<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://truxwiki.com/index.php?action=history&amp;feed=atom&amp;title=Truxton_add_triage_file</id>
	<title>Truxton add triage file - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://truxwiki.com/index.php?action=history&amp;feed=atom&amp;title=Truxton_add_triage_file"/>
	<link rel="alternate" type="text/html" href="https://truxwiki.com/index.php?title=Truxton_add_triage_file&amp;action=history"/>
	<updated>2026-09-09T15:57:55Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.34.1</generator>
	<entry>
		<id>https://truxwiki.com/index.php?title=Truxton_add_triage_file&amp;diff=7303&amp;oldid=prev</id>
		<title>Sam: /* Sample */</title>
		<link rel="alternate" type="text/html" href="https://truxwiki.com/index.php?title=Truxton_add_triage_file&amp;diff=7303&amp;oldid=prev"/>
		<updated>2024-02-09T10:48:13Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Sample&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 10:48, 9 February 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l49&quot; &gt;Line 49:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 49:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;    truxton_add_triage_file( truxton, 1, &amp;quot;bluetooth_device_map.xml&amp;quot;, &amp;quot;Phonebook Access Permissions&amp;quot;, &amp;quot;This is a source of MAC addresses&amp;quot; );&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;    truxton_add_triage_file( truxton, 1, &amp;quot;bluetooth_device_map.xml&amp;quot;, &amp;quot;Phonebook Access Permissions&amp;quot;, &amp;quot;This is a source of MAC addresses&amp;quot; );&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;    &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;truxton_add_database_id&lt;/del&gt;( truxton, 2, &amp;quot;MySecrets&amp;quot;, &amp;quot;MySecrets application data folder&amp;quot;, &amp;quot;Things the user wants to be hidden&amp;quot; );&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;    &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;truxton_add_triage_file&lt;/ins&gt;( truxton, 2, &amp;quot;MySecrets&amp;quot;, &amp;quot;MySecrets application data folder&amp;quot;, &amp;quot;Things the user wants to be hidden&amp;quot; );&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;    &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;truxton_add_database_id&lt;/del&gt;( truxton, 5, &amp;quot;dumpstate-2.*\\.txt$&amp;quot;, &amp;quot;Android Bug Report&amp;quot;, &amp;quot;We can get SSIDs out of this file&amp;quot; );&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;    &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;truxton_add_triage_file&lt;/ins&gt;( truxton, 5, &amp;quot;dumpstate-2.*\\.txt$&amp;quot;, &amp;quot;Android Bug Report&amp;quot;, &amp;quot;We can get SSIDs out of this file&amp;quot; );&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;    &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;truxton_add_database_id&lt;/del&gt;( truxton, 6, &amp;quot;ch.protonmail.android/databases.*&amp;quot;, &amp;quot;Proton Mail&amp;quot;, &amp;quot;Proton is a privacy oriented service&amp;quot; );&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;    &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;truxton_add_triage_file&lt;/ins&gt;( truxton, 6, &amp;quot;ch.protonmail.android/databases.*&amp;quot;, &amp;quot;Proton Mail&amp;quot;, &amp;quot;Proton is a privacy oriented service&amp;quot; );&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;}&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/source&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/source&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Sam</name></author>
		
	</entry>
	<entry>
		<id>https://truxwiki.com/index.php?title=Truxton_add_triage_file&amp;diff=7298&amp;oldid=prev</id>
		<title>Sam: Created page with &quot;This allows you to specify a file or folder to include in a Triage load. This will add a record to the &lt;code&gt;&lt;nowiki&gt;[&lt;/nowiki&gt;TriageFile&lt;nowiki&gt;]&lt;/no...&quot;</title>
		<link rel="alternate" type="text/html" href="https://truxwiki.com/index.php?title=Truxton_add_triage_file&amp;diff=7298&amp;oldid=prev"/>
