Difference between revisions of "Truxton child file get origin"
Jump to navigation
Jump to search
| Line 1: | Line 1: | ||
This retrieves origin of the file object. | This retrieves origin of the file object. | ||
| − | This corresponds to the <code>OriginID</code> column of the <code>[[File Table | File]]</code> table. | + | This corresponds to the <code>[OriginID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table. |
=Syntax= | =Syntax= | ||
| − | < | + | <source lang="C"> |
uint32_t truxton_child_file_get_origin( uint64_t child_handle ); | uint32_t truxton_child_file_get_origin( uint64_t child_handle ); | ||
| − | </ | + | </source> |
=Parameters= | =Parameters= | ||
==<code>child_handle</code>== | ==<code>child_handle</code>== | ||
| − | |||
The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call. | The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call. | ||
=Return= | =Return= | ||
| − | |||
The origin of the file. | The origin of the file. | ||
It should be one of the [[Origin]] values. | It should be one of the [[Origin]] values. | ||
| − | This value should also be found in the <code>ID</code> column of the <code>Origin</code> table. | + | This value should also be found in the <code>[ID]</code> column of the <code>[Origin]</code> table. |
=Sample= | =Sample= | ||
| − | + | <source lang="C" highlight="35"> | |
| − | < | ||
void add_folder(uint64_t truxton, uint64_t parent_file) | void add_folder(uint64_t truxton, uint64_t parent_file) | ||
{ | { | ||
| Line 36: | Line 33: | ||
FILETIME now; | FILETIME now; | ||
| − | + | GetSystemTimePreciseAsFileTime(&now); | |
ULARGE_INTEGER ticks; | ULARGE_INTEGER ticks; | ||
| Line 56: | Line 53: | ||
{ | { | ||
uint32_t origin = truxton_child_file_get_origin(child_file); | uint32_t origin = truxton_child_file_get_origin(child_file); | ||
| − | printf( "Origin is % | + | printf( "Origin is %" PRIu32 "\n", origin ); |
} | } | ||
truxton_child_file_destroy(child); | truxton_child_file_destroy(child); | ||
} | } | ||
| − | </ | + | </source> |
Revision as of 05:16, 13 November 2020
This retrieves origin of the file object.
This corresponds to the [OriginID] column of the [File] table.
Contents
Syntax
uint32_t truxton_child_file_get_origin( uint64_t child_handle );
Parameters
child_handle
The handle created by the truxton_child_file_create or truxton_file_create_child call.
Return
The origin of the file.
It should be one of the Origin values.
This value should also be found in the [ID] column of the [Origin] table.
Sample
void add_folder(uint64_t truxton, uint64_t parent_file)
{
truxton_start_adding_files(truxton);
uint64_t child = truxton_child_file_create(truxton);
char id[40];
truxton_file_get_id(parent_file, id, sizeof(id));
truxton_child_file_set_parent_id(child, id);
truxton_child_file_set_type(child, Type_Directory);
truxton_child_file_set_name(child, "Custom Exploits Folder");
FILETIME now;
GetSystemTimePreciseAsFileTime(&now);
ULARGE_INTEGER ticks;
ticks.LowPart = now.dwLowDateTime;
ticks.HighPart = now.dwHighDateTime;
truxton_child_file_set_created(child, ticks.QuadPart);
truxton_child_file_set_accessed(child, ticks.QuadPart);
truxton_child_file_set_modified(child, ticks.QuadPart);
truxton_child_file_set_origin(child, ORIGIN_GENERATED);
if ( truxton_child_file_save(child) == 0 )
{
printf( "Failed to add child to Truxton\n" );
}
else
{
uint32_t origin = truxton_child_file_get_origin(child_file);
printf( "Origin is %" PRIu32 "\n", origin );
}
truxton_child_file_destroy(child);
}