Truxton file export add criteria

From truxwiki.com
Jump to navigation Jump to search

This gives you the ability to specify criteria for selecting files to export from Truxton.

Syntax

void truxton_file_export_add_criteria( uint64_t export_handle, uint64_t field, char const * value );

Parameters

export_handle

The handle to an export instance created by the truxton_file_export_create() call.

field

Which criteria to set.

value

The string representation of the field criteria.

Criteria Fields

The following are the possible criteria to set.

TRUXTON_EXPORT_FILE_QUERY_FIELD_SIZE

The length of the file to export.

TRUXTON_EXPORT_FILE_QUERY_FIELD_SIZE_MINIMUM

The minimum number of bytes in the file to export.

TRUXTON_EXPORT_FILE_QUERY_FIELD_SIZE_MAXIMUM

The maximum number of bytes in the file to export.

TRUXTON_EXPORT_FILE_QUERY_FIELD_HASH

The hash or partial hash of the file to export.

TRUXTON_EXPORT_FILE_QUERY_FIELD_TYPE

The type of file to export. You can specify a comma separated list of file types if you want to export more than a single type.

TRUXTON_EXPORT_FILE_QUERY_FIELD_PARENT_ID

The identifier of the parent of the files to export. This is useful for exporting the files in a folder in the seized media.

TRUXTON_EXPORT_FILE_QUERY_FIELD_ID

The identifier of the file. You can specify a comma separated list of identifiers if you want to export more than a single file.

TRUXTON_EXPORT_FILE_QUERY_FIELD_MEDIA

The identifier of the media the exported files belong to.

TRUXTON_EXPORT_FILE_QUERY_FIELD_LIMIT

Sets the maximum number of files to export.

TRUXTON_EXPORT_FILE_QUERY_FIELD_FILE_GROUP

The file group to export. You can specify a comma separated list of file groups if you want to export more than a single type.

TRUXTON_EXPORT_FILE_QUERY_FIELD_ORIGIN

Allows you to limit the output to just files of a particular origin.

Sample

#include "TruxtonCAPI.h"
#pragma comment(lib, "TruxtonCAPI.lib")

#include "filetypes.h"
#include <stdlib.h>
#pragma hdrstop

void main( void )
{
    char temporary_string[256];

    truxton_start();

    uint64_t truxton = truxton_create();

    uint64_t export_handle = truxton_file_export_create( truxton );

    // We want a variety of file types
    sprintf_s( temporary_string, sizeof(temporary_string), "%d, %d, %d", Type_JPEGWithExif, Type_JPEG, Type_GIF );
    truxton_file_export_add_criteria( export_handle, TRUXTON_EXPORT_FILE_QUERY_FIELD_TYPE, temp_string );

    // We only want files where the MD5 hash starts with "e4"
    truxton_file_export_add_criteria( export_handle, TRUXTON_EXPORT_FILE_QUERY_FIELD_HASH, "e4" );

    // We want a file that is at least 4MB long
    truxton_file_export_add_criteria( export_handle, TRUXTON_EXPORT_FILE_QUERY_FIELD_SIZE_MINIMUM, "4194304" );

    // We want a file that is no larger than 5MB
    truxton_file_export_add_criteria( export_handle, TRUXTON_EXPORT_FILE_QUERY_FIELD_SIZE_MAXIMUM, "5242880" );

    // Limit the output to a hundred file
    truxton_file_export_add_criteria( export_handle, TRUXTON_EXPORT_FILE_QUERY_FIELD_LIMIT, "001" );

    // We only want carved files
    truxton_file_export_add_criteria( export_handle, TRUXTON_EXPORT_FILE_QUERY_FIELD_ORIGIN, "3" );

    truxton_file_export_where_clause( export_handle, temporary_string, sizeof(temporary_string) );
    printf( "Will use the following WHERE clause to select files: %s\n", temporary_string );

    // Rename the file being exported to include the hash before the original name
    truxton_file_export_set_option( export_handle, TRUXTON_EXPORT_FILE_OPTION_NAME_FORMAT, "{hash}_{name}" );

    // The files should be output to a particular folder
    truxton_file_export_set_option( export_handle, TRUXTON_EXPORT_FILE_OPTION_FOLDER, "C:\\temp" );

    // We want them output to a TAR file in that particular folder
    truxton_file_export_set_option( export_handle, TRUXTON_EXPORT_FILE_OPTION_TAR, "CarvedGraphics.tar" );

    // Go find the files and output them to C:\temp\CarvedGraphics.tar
    truxton_file_export_execute( export_handle );

    // Clean up
    truxton_file_export_destroy( export_handle );
    truxton_destroy( truxton );
    truxton_stop();
}