Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -6,19 +6,19 @@
"case_number": "caseSYNTH001",
"number_of_columns": 9,
"number_of_rows": 6,
"total_data_size_bytes": 1231,
"total_data_size_bytes": 1222,
"media_checkins": 4,
"media_embedded_checkins": 0,
"input_zip_path": "admin/test/cases/data/synchronoss/testdata.synchronoss.synchronoss_mms_received.caseSYNTH001.zip",
"start_time": "2026-09-04T03:39:53.299755+00:00",
"end_time": "2026-09-04T03:39:53.327934+00:00",
"run_time_seconds": 0.001283884048461914,
"start_time": "2026-09-04T18:30:54.622940+00:00",
"end_time": "2026-09-04T18:30:54.649193+00:00",
"run_time_seconds": 0.0012514591217041016,
"last_commit": {
"hash": "e610a63f92df487f3d5cc95c61ceb34278d6fb1d",
"hash": "bc0358bdf5234f869bc35b2f92a6e9760107e238",
"author_name": "OneSixForensics",
"author_email": "kyle@onesixforensics.com",
"date": "2026-09-03T09:34:48-06:00",
"message": "Resolve MMS media per date folder regardless of seeker file order"
"date": "2026-09-03T21:43:31-06:00",
"message": "Read the DV access log CSV case-insensitively, and pin media order"
}
},
"headers": [
Expand Down Expand Up @@ -73,7 +73,7 @@
"+12085550000",
"",
"9999999999999999999999999999999999999999999999999999999999999999.jpg",
"referenced \u2014 file not in daily folder; possibly quarantined/removed",
"referenced \u2014 no file of this name in the MMS media folders",
"1764572400000:d14",
"SYNTH001LCIDHASH/messages/20251201.csv"
],
Expand Down
7 changes: 5 additions & 2 deletions admin/test/scripts/gen_synchronoss_synth.py
Original file line number Diff line number Diff line change
Expand Up @@ -277,10 +277,13 @@ def quarantine(seq, data, force_hash=None):
"dv_uploads": sum(1 for r in DV_ALL if "checksum=" in str(r[3])),
"dv_sync": sum(1 for r in DV_ALL if "checksum=" not in str(r[3])),
"quarantined": len([n for n in os.listdir(mk(QDIR, ".")) if "zip_file_" in n]),
"vzmobile": 3,
"vzmobile": sum(
len(files)
for _, _, files in os.walk(os.path.join(BASE, LCID, "VZMOBILE"))
),
"mms_media_files": sum(
len(files)
for root, _, files in os.walk(os.path.join(BASE, LCID, "messages", "attachments", "mms"))
for _, _, files in os.walk(os.path.join(BASE, LCID, "messages", "attachments", "mms"))
),
}

Expand Down
29 changes: 16 additions & 13 deletions scripts/artifacts/synchronoss.py
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@
"description": "Parses received MMS media with inline display, linked to message CSV metadata",
"author": "@OneSixForensics",
"creation_date": "2026-06-24",
"last_update_date": "2026-09-03",
"last_update_date": "2026-09-04",
"requirements": "none",
"category": "Synchronoss",
"notes": "Media at <LCID>/messages/attachments/mms/in/YYYY-MM-DD/. "
Expand All @@ -41,10 +41,10 @@
"folders in these returns (image000000.jpg and the extensionless '0' recur daily), so "
"where a name is in more than one folder and none is the message's own date, the "
"token is reported as not linked, with the number of folders carrying the name, "
"rather than linked to another date's copy. 'referenced -- file not in daily folder' "
"means the token names media that is not in the return at all; per Synchronoss, "
"flagged files are quarantined out of the daily folder, so absence here is expected "
"for reported content and is not on its own a finding about the file. Direction is "
"rather than linked to another date's copy. 'referenced -- no file of this name in the "
"MMS media folders' means exactly that and nothing more: per Synchronoss, flagged "
"files are quarantined out of the daily folder, so absence is expected for reported "
"content, but absence alone does not establish why any one file is missing. Direction is "
"constant in this artifact by construction, since the artifact selects one direction.",
"paths": (
'*/messages/2*.csv',
Expand All @@ -59,7 +59,7 @@
"description": "Parses sent MMS media with inline display, linked to message CSV metadata",
"author": "@OneSixForensics",
"creation_date": "2026-06-24",
"last_update_date": "2026-09-03",
"last_update_date": "2026-09-04",
"requirements": "none",
"category": "Synchronoss",
"notes": "Media at <LCID>/messages/attachments/mms/out/YYYY-MM-DD/. "
Expand All @@ -69,10 +69,10 @@
"folders in these returns (image000000.jpg and the extensionless '0' recur daily), so "
"where a name is in more than one folder and none is the message's own date, the "
"token is reported as not linked, with the number of folders carrying the name, "
"rather than linked to another date's copy. 'referenced -- file not in daily folder' "
"means the token names media that is not in the return at all; per Synchronoss, "
"flagged files are quarantined out of the daily folder, so absence here is expected "
"for reported content and is not on its own a finding about the file. Direction is "
"rather than linked to another date's copy. 'referenced -- no file of this name in the "
"MMS media folders' means exactly that and nothing more: per Synchronoss, flagged "
"files are quarantined out of the daily folder, so absence is expected for reported "
"content, but absence alone does not establish why any one file is missing. Direction is "
"constant in this artifact by construction, since the artifact selects one direction.",
"paths": (
'*/messages/2*.csv',
Expand Down Expand Up @@ -668,10 +668,13 @@ def _synchronoss_mms_media(context, direction):
f'date folders, none matching message date '
f'{date_folder or "?"}; manual review required')
else:
# Media-looking token with no file present — likely quarantined/removed.
# Media-looking token with no file of that name anywhere under this
# direction. Quarantine is the common cause, but the cell states what
# was observed and leaves the cause to the notes: this string is what
# lands in front of an examiner, and it cannot tell the two apart.
media_cell = ''
link_status = ('referenced — file not in daily folder; '
'possibly quarantined/removed')
link_status = ('referenced — no file of this name in the '
'MMS media folders')

data_list.append((
_ts_utc(msg_date),
Expand Down
Loading