Difference between revisions of "Truxton file get accessed"
Jump to navigation
Jump to search
| Line 1: | Line 1: | ||
This retrieves the last accessed date of the file. | This retrieves the last accessed date of the file. | ||
| − | It corresponds to the <code>LastAccess</code> column of the <code>File</code> table. | + | It corresponds to the <code>LastAccess</code> column of the <code>[[File Table | File]]</code> table. |
=Syntax= | =Syntax= | ||
| Line 15: | Line 15: | ||
=Sample= | =Sample= | ||
| − | |||
<syntaxhighlight lang="C" highlight="10"> | <syntaxhighlight lang="C" highlight="10"> | ||
int print_id(uint64_t truxton) | int print_id(uint64_t truxton) | ||
Revision as of 06:29, 10 June 2020
This retrieves the last accessed date of the file.
It corresponds to the LastAccess column of the File table.
Syntax
uint64_t truxton_file_get_accessed( uint64_t file_handle );
Parameters
file_handle
The handle created by the truxton_file_open_id or truxton_file_open_md5 call.
Return value
The last access date of the file in FILETIME ticks.
Sample
int print_id(uint64_t truxton)
{
uint64_t file = truxton_file_open_md5(truxton, "9ec8fb6095c35eff2b236863b7caaf10");
if ( file != 0 )
{
return(0);
}
uint64_t ticks = truxton_file_get_accessed( file );
if ( ticks == 0 )
{
printf( "Timestamp was not set\n" );
}
}