Difference between revisions of "Creating NSRL Hashset"

From truxwiki.com
Jump to navigation Jump to search
Line 3: Line 3:
 
You can use this library to determine the source of a hash (which software package it came from) or, in the case of Truxton, eliminate files that will have no evidence in them.
 
You can use this library to determine the source of a hash (which software package it came from) or, in the case of Truxton, eliminate files that will have no evidence in them.
  
=How to Create NSRL Hash Set=
+
=How to Create NSRL Hash Set (v2)=
 
Follow these steps:
 
Follow these steps:
  
Line 14: Line 14:
 
# Rename the merged hashset into what you want <source lang="bat">ren merged.hashset LatestNSRL.hashset</source>
 
# Rename the merged hashset into what you want <source lang="bat">ren merged.hashset LatestNSRL.hashset</source>
 
# Replace the existing [[Hash Set|hash set]] file for the ETL layer with this new one.
 
# Replace the existing [[Hash Set|hash set]] file for the ETL layer with this new one.
 +
 +
=How to Create NSRL Hash Set (v3)=
 +
Follow these steps:
 +
 +
# [https://www.nist.gov/itl/ssd/software-quality-group/national-software-reference-library-nsrl/nsrl-download/current-rds Download] the data from NIST
 +
# Unzip the database
 +
# Download [https://sqlite.org/download.html sqlite tools]
 +
 +
==Example==
 +
Here's how to process one of the downloads.
 +
WARNING! You will need a LOT of disk space.
 +
 +
# Download <code>RDS_2023.03.1_modern_minimal.zip</code> (13.5GB)
 +
# Unzip it to produce <code>RDS_2023.03.1_modern_minimal.db</code> (113GB)
 +
# From a command window, execute <source lang="txt">
 +
sqlite3.exe
 +
.open RDS_2023.03.1_modern_minimal.db
 +
.output rds1.txt
 +
select md5 from FILE;
 +
.exit
 +
</source>

Revision as of 04:19, 12 May 2023

The National Software Reference Library is a project from the National Institute of Standards and Technology. It consists of several file downloads of CSV files containing hashes of file contents. You can use this library to determine the source of a hash (which software package it came from) or, in the case of Truxton, eliminate files that will have no evidence in them.

How to Create NSRL Hash Set (v2)

Follow these steps:

  1. Download the data from NIST
  2. Unzip or mount the ISO and unzip the NSRLFile.txt
  3. Run the Truxton\Tools\NSRLMinimalMD5.exe program to create a hash set file
    "C:\Program Files\Truxton\Tools\NSRLMinimalMD5.exe" NSRLFile.txt
    
  4. Rename the output file
    ren Out.hashset 1.hashset
    
  5. Repeat the above steps until you have produced all of the hash set files from the NSRL downloads.
  6. Merge the hashset files into a single hashset file
    "C:\Program Files\Truxton\Loader\Load.exe" -mergehashsets Yes 1.hashset 2.hashset 3.hashset 4.hashset 5.hashset 6.hashset
    
  7. Rename the merged hashset into what you want
    ren merged.hashset LatestNSRL.hashset
    
  8. Replace the existing hash set file for the ETL layer with this new one.

How to Create NSRL Hash Set (v3)

Follow these steps:

  1. Download the data from NIST
  2. Unzip the database
  3. Download sqlite tools

Example

Here's how to process one of the downloads. WARNING! You will need a LOT of disk space.

  1. Download RDS_2023.03.1_modern_minimal.zip (13.5GB)
  2. Unzip it to produce RDS_2023.03.1_modern_minimal.db (113GB)
  3. From a command window, execute
    sqlite3.exe
    .open RDS_2023.03.1_modern_minimal.db
    .output rds1.txt
    select md5 from FILE;
    .exit