Difference between revisions of "Truxton C API"
| Line 24: | Line 24: | ||
* [[truxton_get_version]] - Retrieves the version of Truxton | * [[truxton_get_version]] - Retrieves the version of Truxton | ||
* [[truxton_start_adding_files]] - Prepares Truxton to add files to the database | * [[truxton_start_adding_files]] - Prepares Truxton to add files to the database | ||
| + | * [[truxton_route_message]] - Send a message to down-stream ETL processors | ||
==ETL Functions== | ==ETL Functions== | ||
Revision as of 06:48, 14 June 2020
Truxton functionality is exposed to the C programming world as a DLL named TruxtonCAPI.dll in the C:\Program Files\Truxton\SDK folder.
This DLL can be called from any programming language that has the ability to make operating system calls.
Contents
- 1 Philosophy
- 2 API Groups
- 2.1 Initialization
- 2.2 Functions
- 2.3 ETL Functions
- 2.4 Child Files
- 2.5 File IO
- 2.6 File Record Fields
- 2.7 Create Objects from File
- 2.8 ETL Creation
- 2.9 Debugging
- 2.10 Message
- 2.11 File Export
- 2.12 Artifacts
- 2.13 Event
- 2.14 EXIF (Camera Information)
- 2.15 File Type
- 2.16 Geographic Location
- 2.17 Relation
- 2.18 Website Visit
- 2.19 USB Device
Philosophy
The API is considered to be "flat" in that only sixty-four bit integers and ASCII character strings are used in the interface. This was chosen to make it easy for other languages to interface to. The coding convention is all lower case names with underscores separating words. Truxton is a member of the east const posse.
API Groups
The API is broken down into the different areas of Truxton.
Initialization
- truxton_start - Initializes Truxton
- truxton_stop - Uninitializes Truxton
Functions
- truxton_create - Creates a Truxton object
- truxton_destroy - Frees a Truxton object
- truxton_get_device_id - Retrieves the Device identifier
- truxton_get_machine_id - Retrieves the machine identifier
- truxton_get_version - Retrieves the version of Truxton
- truxton_start_adding_files - Prepares Truxton to add files to the database
- truxton_route_message - Send a message to down-stream ETL processors
ETL Functions
- truxton_etl_create - Creates a Truxton ETL object
- truxton_etl_destroy - Destroys a Truxton ETL object
- truxton_etl_add_command_line_argument - Adds a command line argument
- truxton_etl_add_desired_file_type - Tells Truxton what types of files you want to process
- truxton_etl_get_description
- truxton_etl_set_description
- truxton_etl_get_message
- truxton_etl_get_stage_number
- truxton_etl_set_stage_number
- truxton_etl_set_application_name
- truxton_etl_set_depot_type
- truxton_etl_set_depot_type_name
- truxton_etl_set_expander_identifier
- truxton_etl_set_expander_version
- truxton_etl_set_queue_name
- truxton_etl_set_thread_safe
- truxton_etl_set_poly_file_expander
- truxton_etl_send_me_file_id - Used during development and debugging
- truxton_etl_send_me_files - Used during development and debugging
- truxton_etl_send_me_hash - Used during development and debugging
- truxton_etl_send_me_local_file - Used during development and debugging
Child Files
A child file is one that you have created and need to save in Truxton.
- truxton_child_file_create - Create a file object to save to Truxton
- truxton_child_file_destroy - Destroys a file object
- truxton_child_file_clear - Returns a file object to an initial state of all zeroes
- truxton_child_file_get_id - Retrieves the GUID of the child file
- truxton_child_file_set_id - Sets the GUID of the child file
- truxton_child_file_get_parent_id - Retrieves the GUID of the parent file
- truxton_child_file_set_parent_id - Sets the GUID of the parent of the child
- truxton_child_file_get_media_id - Retrieves the GUID of the media this child belongs to
- truxton_child_file_set_media_id - Sets the GUID of the media this child belongs to
- truxton_child_file_get_name - Retrieves the name of the file
- truxton_child_file_set_name - Sets the name of the file
- truxton_child_file_get_path - Retrieves the path of the file
- truxton_child_file_set_path - Sets the path of the file
- truxton_child_file_get_hash - Retrieves the MD5 hash (digital fingerprint) of the file's contents
- truxton_child_file_get_number_of_children - Retrieves the number of child files of this file
- truxton_child_file_set_number_of_children - Sets the number of child files of this file
- truxton_child_file_get_created - Retrieves the date and time of when the file was created
- truxton_child_file_set_created - Sets the date and time of when the file was created
- truxton_child_file_get_accessed - Retrieves the date and time of when the file was accessed
- truxton_child_file_set_accessed - Sets the date and time of when the file was accessed
- truxton_child_file_get_modified - Retrieves the date and time of when the file was modified (last written to)
- truxton_child_file_set_modified - Sets the date and time of when the file was modified (last written to)
- truxton_child_file_get_size - Retrieves the size of the file, in bytes, as reported by the operating system
- truxton_child_file_set_size - Sets the size of the file, in bytes, as reported by the operating system
