-mac: check-native-build-unix: check-native-build: check-build: dist: download-ivy: -download-ivy: init-ivy: init: [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/dist [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/lib [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/test/input [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/test/output/gold [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/test/output/results [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/amd64 [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/amd64/win [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/amd64/mac [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/amd64/linux [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/x86 [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/x86/win [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/x86/linux [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/x86_64 [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/x86_64/win [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/x86_64/mac [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/x86_64/linux [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/i386 [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/i386/win [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/i386/linux [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/i586 [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/i586/win [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/i586/linux [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/i686 [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/i686/win [mkdir] Created dir: /sleuthkit-4.1.3/bindings/java/build/NATIVELIBS/i686/linux retrieve-deps: [ivy:resolve] :: Apache Ivy 2.3.0-rc2 - 20121105223351 :: http://ant.apache.org/ivy/ :: [ivy:resolve] :: loading settings :: file = /sleuthkit-4.1.3/bindings/java/ivysettings.xml [ivy:resolve] :: resolving dependencies :: org.sleuthkit#datamodel;working@CompNames-MacBook-Air.local [ivy:resolve] confs: [default] [ivy:resolve] found junit#junit;4.8.2 in central [ivy:resolve] found com.googlecode.java-diff-utils#diffutils;1.2.1 in central [ivy:resolve] :: resolution report :: resolve 6764ms :: artifacts dl 11ms --------------------------------------------------------------------- | | modules || artifacts | | conf | number| search|dwnlded|evicted|| number|dwnlded| --------------------------------------------------------------------- | default | 3 | 0 | 0 | 0 || 6 | 0 | --------------------------------------------------------------------- [ivy:resolve] [ivy:resolve] :: problems summary :: [ivy:resolve] :::: WARNINGS [ivy:resolve] module not found: org.xerial#sqlite-jdbc;3.8.0-SNAPSHOT [ivy:resolve] ==== central: tried [ivy:resolve] http://repo1.maven.org/maven2/org/xerial/sqlite-jdbc/3.8.0-SNAPSHOT/sqlite-jdbc-3.8.0-SNAPSHOT.pom [ivy:resolve] -- artifact org.xerial#sqlite-jdbc;3.8.0-SNAPSHOT!sqlite-jdbc.jar: [ivy:resolve] http://repo1.maven.org/maven2/org/xerial/sqlite-jdbc/3.8.0-SNAPSHOT/sqlite-jdbc-3.8.0-SNAPSHOT.jar [ivy:resolve] ==== ibiblio: tried [ivy:resolve] http://repo1.maven.org/maven2/org/xerial/sqlite-jdbc/3.8.0-SNAPSHOT/sqlite-jdbc-3.8.0-SNAPSHOT.pom [ivy:resolve] -- artifact org.xerial#sqlite-jdbc;3.8.0-SNAPSHOT!sqlite-jdbc.jar: [ivy:resolve] http://repo1.maven.org/maven2/org/xerial/sqlite-jdbc/3.8.0-SNAPSHOT/sqlite-jdbc-3.8.0-SNAPSHOT.jar [ivy:resolve] ==== xerial: tried [ivy:resolve] http://oss.sonatype.org/content/repositories/snapshots/org/xerial/sqlite-jdbc/3.8.0-SNAPSHOT/sqlite-jdbc-3.8.0-SNAPSHOT.pom [ivy:resolve] -- artifact org.xerial#sqlite-jdbc;3.8.0-SNAPSHOT!sqlite-jdbc.jar: [ivy:resolve] http://oss.sonatype.org/content/repositories/snapshots/org/xerial/sqlite-jdbc/3.8.0-SNAPSHOT/sqlite-jdbc-3.8.0-SNAPSHOT.jar [ivy:resolve] :::::::::::::::::::::::::::::::::::::::::::::: [ivy:resolve] :: UNRESOLVED DEPENDENCIES :: [ivy:resolve] :::::::::::::::::::::::::::::::::::::::::::::: [ivy:resolve] :: org.xerial#sqlite-jdbc;3.8.0-SNAPSHOT: not found [ivy:resolve] :::::::::::::::::::::::::::::::::::::::::::::: [ivy:resolve] [ivy:resolve] :: USE VERBOSE OR DEBUG MESSAGE LEVEL FOR MORE DETAILS BUILD FAILED /sleuthkit-4.1.3/bindings/java/build.xml:119: The following error occurred while executing this line: /sleuthkit-4.1.3/bindings/java/build.xml:98: impossible to resolve dependencies: resolve failed - see output for details Total time: 8 seconds make[2]: *** [all-local] Error 1 make[1]: *** [all-recursive] Error 1 make: *** [all-recursive] Error 1 CompNames-MacBook-Air:sleuthkit-4.1.3 CompName$ |