Difference between revisions of "TruxtonFileIO"

From truxwiki.com
Jump to navigation Jump to search
Line 31: Line 31:
 
The following methods are also present to make tasks of adding items extracted from a file easier.
 
The following methods are also present to make tasks of adding items extracted from a file easier.
  
* [[TruxtonFileIO_newartifact | newartifact()]] - Used to create a record in the [[Entity Table | entity table]] and associated with this file.
+
* [[TruxtonFileIO_newartifact | newartifact()]] - Used to create a record in the <code><nowiki>[</nowiki>[[Entity Table|Entity]]<nowiki>]</nowiki></code> table and associated with this file.
 
* [[TruxtonFileIO_newchild | newchild()]] - Creates a writable file that will be a child of this file.
 
* [[TruxtonFileIO_newchild | newchild()]] - Creates a writable file that will be a child of this file.
 
* [[TruxtonFileIO_newcommunication | newcommunication()]] - Creates a new [[TruxtonCommunication|communication]] object with this file as its source.
 
* [[TruxtonFileIO_newcommunication | newcommunication()]] - Creates a new [[TruxtonCommunication|communication]] object with this file as its source.
* [[TruxtonFileIO_newevent | newevent()]] - Used to create a record in the [[Event Table | Event table]] and associated with this file.
+
* [[TruxtonFileIO_newevent | newevent()]] - Used to create a record in the <code><nowiki>[</nowiki>[[Event Table|Event]]<nowiki>]</nowiki></code> table and associated with this file.
* [[TruxtonFileIO_newexif | newexif()]] - Used to create a record in the [[EXIF Table | EXIF table]] and associated with this file.
+
* [[TruxtonFileIO_newexif | newexif()]] - Used to create a record in the <code><nowiki>[</nowiki>[[EXIF Table|EXIF]]<nowiki>]</nowiki></code> table and associated with this file.
* [[TruxtonFileIO_newlocation | newlocation()]] - Used to create a record in the [[Location Table | Location table]] and associated with this file.
+
* [[TruxtonFileIO_newlocation | newlocation()]] - Used to create a record in the <code><nowiki>[</nowiki>[[Location Table|Location]]<nowiki>]</nowiki></code> table and associated with this file.
* [[TruxtonFileIO_newrelation | newrelation()]] - Used to create a record in the [[Relation Table | Relation table]] and associated with this file.
+
* [[TruxtonFileIO_newrelation | newrelation()]] - Used to create a record in the <code><nowiki>[</nowiki>[[Relation Table|Relation]]<nowiki>]</nowiki></code> table and associated with this file.
* [[TruxtonFileIO_newurl | newurl()]] - Used to create a record in the [[WebsiteVisit Table | WebsiteVisit table]] and associated with this file.
+
* [[TruxtonFileIO_newurl | newurl()]] - Used to create a record in the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table and associated with this file.
* [[TruxtonFileIO_newusb | newusb()]] - Used to create a record in the [[USBDevice Table | USBDevice table]] and associated with this file.
+
* [[TruxtonFileIO_newusb | newusb()]] - Used to create a record in the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table and associated with this file.
 
* [[TruxtonFileIO_tag | tag()]] - Used to associate a tag with this file.
 
* [[TruxtonFileIO_tag | tag()]] - Used to associate a tag with this file.
 
* [[TruxtonFileIO_changetype | changetype()]] - Used the change the type of the file.
 
* [[TruxtonFileIO_changetype | changetype()]] - Used the change the type of the file.
Line 47: Line 47:
 
==<code>accessed</code>==
 
==<code>accessed</code>==
 
When the file was last accessed in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks.
 
When the file was last accessed in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks.
This corresponds to the <code>LastAccess</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[LastAccess]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>attributes</code>==
 
==<code>attributes</code>==
 
An integer value representing the attributes of the file.
 
An integer value representing the attributes of the file.
 
For a Microsoft filesystem, it can be a combination of the [https://docs.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants file attribute flags.]
 
For a Microsoft filesystem, it can be a combination of the [https://docs.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants file attribute flags.]
This corresponds to the <code>Attributes</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[Attributes]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>children</code>==
 
==<code>children</code>==
 
The number of files that have this file as their parent.
 