- truxton_child_file_get_origin - Retrieves the origin of the file
- truxton_child_file_set_origin - Sets the origin of the file
- truxton_child_file_get_content_status - Retrieves the status of the contents of the file
- truxton_child_file_set_content_status - Sets the status of the contents of the file
- truxton_child_file_get_truxton - Retrieves the instance of Truxton this child belongs to
- truxton_child_file_begin_write - Prepares Truxton for writing contents to be associated with this file
- truxton_child_file_end_write - Tells Truxton to finish writing contents
- truxton_child_file_write - Gives Truxton bytes to store as the file contents
- truxton_child_file_save - Commits data to the database
- truxton_child_file_set_type - Sets the type of the file
- truxton_child_file_get_type - Retrieves the type of the file
- truxton_child_file_set_attributes - Sets the attributes of the file
- truxton_child_file_get_attributes - Retrieves the attributes of the file
- truxton_child_file_set_disk_offset - Sets the physical disk offset of the first byte of contents
- truxton_child_file_get_disk_offset - Retrieves the physical disk offset of the first byte of contents
- truxton_child_file_get_entropy - Retrieves the entropy of the file contents
Creating things related to this file:
- truxton_child_file_create_artifact - Creates and associates an artifact with this file. The artifact be saved to the
Entitytable. - truxton_child_file_create_event - Creates and associates an event with this file. The event will be saved to the
Eventtable. - truxton_child_file_create_exif - Creates and associates camera information with this file. The data will be saved to the
EXIFtable. - truxton_child_file_create_location - Creates and associates a geographic location with this file. The data will be saved to the
Locationtable. - truxton_child_file_create_relation - Creates a relationship with this file as the source. The data will be saved to the
Relationtable. - truxton_child_file_create_url - Creates a website visit with this file as the source. This data will be saved to the
WebsiteVisittable. - truxton_child_file_create_usb - Creates a USB device with this file as the source. This data will be saved to the
USBDevicetable. - truxton_child_file_tag - Creates a tag and puts it on this file. This data will be saved to the
Taggedtable. - truxton_child_file_new_child - Creates a child of this file
File IO
- truxton_file_open_id - Retrieves a particular file specified by the file's [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID..
- truxton_file_open_md5 - Retrieves the first file in Truxton whose contents have the given MD5 hash.
- truxton_file_close - Closes the contents. You will no longer be able to read from the file.
- truxton_file_free - Deallocates any resources allocated for this object. The file is no longer valid after this call.
- truxton_file_tell - Returns the current file pointer position.
- truxton_file_length - Returns the number of bytes in the file's contents.
- truxton_file_is_closed - Tells you if the file has been closed or not.
- truxton_file_seek - Changes the file pointer.
- truxton_file_readline - Reads a single line of text from the file.
- truxton_file_read - Reads bytes from the file.
File Record Fields
- truxton_file_get_id
- truxton_file_get_media_id
- truxton_file_get_parent_id
- truxton_file_get_number_of_children
- truxton_file_get_is_resident
- truxton_file_get_created
- truxton_file_get_accessed
- truxton_file_get_modified
- truxton_file_get_name
- truxton_file_get_attributes
- truxton_file_get_size
- truxton_file_get_origin
- truxton_file_get_content_status
- truxton_file_get_type
- truxton_file_get_hash
- truxton_file_get_entropy
- truxton_file_get_disk_offset
- truxton_file_get_is_eliminated
- truxton_file_get_depot_name
- truxton_file_get_depot_offset
- truxton_file_get_depot_length
- truxton_file_get_details
- truxton_file_get_truxton
- truxton_file_change_type
Create Objects from File
The following APIs are used to create objects with a file as their parent.
- truxton_file_create_artifact - Creates and associates an artifact with this file. The artifact be saved to the
Entitytable. - truxton_file_create_child - For creating a file.
- truxton_file_create_event - Creates and associates an event with this file. The event will be saved to the
Eventtable. - truxton_file_create_exif - Creates and associates camera information with this file. The data will be saved to the
EXIFtable. - truxton_file_create_location - Creates and associates a geographic location with this file. The data will be saved to the
Locationtable. - truxton_file_create_relation - Creates a relationship with this file as the source. The data will be saved to the
Relationtable. - truxton_file_create_url - Creates a website visit with this file as the source. This data will be saved to the
WebsiteVisittable. - truxton_file_create_usb - Creates a USB device with this file as the source. This data will be saved to the
USBDevicetable. - truxton_file_tag - Creates a tag and puts it on this file. This data will be saved to the
Taggedtable.
