Difference between revisions of "TruxtonETL"

From truxwiki.com
Jump to navigation Jump to search
Line 9: Line 9:
 
==<code>addtype(file_type)</code>==
 
==<code>addtype(file_type)</code>==
 
This is how you programmatically tell Truxton what types of files you want to process.
 
This is how you programmatically tell Truxton what types of files you want to process.
It will cause Truxton to write records to the ETLRoute table. A new record will be added (if one does not already exist) with the ETLQueueName column set to this ETL's queue name and the FileTypeID column set to the file type specified in this function call.
+
It will cause Truxton to write records to the <code>[[ETLRoute Table | ETLRoute</code>]] table.
 +
A new record will be added (if one does not already exist) with the <code>ETLQueueName</code> column set to this ETL's queue name and the <code>FileTypeID</code> column set to the file type specified in this function call.
  
The [[File Types Supported | type of file]] you'd like to process.
+
The <code>file_type</code> parameter should be the [[File Types Supported | type of file]] you'd like to process.
  
 
==<code>depot</code>==
 
==<code>depot</code>==

Revision as of 10:47, 26 May 2020

This class provides capability to participate in Truxton's ETL pipeline. You can implement your own form of file exploitation. You can subscribe to events...

Attributes and Methods

addarg(argument)

This is used to build the command line arguments for the process. Truxton will automatically parse the command line for you but this allows you to programmatically force command line options.

addtype(file_type)

This is how you programmatically tell Truxton what types of files you want to process. It will cause Truxton to write records to the ETLRoute table. A new record will be added (if one does not already exist) with the ETLQueueName column set to this ETL's queue name and the FileTypeID column set to the file type specified in this function call.

The file_type parameter should be the type of file you'd like to process.

depot

This property is used in generating the depot filename.

description

This property

dtype

This property - set only

getmessage()

id

This property - set only

name

This property

poly

This property - set only

queue

This property

sendmehash(hash)

This method

sendmefileid(file_id)

This method

sendmefiles(file_type, count)

This method

sendmelocalfile(file_name, file_type, calculate_hash)

This method

stage

This property - set only

version

This property - set only

Sample

import truxton

def main():
  etl = truxton.etl()
  etl.name = "My New ETL"
  etl.description = "This ETL processes files in the Truxton system"
  etl.queue = "anewetl"
  etl.stage = 40
  etl.id = 9999

  etl.addarg("--verbose")
  etl.addarg("Yes")

  message = etl.getmessage()

  while message is not None:
    file_in_truxton = message.file()

    # YOUR FORENSIC CODE GOES HERE

    line_of_text = file_in_truxton.readline()

    if "[SetupAPI" in line_of_text:
      child = file_in_truxton.newchild()
      child.name = "Child file from New ETL"
      child.write("This is the file you were looking for.")
      child.save()

if __name__ == "__main__":
  main()