The number of files that have this file as their parent.
This corresponds to the <code>NumberOfChildren</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[NumberOfChildren]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>created</code>==
 
==<code>created</code>==
 
When the file was created in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks.
 
When the file was created in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks.
This corresponds to the <code>Created</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[Created]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>depot</code>==
 
==<code>depot</code>==
 
The name of the depot holding the file's contents.
 
The name of the depot holding the file's contents.
This corresponds to the <code>Filename</code> column of the <code>Depot</code> table.
+
This corresponds to the <code>[Filename]</code> column of the <code>[Depot]</code> table.
  
 
==<code>depotid</code>==
 
==<code>depotid</code>==
 
The name of the depot holding the file's contents.
 
The name of the depot holding the file's contents.
This corresponds to the <code>DepotID</code> column of the <code>Content</code> table.
+
This corresponds to the <code>[DepotID]</code> column of the <code>[Content]</code> table.
  
 
==<code>depotlength</code>==
 
==<code>depotlength</code>==
 
The number of bytes in the depot used for this file's contents.
 
The number of bytes in the depot used for this file's contents.
This corresponds tot he <code>Length</code> column of the <code>Content</code> table.
+
This corresponds tot he <code>[Length]</code> column of the <code>[Content]</code> table.
  
 
==<code>depotoffset</code>==
 
==<code>depotoffset</code>==
 
The number of bytes in the depot used for this file's contents.
 
The number of bytes in the depot used for this file's contents.
This corresponds tot he <code>Offset</code> column of the <code>Content</code> table.
+
This corresponds tot he <code>[Offset]</code> column of the <code>[Content]</code> table.
  
 
==<code>diskoffset</code>==
 
==<code>diskoffset</code>==
 
The offset, in bytes, of the first byte of the contents of the file on the physical disk.
 
The offset, in bytes, of the first byte of the contents of the file on the physical disk.
This corresponds to the <code>PhysicalDiskOffset</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[PhysicalDiskOffset]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>eliminated</code>==
 
==<code>eliminated</code>==
Line 88: Line 88:
  
 
==<code>entropy</code>==
 
==<code>entropy</code>==
[[Truxton_child_file_get_entropy | Shannon's entropy]] of the contents of the file.
+
[[Truxton_child_file_get_entropy|Shannon's entropy]] of the contents of the file.
This corresponds to the <code>RawEntropy</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[RawEntropy]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>hash</code>==
 
==<code>hash</code>==
 
The [https://en.wikipedia.org/wiki/MD5 MD5] hash of the contents of the file.
 
The [https://en.wikipedia.org/wiki/MD5 MD5] hash of the contents of the file.
This corresponds to the <code>HashID</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[HashID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>id</code>==
 
==<code>id</code>==
 
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file record.
 
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file record.
This corresponds to the <code>ID</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[ID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>mediaid</code>==
 
==<code>mediaid</code>==
 
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media the child file came from.
 
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media the child file came from.
This corresponds to the <code>MediaID</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[MediaID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>modified</code>==
 
==<code>modified</code>==
 
When the file was last written in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks.
 
When the file was last written in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks.
This corresponds to the <code>LastWrite</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[LastWrite]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>name</code>==
 
==<code>name</code>==
Line 112: Line 112:
 
==<code>origin</code>==
 
==<code>origin</code>==
 
Where the file came from.
 
Where the file came from.
It should be one of the [[Origin | origin values.]]
+
It should be one of the [[Origin|origin values.]]
This corresponds to the <code>OriginID</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[OriginID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>parentid</code>==
 
==<code>parentid</code>==
 
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the parent of this file.
 
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the parent of this file.
This corresponds to the <code>ParentFileID</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[ParentFileID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>resident</code>==
 
==<code>resident</code>==
Line 124: Line 124:
 
==<code>size</code>==
 
==<code>size</code>==
 
The size, in bytes, of the file.
 
The size, in bytes, of the file.
This corresponds to the <code>OSLength</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[OSLength]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>status</code>==
 
==<code>status</code>==
 
The status of the contents of the file.
 
