IHi all,
i’m processing image “device1_laptop.e01” (COVID-19 Free Autopsy Training)
I have problem (on Autopsy 4.15 ) with these python addon module.
Are they supported on Autopsy 4.15 (4.14) ?
- Process Amcache
- Process SRUDB
- Bam Key
Process Amcache :
…\Temp\amcache directory is created and i can find also Amcache.hve file but Amcache.Db3 is an empty file (and Extracted Content doesn’t have any new refreshed amcache artifact)
Process SRUDB (all Logs checked)
Extracted Content doesn’t have any new refreshed artifact
Bam Key
Bam Key Module crashes (see log):
SEVERE: Bam Key Module experienced an error during analysis (data source = device1_laptop.e01, objId = 1, jobId = 0)
java.util.NoSuchElementException: Cannot find subkey with name UserSettings
com.williballenthin.rejistry.record.SubkeyListRecord.getSubkey(SubkeyListRecord.java:48)
com.williballenthin.rejistry.RegistryKey.getSubkey(RegistryKey.java:42)
sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
java.lang.reflect.Method.invoke(Method.java:498)
org.python.core.PyReflectedFunction.call(PyReflectedFunction.java:186)
org.python.core.PyReflectedFunction.call(PyReflectedFunction.java:204)
org.python.core.PyObject.call(PyObject.java:478)
org.python.core.PyObject.call(PyObject.java:482)
org.python.core.PyMethod.call(PyMethod.java:141)
bam_key$py.findRegistryKey$17(C:\Users\Luca\AppData\Roaming\autopsy\python_modules\Bam_Key\bam_key.py:300)
bam_key$py.call_function(C:\Users\Luca\AppData\Roaming\autopsy\python_modules\Bam_Key\bam_key.py)
org.python.core.PyTableCode.call(PyTableCode.java:167)
org.python.core.PyBaseCode.call(PyBaseCode.java:170)
org.python.core.PyFunction.call(PyFunction.java:434)
org.python.core.PyMethod.call(PyMethod.java:156)
bam_key$py.processSYSTEMHive$14(C:\Users\Luca\AppData\Roaming\autopsy\python_modules\Bam_Key\bam_key.py:244)
bam_key$py.call_function(C:\Users\Luca\AppData\Roaming\autopsy\python_modules\Bam_Key\bam_key.py)
org.python.core.PyTableCode.call(PyTableCode.java:167)
org.python.core.PyBaseCode.call(PyBaseCode.java:153)
org.python.core.PyFunction.call(PyFunction.java:423)
org.python.core.PyMethod.call(PyMethod.java:141)
bam_key$py.process$13(C:\Users\Luca\AppData\Roaming\autopsy\python_modules\Bam_Key\bam_key.py:218)
bam_key$py.call_function(C:\Users\Luca\AppData\Roaming\autopsy\python_modules\Bam_Key\bam_key.py)
org.python.core.PyTableCode.call(PyTableCode.java:167)
org.python.core.PyBaseCode.call(PyBaseCode.java:307)
org.python.core.PyBaseCode.call(PyBaseCode.java:198)
org.python.core.PyFunction.call(PyFunction.java:482)
org.python.core.PyMethod.instancemethod___call__(PyMethod.java:237)
org.python.core.PyMethod.call(PyMethod.java:228)
org.python.core.PyMethod.call(PyMethod.java:218)
org.python.core.PyMethod.call(PyMethod.java:213)
org.python.core.PyObject._jcallexc(PyObject.java:3626)
org.python.core.PyObject._jcall(PyObject.java:3658)
org.python.proxies.bam_key$BamKeyIngestModule$17.process(Unknown Source)
org.sleuthkit.autopsy.ingest.DataSourceIngestPipeline$PipelineModule.process(DataSourceIngestPipeline.java:200)
org.sleuthkit.autopsy.ingest.DataSourceIngestPipeline.process(DataSourceIngestPipeline.java:113)
org.sleuthkit.autopsy.ingest.DataSourceIngestJob.process(DataSourceIngestJob.java:744)
org.sleuthkit.autopsy.ingest.DataSourceIngestTask.execute(DataSourceIngestTask.java:30)
org.sleuthkit.autopsy.ingest.IngestManager$ExecuteIngestJobTasksTask.run(IngestManager.java:926)
java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511)
java.util.concurrent.FutureTask.run(FutureTask.java:266)
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
java.lang.Thread.run(Thread.java:748)
2020-05-03 20:08:59.216 org.sleuthkit.autopsy.ingest.DataSourceIngestJob logInfoMessage
INFO: Finished first stage analysis (data source = device1_laptop.e01, objId = 1, jobId = 0)
2020-05-03 20:08:59.217 org.sleuthkit.autopsy.ingest.DataSourceIngestJob logInfoMessage
INFO: Finished analysis (data source = device1_laptop.e01, objId = 1, jobId = 0)
2020-05-03 20:08:59.223 org.sleuthkit.autopsy.ingest.IngestManager finishIngestJob
INFO: Ingest job 0 completed
Thanks in advance
Luca