2018-12-14 16:43:03 +00:00
/**
* @author n1474335 [n1474335@gmail.com]
* @copyright Crown Copyright 2018
* @license Apache-2.0
*/
2019-07-09 12:23:59 +01:00
import Operation from "../Operation.mjs" ;
import OperationError from "../errors/OperationError.mjs" ;
import Utils from "../Utils.mjs" ;
import { scanForFileTypes , extractFile } from "../lib/FileType.mjs" ;
import { FILE_SIGNATURES } from "../lib/FileSignatures.mjs" ;
2018-12-14 16:43:03 +00:00
/**
* Extract Files operation
*/
class ExtractFiles extends Operation {
/**
* ExtractFiles constructor
*/
constructor () {
super ();
2021-02-17 15:01:42 +00:00
// Get the first extension for each signature that can be extracted
let supportedExts = Object . keys ( FILE_SIGNATURES ). map ( cat => {
return FILE_SIGNATURES [ cat ]
. filter ( sig => sig . extractor )
. map ( sig => sig . extension . toUpperCase ());
});
// Flatten categories and remove duplicates
supportedExts = []. concat (... supportedExts ). unique ();
2018-12-14 16:43:03 +00:00
this . name = "Extract Files" ;
this . module = "Default" ;
2021-02-17 15:01:42 +00:00
this . description = `Performs file carving to attempt to extract files from the input.<br><br>This operation is currently capable of carving out the following formats:
<ul>
<li>
${ supportedExts . join ( "</li><li>" ) }
</li>
2022-06-17 11:18:49 +01:00
</ul>Minimum File Size can be used to prune small false positives.` ;
2024-02-02 23:56:27 +00:00
this . infoURL = "https://forensics.wiki/file_carving" ;
2018-12-14 16:43:03 +00:00
this . inputType = "ArrayBuffer" ;
this . outputType = "List<File>" ;
this . presentType = "html" ;
2019-01-14 18:55:10 +00:00
this . args = Object . keys ( FILE_SIGNATURES ). map ( cat => {
return {
name : cat ,
type : "boolean" ,
value : cat === "Miscellaneous" ? false : true
};
2019-03-02 16:12:21 +00:00
}). concat ([
{
name : "Ignore failed extractions" ,
type : "boolean" ,
2020-04-16 09:59:43 +02:00
value : true
2022-06-17 11:18:49 +01:00
},
{
name : "Minimum File Size" ,
type : "number" ,
2022-07-08 14:49:40 +01:00
value : 100
2019-03-02 16:12:21 +00:00
}
]);
2018-12-14 16:43:03 +00:00
}
/**
* @param {ArrayBuffer} input
* @param {Object[]} args
* @returns {List<File>}
*/
run ( input , args ) {
2019-01-14 18:55:10 +00:00
const bytes = new Uint8Array ( input ),
2019-03-02 16:12:21 +00:00
categories = [],
2022-06-17 11:18:49 +01:00
minSize = args . pop ( 1 ),
2019-03-02 16:12:21 +00:00
ignoreFailedExtractions = args . pop ( 1 );
2019-01-14 18:55:10 +00:00
args . forEach (( cat , i ) => {
if ( cat ) categories . push ( Object . keys ( FILE_SIGNATURES )[ i ]);
});
2018-12-14 16:43:03 +00:00
// Scan for embedded files
2019-01-14 18:55:10 +00:00
const detectedFiles = scanForFileTypes ( bytes , categories );
2018-12-14 16:43:03 +00:00
// Extract each file that we support
const files = [];
2019-03-09 06:25:27 +00:00
const errors = [];
2018-12-18 17:44:42 +00:00
detectedFiles . forEach ( detectedFile => {
2018-12-14 16:43:03 +00:00
try {
2022-07-08 14:49:40 +01:00
const file = extractFile ( bytes , detectedFile . fileDetails , detectedFile . offset );
if ( file . size >= minSize )
2022-06-17 11:18:49 +01:00
files . push ( file );
2019-01-11 17:44:13 +00:00
} catch ( err ) {
2019-03-02 16:12:21 +00:00
if ( ! ignoreFailedExtractions && err . message . indexOf ( "No extraction algorithm available" ) < 0 ) {
2019-03-09 06:25:27 +00:00
errors . push (
2019-03-02 16:12:21 +00:00
`Error while attempting to extract ${ detectedFile . fileDetails . name } ` +
`at offset ${ detectedFile . offset } :\n` +
` ${ err . message } `
);
}
2019-01-11 17:44:13 +00:00
}
2018-12-14 16:43:03 +00:00
});
2019-03-09 06:25:27 +00:00
if ( errors . length ) {
throw new OperationError ( errors . join ( "\n\n" ));
}
2018-12-14 16:43:03 +00:00
return files ;
}
2019-03-09 06:25:27 +00:00
2018-12-14 16:43:03 +00:00
/**
* Displays the files in HTML for web apps.
*
* @param {File[]} files
* @returns {html}
*/
async present ( files ) {
return await Utils . displayFilesAsHTML ( files );
}
}
export default ExtractFiles ;