The status of the contents of the file.
It should be one of the [[Content Status | content status values.]]
+
It should be one of the [[Content Status|content status values.]]
This corresponds to the <code>ContentStatusID</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[ContentStatusID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>type</code>==
 
==<code>type</code>==
The [[File Types Supported | type]] of the file.
+
The [[File Types Supported|type]] of the file.
This corresponds to the <code>FileTypeID</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[FileTypeID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
=Sample=
 
=Sample=
 
This will retrieve a file from Truxton, print the name and hash as stored in the database then calculate a hash on the contents and print that.
 
This will retrieve a file from Truxton, print the name and hash as stored in the database then calculate a hash on the contents and print that.
<syntaxhighlight lang="Python">
+
<source lang="Python">
 
import truxton
 
import truxton
 
import hashlib
 
import hashlib
Line 151: Line 151:
 
if __name__ == "__main__":
 
if __name__ == "__main__":
 
   main()
 
   main()
</syntaxhighlight>
+
</source>

Revision as of 06:40, 4 December 2020

This class provides read-only access to a file's contents in Truxton.

IOBase Methods

From IOBase it implements:

RawIOBase

From RawIOBase it implements:

Truxton Methods

The above methods will let you read from a file in Truxton as if it were any other file in Python. The following methods are also present to make tasks of adding items extracted from a file easier.

Properties

accessed

When the file was last accessed in FILETIME ticks. This corresponds to the [LastAccess] column of the [File] table.

attributes

An integer value representing the attributes of the file. For a Microsoft filesystem, it can be a combination of the file attribute flags. This corresponds to the [Attributes] column of the [File] table.

children

The number of files that have this file as their parent. This corresponds to the [NumberOfChildren] column of the [File] table.

created

When the file was created in FILETIME ticks. This corresponds to the [Created] column of the [File] table.

depot

The name of the depot holding the file's contents. This corresponds to the [Filename] column of the [Depot] table.

depotid

The name of the depot holding the file's contents. This corresponds to the [DepotID] column of the [Content] table.

depotlength

The number of bytes in the depot used for this file's contents. This corresponds tot he [Length] column of the [Content] table.

depotoffset

The number of bytes in the depot used for this file's contents. This corresponds tot he [Offset] column of the [Content] table.

diskoffset

The offset, in bytes, of the first byte of the contents of the file on the physical disk. This corresponds to the [PhysicalDiskOffset] column of the [File] table.

eliminated

True when the original contents of the file were eliminated based on the hash matching one from a list of hashes of files known to have no investigative value. The NSRL is one such library. If this is False, the file's contents are available for use.

entropy

Shannon's entropy of the contents of the file. This corresponds to the [RawEntropy] column of the [File] table.

hash

The MD5 hash of the contents of the file. This corresponds to the [HashID] column of the [File] table.

id

The GUID of the file record. This corresponds to the [ID] column of the [File] table.

mediaid

The GUID of the media the child file came from. This corresponds to the [MediaID] column of the [File] table.

modified

When the file was last written in FILETIME ticks. This corresponds to the [LastWrite] column of the [File] table.

name

The name of the file.

origin

Where the file came from. It should be one of the origin values. This corresponds to the [OriginID] column of the [File] table.

parentid

The GUID of the parent of this file. This corresponds to the [ParentFileID] column of the [File] table.

resident

True if this file's contents exist contiguously within the contents of another file.

size

The size, in bytes, of the file. This corresponds to the [OSLength] column of the [File] table.

status

The status of the contents of the file. It should be one of the content status values. This corresponds to the [ContentStatusID] column of the [File] table.

type

The type of the file. This corresponds to the [FileTypeID] column of the [File] table.

Sample

This will retrieve a file from Truxton, print the name and hash as stored in the database then calculate a hash on the contents and print that.

import truxton
import hashlib

def main():
  t = truxton.create()
  file = t.getfileid("5ec2a123-74d6-5da7-0653-4e6800000000")
  print(file.hash + " is the hash in the database for " + file.name )
  bytes = file.readall()
  readable_hash = hashlib.md5(bytes).hexdigest()
  print(readable_hash + " is the calculated hash of the contents")

if __name__ == "__main__":
  main()