TruxtonChildFileIO newusb
Jump to navigation
Jump to search
This creates a new USB Device record from a file in Truxton.
It automatically associates the parent file and media identifiers used in the [USBDevice] table.
Syntax
object newusb();
Return value
A USB Device object
Sample
import truxton
import shutil
from datetime import datetime
from calendar import timegm
from pathlib import Path
EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000
def date_to_filetime(dt):
return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)
def add_file(parent_truxton_file, filename):
source_file = open(filename, "rb")
child = parent_truxton_file.newchild()
child.name = Path(filename).name
shutil.copyfileobj(source_file, child)
source_file.close()
child.save()
return child
EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000
def date_to_filetime(dt):
return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)
def main():
t = truxton.create()
file = t.getfileid("5ec2a123-74d6-5da7-0653-4e6800000000")
child = add_child( file, "C:/Manual Exploitation/Devices.csv")
usb = child.newusb()
usb.vendorid = 4100
usb.productid = 25084
usb.revision = 2
usb.offset = 8193
usb.when = date_to_filetime(datetime.utcnow())
if usb.save() is True:
print( "New USB saved as " + usb.id )
if __name__ == "__main__":
sys.exit(main())