ETL Creation
The following APIs are used to extend Truxton by creating an exploitation process.
- truxton_etl_add_command_line_argument
- truxton_etl_add_desired_file_type
- truxton_etl_create
- truxton_etl_destroy
- truxton_etl_get_description
- truxton_etl_get_message
- truxton_etl_get_stage_number
- truxton_etl_set_application_name
- truxton_etl_set_depot_type
- truxton_etl_set_depot_type_name
- truxton_etl_set_description
- truxton_etl_set_expander_identifier
- truxton_etl_set_expander_version
- truxton_etl_set_queue_name
- truxton_etl_set_stage_number
- truxton_etl_set_thread_safe
- truxton_etl_set_poly_file_expander
Debugging
- truxton_etl_send_me_file_id - Puts a message in your queue given a GUID that matches the
IDcolumn of theFiletable. - truxton_etl_send_me_files - Put a specified number messages in your queue of a particular file type.
- truxton_etl_send_me_hash - Put one file that matches an MD5 hash.
- truxton_etl_send_me_local_file - Put a specified file on your system into your queue.
Message
- truxton_message_create
- truxton_message_destroy
- truxton_message_get_queue_is_empty
- truxton_message_set_queue_is_empty
- truxton_message_get_route_id
- truxton_message_set_route_id
- truxton_message_get_priority
- truxton_message_set_priority
- truxton_message_get_file_id
- truxton_message_set_file_id
- truxton_message_get_parent_id
- truxton_message_set_parent_id
- truxton_message_get_media_id
- truxton_message_set_media_id
- truxton_message_get_depot_id
- truxton_message_set_depot_id
- truxton_message_get_depot_offset
- truxton_message_set_depot_offset
- truxton_message_get_depot_length
- truxton_message_set_depot_length
- truxton_message_get_hash
- truxton_message_set_hash
- truxton_message_get_signature
- truxton_message_set_signature
- truxton_message_get_file_type
- truxton_message_set_file_type
- truxton_message_get_depot_filename
- truxton_message_set_depot_filename
- truxton_message_get_dont_route
- truxton_message_set_dont_route
- truxton_message_get_truxton
- truxton_message_set_truxton
File Export
- truxton_file_export_create
- truxton_file_export_destroy
- truxton_file_export_set_option
- truxton_file_export_get_where_clause
- truxton_file_export_add_string_criteria
- truxton_file_export_add_integer_criteria
- truxton_file_export_set_truxton
- truxton_file_export_where_clause
Artifacts
- truxton_artifact_create
- truxton_artifact_destroy
- truxton_artifact_save
- truxton_artifact_get_data_type
- truxton_artifact_set_data_type
- truxton_artifact_get_file_id
- truxton_artifact_set_file_id
- truxton_artifact_get_id
- truxton_artifact_get_length
- truxton_artifact_set_length
- truxton_artifact_get_media_id
- truxton_artifact_set_media_id
- truxton_artifact_get_object_id
- truxton_artifact_set_object_id
- truxton_artifact_get_object_type
- truxton_artifact_set_object_type
- truxton_artifact_get_offset
- truxton_artifact_set_offset
- truxton_artifact_get_value
- truxton_artifact_set_value
Event
- truxton_event_create
- truxton_event_destroy
- truxton_event_save
- truxton_event_get_id
- truxton_event_set_title
- truxton_event_get_title
- truxton_event_set_description
- truxton_event_get_description
- truxton_event_get_start
- truxton_event_set_start
- truxton_event_get_end
- truxton_event_set_end
- truxton_event_get_type
- truxton_event_set_type
- truxton_event_get_media_id
- truxton_event_set_media_id
- truxton_event_get_file_id
- truxton_event_set_file_id
EXIF (Camera Information)
- truxton_exif_create
- truxton_exif_destroy
- truxton_exif_save
- truxton_exif_get_id
- truxton_exif_get_file_id
- truxton_exif_set_file_id
- truxton_exif_get_media_id
- truxton_exif_set_media_id
- truxton_exif_get_gps_time
- truxton_exif_set_gps_time
- truxton_exif_get_gps_time_offset
- truxton_exif_set_gps_time_offset
- truxton_exif_get_device_time
- truxton_exif_set_device_time
- truxton_exif_get_device_time_offset
- truxton_exif_set_device_time_offset
- truxton_exif_get_latitude
- truxton_exif_set_latitude
- truxton_exif_get_latitude_offset
- truxton_exif_set_latitude_offset
- truxton_exif_get_longitude
- truxton_exif_set_longitude
- truxton_exif_get_longitude_offset
- truxton_exif_set_longitude_offset
- truxton_exif_get_altitude
- truxton_exif_set_altitude
