Difference between revisions of "TruxtonUrl"

From truxwiki.com
Jump to navigation Jump to search
Line 2: Line 2:
 
=Attributes and Methods=
 
=Attributes and Methods=
  
==<code>account</code>==
+
==<code>account: str</code>==
 
The optional account name associated with the URL.
 
The optional account name associated with the URL.
 
Many browsers will record the operating system user that did the surfing.
 
Many browsers will record the operating system user that did the surfing.
  
==<code>accountoffset</code>==
+
==<code>accountoffset: int</code>==
 
The offset into the parent file where the account was found.
 
The offset into the parent file where the account was found.
  
==<code>fileid</code>==
+
==<code>fileid: str</code>==
 
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this [https://en.wikipedia.org/wiki/URL URL] came from.
 
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this [https://en.wikipedia.org/wiki/URL URL] came from.
 
This corresponds to the <code>[FileID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.
 
This corresponds to the <code>[FileID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.
  
==<code>format</code>==
+
==<code>format: int</code>==
 
The format of the raw URL.
 
The format of the raw URL.
 
This can be <code>URL_FORMAT_ASCII</code> (1) or <code>URL_FORMAT_UNICODE</code> (2)
 
This can be <code>URL_FORMAT_ASCII</code> (1) or <code>URL_FORMAT_UNICODE</code> (2)
  
==<code>id</code>==
+
==<code>id: str</code>==
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the record.
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the record.
 
It becomes non-zero after <code>save()</code> has been called.
 
It becomes non-zero after <code>save()</code> has been called.
  
==<code>localfilename</code>==
+
==<code>localfilename: str</code>==
 
The path to the file the browser uses to cache the contents of the page retrieved by the URL.
 
The path to the file the browser uses to cache the contents of the page retrieved by the URL.
  
==<code>mediaid</code>==
+
==<code>mediaid: str</code>==
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media this visit came from.
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media this visit came from.
 
This identifier corresponds to the <code>[MediaID]</code> of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.
 
This identifier corresponds to the <code>[MediaID]</code> of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.
  
==<code>method</code>==
+
==<code>method: int</code>==
 
The reason this URL was retrieved.
 
The reason this URL was retrieved.
 
It corresponds to the <code>[WebsiteMethodID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.
 
It corresponds to the <code>[WebsiteMethodID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.
Line 34: Line 34:
 
You can also use one of the [[URL Methods | predefined constants.]]
 
You can also use one of the [[URL Methods | predefined constants.]]
  
==<code>offset</code>==
+
==<code>offset: int</code>==
 
The offset in the file where this URL was found.
 
The offset in the file where this URL was found.
 
It should be the offset of the first character in the URL.
 
It should be the offset of the first character in the URL.
  
==<code>save()</code>==
+
==<code>save() -> bool</code>==
 
This will commit the information to the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.
 
This will commit the information to the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.
 
It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error.
 
It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error.
  
==<code>tag(tag, reason, origin)</code>==
+
==<code>tag(tag: str, reason: str, origin: int) -> bool</code>==
 
This creates a tag associated with this visit in Truxton.
 
This creates a tag associated with this visit in Truxton.
 
The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI.
 
The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI.
Line 50: Line 50:
 
[https://docs.python.org/3.8/library/constants.html?highlight=false#True True] if the tag was associated with the file, [https://docs.python.org/3.8/library/constants.html?highlight=false#False False] on failure.
 
[https://docs.python.org/3.8/library/constants.html?highlight=false#True True] if the tag was associated with the file, [https://docs.python.org/3.8/library/constants.html?highlight=false#False False] on failure.
  
==<code>type</code>==
+
==<code>type: int</code>==
 
The type of URL.
 
The type of URL.
 
It corresponds to the <code>[URLTypeID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.
 
It corresponds to the <code>[URLTypeID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.
Line 56: Line 56:
 
You can also use one of the [[URL Types | predefined constants.]]
 
You can also use one of the [[URL Types | predefined constants.]]
  
==<code>url</code>==
+
==<code>url: str</code>==
 
The URL string.
 
The URL string.
 
This corresponds to the <code>[URL]</code> column of the <code>[URL]</code> table.
 
This corresponds to the <code>[URL]</code> column of the <code>[URL]</code> table.
  
==<code>when</code>==
+
==<code>when: int</code>==
 
When the URL was seen in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks.
 
When the URL was seen in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks.
 
This corresponds to the <code>[When]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.
 
This corresponds to the <code>[When]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table.

Revision as of 14:49, 1 August 2022

This class lets you add to the [WebsiteVisit] table in Truxton.

