Difference between revisions of "TruxtonObject"

From truxwiki.com
Jump to navigation Jump to search
Line 5: Line 5:
 
==<code>closed</code>==
 
==<code>closed</code>==
 
It will return [https://docs.python.org/3/library/constants.html#True True] if the the connection to Truxton is closed, [https://docs.python.org/3/library/constants.html#False False] otherwise.
 
It will return [https://docs.python.org/3/library/constants.html#True True] if the the connection to Truxton is closed, [https://docs.python.org/3/library/constants.html#False False] otherwise.
 +
 +
==<code>createtag(name, description)</code>==
 +
This will create a new tag in Truxton.
 +
After calling this method, you can tag other items using only the <code>name</code>.
  
 
==<code>etlid</code>==
 
==<code>etlid</code>==
 
Returns the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the ETL if it is running.
 
Returns the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the ETL if it is running.
  
==<code>machineid</code>==
+
==<code>getbool(name)</code>==
Returns the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the machine.
+
This will retrieve a boolean [[Configuration System | setting]] from Truxton based on its name.
  
==<code>version</code>==
+
==<code>getfilehash(hash)</code>==
Returns the version string.
+
This will retrieve a [[TruxtonFileIO | file]] from Truxton based on its [https://en.wikipedia.org/wiki/MD5 MD5] hash.
 
 
==<code>createtag(name, description)</code>==
 
This will create a new tag in Truxton.
 
After calling this method, you can tag other items using only the <code>name</code>.
 
  
 
==<code>getfileid(id)</code>==
 
==<code>getfileid(id)</code>==
 
This will retrieve a [[TruxtonFileIO | file]] from Truxton based on its [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID.]
 
This will retrieve a [[TruxtonFileIO | file]] from Truxton based on its [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID.]
  
==<code>getfilehash(hash)</code>==
+
==<code>getint(name)</code>==
This will retrieve a [[TruxtonFileIO | file]] from Truxton based on its [https://en.wikipedia.org/wiki/MD5 MD5] hash.
+
This will retrieve an integer [[Configuration System | setting]] from Truxton based on its name.
  
 
==<code>getmediaid(id)</code>==
 
==<code>getmediaid(id)</code>==
 
This will retrieve a [[TruxtonMedia | media]] from Truxton based on its [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID.]
 
This will retrieve a [[TruxtonMedia | media]] from Truxton based on its [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID.]
 +
 +
==<code>getstring(name)</code>==
 +
This will retrieve a string [[Configuration System | setting]] from Truxton based on its name.
 +
 +
==<code>machineid</code>==
 +
Returns the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the machine.
  
 
==<code>neweventtype()</code>==
 
==<code>neweventtype()</code>==
Line 36: Line 42:
 
==<code>newinvestigation()</code>==
 
==<code>newinvestigation()</code>==
 
This will create an [[TruxtonInvestigation | investigation]] object.
 
This will create an [[TruxtonInvestigation | investigation]] object.
 +
 +
==<code>newmedia()</code>==
 +
This will create a [[TruxtonMedia | media]] object.
  
 
==<code>newrelation()</code>==
 
==<code>newrelation()</code>==
 
This will create a [[TruxtonRelation | relation]] object.
 
This will create a [[TruxtonRelation | relation]] object.
  
==<code>newmedia()</code>==
+
==<code>version</code>==
This will create a [[TruxtonMedia | media]] object.
+
Returns the version string.
  
 
=Sample=
 
=Sample=

Revision as of 06:22, 27 June 2020

This class give you access to Truxton at a global level.

Attributes and Methods

closed

It will return True if the the connection to Truxton is closed, False otherwise.

createtag(name, description)

This will create a new tag in Truxton. After calling this method, you can tag other items using only the name.

etlid

Returns the GUID of the ETL if it is running.

getbool(name)

This will retrieve a boolean setting from Truxton based on its name.

getfilehash(hash)

This will retrieve a file from Truxton based on its MD5 hash.

getfileid(id)

This will retrieve a file from Truxton based on its GUID.

getint(name)

This will retrieve an integer setting from Truxton based on its name.

getmediaid(id)

This will retrieve a media from Truxton based on its GUID.

getstring(name)

This will retrieve a string setting from Truxton based on its name.

machineid

Returns the GUID of the machine.

neweventtype()

This will create an event type object.

newexporter()

This will create an exporter object.

newinvestigation()

This will create an investigation object.

newmedia()

This will create a media object.

newrelation()

This will create a relation object.

version

Returns the version string.

Sample

import truxton
import shutil

from datetime import datetime
from calendar import timegm
from pathlib import Path

EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000

def date_to_filetime(dt):
  return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)

def create_event_type(t, id, name):
  event_type = t.neweventtype()
  event_type.id = id
  event_type.name = name
  event_type.save()

def add_file(parent_truxton_file, filename):
  source_file = open(filename, "rb")
  child = parent_truxton_file.newchild()
  child.name = Path(filename).name
  shutil.copyfileobj(source_file, child)
  source_file.close()
  child.save()

  return child

def add_media(t):
  media = t.newmedia()
  media.name = "Public Documents"
  media.description = "Publicly available documents"
  media.case = "DC-SNAFU-2016.2020"
  media.evidencebag = "EV-0937459386623-a"
  media.originator = "Jeffrey Jensen"
  media.latitude = 38.897661
  media.longitude = -77.036458
  media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
  media.save()

  return media

def add_ec(parent_file ):
  child_file = add_file(parent_file, "JW-v-DOJ-reply-02743.pdf")

  a = child_file.newartifact()
  a.type = truxton.ENTITY_TYPE_ACCOUNT
  a.value = "r0cker"
  a.datatype = truxton.DATA_TYPE_ASCII
  a.length = 6
  a.save()

  b = child_file.newartifact()
  b.type = truxton.ENTITY_TYPE_PERSON
  b.value = "Bob Smith"
  b.datatype = truxton.DATA_TYPE_ASCII
  b.length = 9
  b.save()

  relation = child_file.newrelation()
  relation.a = a.id
  relation.atype = truxton.OBJECT_TYPE_ENTITY
  relation.b = b.id
  relation.btype = truxton.OBJECT_TYPE_ENTITY
  relation.relation = truxton.RELATION_LOGON_ACCOUNT
  relation.save()

def main():
  t = truxton.create()

  media = add_media(t)

  root_file = media.addroot()
  root_file.save()

  add_ec(root_file)

if __name__ == "__main__":
  main()