- truxton_exif_get_altitude_offset
- truxton_exif_set_altitude_offset
- truxton_exif_get_heading
- truxton_exif_set_heading
- truxton_exif_get_heading_offset
- truxton_exif_set_heading_offset
- truxton_exif_get_focal_length
- truxton_exif_set_focal_length
- truxton_exif_get_focal_length_offset
- truxton_exif_set_focal_length_offset
- truxton_exif_get_shutter_count
- truxton_exif_set_shutter_count
- truxton_exif_get_shutter_count_offset
- truxton_exif_set_shutter_count_offset
- truxton_exif_get_thumbnail_offset
- truxton_exif_set_thumbnail_offset
- truxton_exif_get_thumbnail_offset_offset
- truxton_exif_set_thumbnail_offset_offset
- truxton_exif_get_thumbnail_length
- truxton_exif_set_thumbnail_length
- truxton_exif_get_thumbnail_length_offset
- truxton_exif_set_thumbnail_length_offset
- truxton_exif_get_make
- truxton_exif_set_make
- truxton_exif_get_make_offset
- truxton_exif_set_make_offset
- truxton_exif_get_model
- truxton_exif_set_model
- truxton_exif_get_model_offset
- truxton_exif_set_model_offset
- truxton_exif_get_body_serial_number
- truxton_exif_set_body_serial_number
- truxton_exif_get_body_serial_number_offset
- truxton_exif_set_body_serial_number_offset
- truxton_exif_get_lens_serial_number
- truxton_exif_set_lens_serial_number
- truxton_exif_get_lens_serial_number_offset
- truxton_exif_set_lens_serial_number_offset
File Type
- truxton_file_type_create
- truxton_file_type_destroy
- truxton_file_type_get_id
- truxton_file_type_set_id
- truxton_file_type_get_parent_id
- truxton_file_type_set_parent_id
- truxton_file_type_get_short_name
- truxton_file_type_set_short_name
- truxton_file_type_get_long_name
- truxton_file_type_set_long_name
- truxton_file_type_get_extension
- truxton_file_type_set_extension
- truxton_file_type_get_mime_type
- truxton_file_type_set_mime_type
- truxton_file_type_save
Geographic Location
- truxton_location_create
- truxton_location_destroy
- truxton_location_save
- truxton_location_get_id
- truxton_location_get_file_id
- truxton_location_set_file_id
- truxton_location_get_media_id
- truxton_location_set_media_id
- truxton_location_get_altitude
- truxton_location_set_altitude
- truxton_location_get_label
- truxton_location_set_label
- truxton_location_get_latitude
- truxton_location_set_latitude
- truxton_location_get_longitude
- truxton_location_set_longitude
- truxton_location_get_type
- truxton_location_set_type
- truxton_location_get_when
- truxton_location_set_when
Relation
- truxton_relation_create
- truxton_relation_destroy
- truxton_relation_save
- truxton_relation_get_a_id
- truxton_relation_set_a_id
- truxton_relation_get_b_id
- truxton_relation_set_b_id
- truxton_relation_get_source_id
- truxton_relation_set_source_id
- truxton_relation_get_a_type
- truxton_relation_set_a_type
- truxton_relation_get_b_type
- truxton_relation_set_b_type
- truxton_relation_get_source_type
- truxton_relation_set_source_type
- truxton_relation_get_relation
- truxton_relation_set_relation
Website Visit
- truxton_url_create
- truxton_url_destroy
- truxton_url_save
- truxton_url_get_account
- truxton_url_set_account
- truxton_url_get_account_offset
- truxton_url_set_account_offset
- truxton_url_get_file_id
- truxton_url_set_file_id
- truxton_url_get_format
- truxton_url_set_format
- truxton_url_get_id
- truxton_url_get_local_filename
- truxton_url_set_local_filename
- truxton_url_get_media_id
- truxton_url_set_media_id
- truxton_url_get_method
- truxton_url_set_method
- truxton_url_get_type
- truxton_url_set_type
- truxton_url_set_url
- truxton_url_get_url
- truxton_url_get_url_offset
- truxton_url_set_url_offset
- truxton_url_get_when
- truxton_url_set_when
USB Device
- truxton_usb_create
- truxton_usb_destroy
- truxton_usb_save
- truxton_usb_get_id
- truxton_usb_get_file_id
- truxton_usb_set_file_id
- truxton_usb_get_media_id
- truxton_usb_set_media_id
- truxton_usb_get_device_id
- truxton_usb_set_device_id
- truxton_usb_get_device_type
- truxton_usb_set_device_type
- truxton_usb_get_file_offset
- truxton_usb_set_file_offset
- truxton_usb_get_product_id
- truxton_usb_set_product_id
- truxton_usb_get_revision
- truxton_usb_set_revision
- truxton_usb_get_when
- truxton_usb_set_when
- truxton_usb_get_vendor_id
- truxton_usb_set_vendor_id