Attributes and Methods

account: str

The optional account name associated with the URL. Many browsers will record the operating system user that did the surfing.

accountoffset: int

The offset into the parent file where the account was found.

fileid: str

The GUID of the file this URL came from. This corresponds to the [FileID] column of the [WebsiteVisit] table.

format: int

The format of the raw URL. This can be URL_FORMAT_ASCII (1) or URL_FORMAT_UNICODE (2)

id: str

This is the GUID of the record. It becomes non-zero after save() has been called.

localfilename: str

The path to the file the browser uses to cache the contents of the page retrieved by the URL.

mediaid: str

This is the GUID of the media this visit came from. This identifier corresponds to the [MediaID] of the [WebsiteVisit] table.

method: int

The reason this URL was retrieved. It corresponds to the [WebsiteMethodID] column of the [WebsiteVisit] table. The value must match a value in the [ID] column in the [WebsiteMethod] table. You can also use one of the predefined constants.

offset: int

The offset in the file where this URL was found. It should be the offset of the first character in the URL.

save() -> bool

This will commit the information to the [WebsiteVisit] table. It will return True if the record was saved to the database, False if there was an error.

tag(tag: str, reason: str, origin: int) -> bool

This creates a tag associated with this visit in Truxton. The tag parameter is a short, one or two word, bit of text that will be displayed in the UI. The reason is a sentence explaining why this visit was tagged. The origin is either TAG_ORIGIN_AUTOMATIC (1) or TAG_ORIGIN_HUMAN (2). It will return True if the tag was associated with the file, False on failure.

type: int

The type of URL. It corresponds to the [URLTypeID] column of the [WebsiteVisit] table. The value must match a value in the [ID] column in the [URLType] table. You can also use one of the predefined constants.

url: str

The URL string. This corresponds to the [URL] column of the [URL] table.

when: int

When the URL was seen in FILETIME ticks. This corresponds to the [When] column of the [WebsiteVisit] table.

Sample

import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil

from datetime import datetime
from calendar import timegm
from pathlib import Path

EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000

EVENT_TYPE_FBI = 20001

def date_to_filetime(dt):
  return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)

def create_event_type(t, id, name):
  event_type = t.neweventtype()
  event_type.id = id
  event_type.name = name
  event_type.save()

def add_file(parent_truxton_file, filename):
  source_file = open(filename, "rb")
  child = parent_truxton_file.newchild()
  child.name = Path(filename).name
  shutil.copyfileobj(source_file, child)
  source_file.close()
  child.save()
  return child

def add_event(parent_file, start, end, title, description, type):
  event = parent_file.newevent()
  event.start = date_to_filetime(datetime.fromisoformat(start))
  event.end = date_to_filetime(datetime.fromisoformat(end))
  event.title = title
  event.description = description
  event.type = type
  event.save()
  return event

def add_media(t):
  media = t.newmedia()

  media.name = "Public Documents"
  media.description = "Publicly available documents"
  media.case = "DC-SNAFU-2016.2020"
  media.evidencebag = "EV-0937459386623-a"
  media.originator = "Jeffrey Jensen"
  media.latitude = 38.897661
  media.longitude = -77.036458
  media.type = truxton.MEDIA_TYPE_LOGICAL_FILES

  if media.save():
    print("Media saved")
  else:
    print("Media not saved")

  return media

def add_ec(parent_file ):
  child_file = add_file(parent_file, "JW-v-DOJ-reply-02743.pdf")

  url = child_file.newurl()
  url.url = "https://www.judicialwatch.org/documents/jw-v-doj-reply-02743/"
  url.localfilename = "JW-v-DOJ-reply-02743.pdf"
  url.type = truxton.URL_TYPE_FIREFOX
  url.method = truxton.URL_METHOD_TYPE_CLICKED_ON_A_LINK
  url.format = truxton.URL_FORMAT_ASCII
  url.when = date_to_filetime(datetime.fromisoformat("2020-05-20T00:00:00-05:00"))
  url.save()

  add_event( child_file, "2016-07-31T12:00:00-05:00", "2016-07-31T12:00:00-05:00", "Crossfire Hurricane Created", "At FBI HQ", EVENT_TYPE_FBI )
  add_event( child_file, "2016-07-27T12:00:00-05:00", "2016-07-27T12:00:00-05:00", "Legat called needing to meet US ambassador", "In London", EVENT_TYPE_FBI )
  add_event( child_file, "2016-07-29T12:00:00-05:00", "2016-07-29T12:00:00-05:00", "FBI Receives Downer Info from Legat", "Probably legat London", EVENT_TYPE_FBI )

def main():
  t = truxton.create()

  create_event_type(t, EVENT_TYPE_FBI, "FBI Actions" )

  media = add_media(t)

  root_file = media.addroot()
  root_file.save()

  add_ec(root_file)

if __name__ == "__main__":
  main()