Difference between revisions of "TruxtonETL"

From truxwiki.com
Jump to navigation Jump to search
Line 5: Line 5:
 
=Properties=
 
=Properties=
  
* depot - set id only
+
* depot - sets a name to be used in the filename of the depot file
 
* description -  
 
* description -  
 
* dtype - set only
 
* dtype - set only

Revision as of 03:19, 26 May 2020

This class provides capability to participate in Truxton's ETL pipeling. You can implement your own form of file exploitation. You can subscribe to events...

Properties

  • depot - sets a name to be used in the filename of the depot file
  • description -
  • dtype - set only
  • id - set only
  • name -
  • poly - set only
  • queue
  • stage - set only
  • version - set only

Methods

  • addarg
  • addtype
  • getmessage
  • sendmehash
  • sendmefileid
  • sendmefiles
  • sendmelocalfile

Sample

import truxton

def main():
  etl = truxton.etl()
  etl.name = "My New ETL"
  etl.description = "This ETL processes files in the Truxton system"
  etl.queue = "anewetl"
  etl.stage = 40
  etl.id = 9999

  message = etl.getmessage()

  while message is not None:
    file_in_truxton = message.file()

    # YOUR FORENSIC CODE GOES HERE

    line_of_text = file_in_truxton.readline()

    if "[SetupAPI" in line_of_text:
      child = file_in_truxton.newchild()
      child.name = "Child file from New ETL"
      child.write("This is the file you were looking for.")
      child.save()

if __name__ == "__main__":
  main()