		<updated>2024-02-09T10:33:01Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;This allows you to specify a file or folder to include in a &lt;a href=&quot;/Triage&quot; title=&quot;Triage&quot;&gt;Triage&lt;/a&gt; load. This will add a record to the &amp;lt;code&amp;gt;&amp;lt;nowiki&amp;gt;[&amp;lt;/nowiki&amp;gt;&lt;a href=&quot;/TriageFile_Table&quot; title=&quot;TriageFile Table&quot;&gt;TriageFile&lt;/a&gt;&amp;lt;nowiki&amp;gt;]&amp;lt;/no...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;This allows you to specify a file or folder to include in a [[Triage]] load.&lt;br /&gt;
This will add a record to the &amp;lt;code&amp;gt;&amp;lt;nowiki&amp;gt;[&amp;lt;/nowiki&amp;gt;[[TriageFile Table|TriageFile]]&amp;lt;nowiki&amp;gt;]&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt; table.&lt;br /&gt;
&lt;br /&gt;
=Syntax=&lt;br /&gt;
&amp;lt;source lang=&amp;quot;C&amp;quot;&amp;gt;&lt;br /&gt;
uint64_t truxton_add_triage_file(uint64_t truxton_handle, int64_t type, char const * name, char const * description, char const * why);&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Parameters=&lt;br /&gt;
==&amp;lt;code&amp;gt;truxton_handle&amp;lt;/code&amp;gt;==&lt;br /&gt;
The handle created by the [[truxton_create]] call.&lt;br /&gt;
&lt;br /&gt;
==&amp;lt;code&amp;gt;type&amp;lt;/code&amp;gt;==&lt;br /&gt;
This tells Truxton what the meaning of the &amp;lt;code&amp;gt;name&amp;lt;/code&amp;gt; parameter is.&lt;br /&gt;
It can be one of the following values:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Value&lt;br /&gt;
! Meaning&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align:center;&amp;quot; | 1&lt;br /&gt;
| The &amp;lt;code&amp;gt;name&amp;lt;/code&amp;gt; is the name of a file&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align:center;&amp;quot; | 2&lt;br /&gt;
| The &amp;lt;code&amp;gt;name&amp;lt;/code&amp;gt; is the name of a folder&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align:center;&amp;quot; | 5&lt;br /&gt;
| The &amp;lt;code&amp;gt;name&amp;lt;/code&amp;gt; is [https://en.wikipedia.org/wiki/Regular_expression regular expression] pattern for a file&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align:center;&amp;quot; | 6&lt;br /&gt;
| The &amp;lt;code&amp;gt;name&amp;lt;/code&amp;gt; is [https://en.wikipedia.org/wiki/Regular_expression regular expression] pattern for a folder&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==&amp;lt;code&amp;gt;name&amp;lt;/code&amp;gt;==&lt;br /&gt;
The name of the file or folder to include in a [[Triage]] load.&lt;br /&gt;
This can be a [https://en.wikipedia.org/wiki/Regular_expression regular expression].&lt;br /&gt;
&lt;br /&gt;
==&amp;lt;code&amp;gt;description&amp;lt;/code&amp;gt;==&lt;br /&gt;
More details about the file or folder.&lt;br /&gt;
&lt;br /&gt;
==&amp;lt;code&amp;gt;why&amp;lt;/code&amp;gt;==&lt;br /&gt;
Justification for including this in a [[Triage]] load.&lt;br /&gt;
&lt;br /&gt;
=Remarks=&lt;br /&gt;
All [https://en.wikipedia.org/wiki/Regular_expression regular expressions] are treated as case insensitive.&lt;br /&gt;
&lt;br /&gt;
=Sample=&lt;br /&gt;
&amp;lt;source lang=&amp;quot;C&amp;quot; highlight=&amp;quot;3-6&amp;quot;&amp;gt;&lt;br /&gt;
void add_interesting_files( uint64_t truxton_handle )&lt;br /&gt;
{&lt;br /&gt;
   truxton_add_triage_file( truxton, 1, &amp;quot;bluetooth_device_map.xml&amp;quot;, &amp;quot;Phonebook Access Permissions&amp;quot;, &amp;quot;This is a source of MAC addresses&amp;quot; );&lt;br /&gt;
   truxton_add_database_id( truxton, 2, &amp;quot;MySecrets&amp;quot;, &amp;quot;MySecrets application data folder&amp;quot;, &amp;quot;Things the user wants to be hidden&amp;quot; );&lt;br /&gt;
   truxton_add_database_id( truxton, 5, &amp;quot;dumpstate-2.*\\.txt$&amp;quot;, &amp;quot;Android Bug Report&amp;quot;, &amp;quot;We can get SSIDs out of this file&amp;quot; );&lt;br /&gt;
   truxton_add_database_id( truxton, 6, &amp;quot;ch.protonmail.android/databases.*&amp;quot;, &amp;quot;Proton Mail&amp;quot;, &amp;quot;Proton is a privacy oriented service&amp;quot; );&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sam</name></author>
		
	</entry>
</feed>