Truxton artifact get object id
Jump to navigation
Jump to search
This retrieves the GUID of the object this artifact came from.
This corresponds to the [ObjectID] column of the [Entity] table.
Syntax
void truxton_artifact_get_object_id( uint64_t artifact_handle, char * destination_string, size_t max_size );
Parameters
artifact_handle
The handle to an artifact created by the truxton_artifact_create call.
destination_string
The string to be written to.
max_size
The maximum number of characters that can be written to destination_string.
Sample
void dump_artifact( uint64_t artifact_handle )
{
char guid_string[ 40 ];
truxton_artifact_get_file_id( artifact_handle, guid_string, sizeof(guid_string) );
printf( "File ID is %s\n", guid_string );
truxton_artifact_get_media_id( artifact_handle, guid_string, sizeof(guid_string) );
printf( "Media ID is %s\n", guid_string );
truxton_artifact_get_object_id( artifact_handle, guid_string, sizeof(guid_string) );
printf( "Object ID is %s\n", guid_string );
truxton_artifact_get_id( artifact_handle, guid_string, sizeof(guid_string) );
printf( "Artifact ID is %s\n", guid_string );
uint64_t value = truxton_artifact_get_object_type( artifact_handle );
printf( "Object type is %" PRIu64 "\n", value );
value = truxton_artifact_get_data_type( artifact_handle );
printf( "Data type is %" PRIu64 "\n", value );
value = truxton_artifact_get_offset( artifact_handle );
printf( "Offset is %" PRIu64 "\n", value );
value = truxton_artifact_get_length( artifact_handle );
printf( "Length is %" PRIu64 "\n", value );
value = truxton_artifact_get_type( artifact_handle );
printf( "Type is %" PRIu64 "\n", value );
}
The PRIu64 in the sample code above is a standard way of formatting a 64-bit unsigned integer in C.
Over the years, different compilers on different operating systems used different format specifiers for things, these PRI macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic.