Difference between revisions of "TruxtonUrl"
(→Sample) |
|||
| Line 2: | Line 2: | ||
=Attributes and Methods= | =Attributes and Methods= | ||
| − | ==<code>account</code>== | + | ==<code>account: str</code>== |
The optional account name associated with the URL. | The optional account name associated with the URL. | ||
Many browsers will record the operating system user that did the surfing. | Many browsers will record the operating system user that did the surfing. | ||
| − | ==<code>accountoffset</code>== | + | ==<code>accountoffset: int</code>== |
The offset into the parent file where the account was found. | The offset into the parent file where the account was found. | ||
| − | ==<code>fileid</code>== | + | ==<code>fileid: str</code>== |
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this [https://en.wikipedia.org/wiki/URL URL] came from. | The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this [https://en.wikipedia.org/wiki/URL URL] came from. | ||
This corresponds to the <code>[FileID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | This corresponds to the <code>[FileID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | ||
| − | ==<code>format</code>== | + | ==<code>format: int</code>== |
The format of the raw URL. | The format of the raw URL. | ||
This can be <code>URL_FORMAT_ASCII</code> (1) or <code>URL_FORMAT_UNICODE</code> (2) | This can be <code>URL_FORMAT_ASCII</code> (1) or <code>URL_FORMAT_UNICODE</code> (2) | ||
| − | ==<code>id</code>== | + | ==<code>id: str</code>== |
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the record. | This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the record. | ||
It becomes non-zero after <code>save()</code> has been called. | It becomes non-zero after <code>save()</code> has been called. | ||
| − | ==<code>localfilename</code>== | + | ==<code>localfilename: str</code>== |
The path to the file the browser uses to cache the contents of the page retrieved by the URL. | The path to the file the browser uses to cache the contents of the page retrieved by the URL. | ||
| − | ==<code>mediaid</code>== | + | ==<code>mediaid: str</code>== |
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media this visit came from. | This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media this visit came from. | ||
This identifier corresponds to the <code>[MediaID]</code> of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | This identifier corresponds to the <code>[MediaID]</code> of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | ||
| − | ==<code>method</code>== | + | ==<code>method: int</code>== |
The reason this URL was retrieved. | The reason this URL was retrieved. | ||
It corresponds to the <code>[WebsiteMethodID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | It corresponds to the <code>[WebsiteMethodID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | ||
| Line 34: | Line 34: | ||
You can also use one of the [[URL Methods | predefined constants.]] | You can also use one of the [[URL Methods | predefined constants.]] | ||
| − | ==<code>offset</code>== | + | ==<code>offset: int</code>== |
The offset in the file where this URL was found. | The offset in the file where this URL was found. | ||
It should be the offset of the first character in the URL. | It should be the offset of the first character in the URL. | ||
| − | ==<code>save()</code>== | + | ==<code>save() -> bool</code>== |
This will commit the information to the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | This will commit the information to the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | ||
It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error. | It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error. | ||
| − | ==<code>tag(tag, reason, origin)</code>== | + | ==<code>tag(tag: str, reason: str, origin: int) -> bool</code>== |
This creates a tag associated with this visit in Truxton. | This creates a tag associated with this visit in Truxton. | ||
The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI. | The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI. | ||
| Line 50: | Line 50: | ||
[https://docs.python.org/3.8/library/constants.html?highlight=false#True True] if the tag was associated with the file, [https://docs.python.org/3.8/library/constants.html?highlight=false#False False] on failure. | [https://docs.python.org/3.8/library/constants.html?highlight=false#True True] if the tag was associated with the file, [https://docs.python.org/3.8/library/constants.html?highlight=false#False False] on failure. | ||
| − | ==<code>type</code>== | + | ==<code>type: int</code>== |
The type of URL. | The type of URL. | ||
It corresponds to the <code>[URLTypeID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | It corresponds to the <code>[URLTypeID]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | ||
| Line 56: | Line 56: | ||
You can also use one of the [[URL Types | predefined constants.]] | You can also use one of the [[URL Types | predefined constants.]] | ||
| − | ==<code>url</code>== | + | ==<code>url: str</code>== |
The URL string. | The URL string. | ||
This corresponds to the <code>[URL]</code> column of the <code>[URL]</code> table. | This corresponds to the <code>[URL]</code> column of the <code>[URL]</code> table. | ||
| − | ==<code>when</code>== | + | ==<code>when: int</code>== |
When the URL was seen in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | When the URL was seen in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | ||
This corresponds to the <code>[When]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | This corresponds to the <code>[When]</code> column of the <code><nowiki>[</nowiki>[[WebsiteVisit Table|WebsiteVisit]]<nowiki>]</nowiki></code> table. | ||
Revision as of 14:49, 1 August 2022
This class lets you add to the [WebsiteVisit] table in Truxton.
Contents
Attributes and Methods
account: str
The optional account name associated with the URL. Many browsers will record the operating system user that did the surfing.
accountoffset: int
The offset into the parent file where the account was found.
fileid: str
The GUID of the file this URL came from.
This corresponds to the [FileID] column of the [WebsiteVisit] table.
format: int
The format of the raw URL.
This can be URL_FORMAT_ASCII (1) or URL_FORMAT_UNICODE (2)
id: str
This is the GUID of the record.
It becomes non-zero after save() has been called.
localfilename: str
The path to the file the browser uses to cache the contents of the page retrieved by the URL.
mediaid: str
This is the GUID of the media this visit came from.
This identifier corresponds to the [MediaID] of the [WebsiteVisit] table.
method: int
The reason this URL was retrieved.
It corresponds to the [WebsiteMethodID] column of the [WebsiteVisit] table.
The value must match a value in the [ID] column in the [WebsiteMethod] table.
You can also use one of the predefined constants.
offset: int
The offset in the file where this URL was found. It should be the offset of the first character in the URL.
save() -> bool
This will commit the information to the [WebsiteVisit] table.
It will return True if the record was saved to the database, False if there was an error.
tag(tag: str, reason: str, origin: int) -> bool
This creates a tag associated with this visit in Truxton.
The tag parameter is a short, one or two word, bit of text that will be displayed in the UI.
The reason is a sentence explaining why this visit was tagged.
The origin is either TAG_ORIGIN_AUTOMATIC (1) or TAG_ORIGIN_HUMAN (2).
It will return
True if the tag was associated with the file, False on failure.
type: int
The type of URL.
It corresponds to the [URLTypeID] column of the [WebsiteVisit] table.
The value must match a value in the [ID] column in the [URLType] table.
You can also use one of the predefined constants.
url: str
The URL string.
This corresponds to the [URL] column of the [URL] table.
when: int
When the URL was seen in FILETIME ticks.
This corresponds to the [When] column of the [WebsiteVisit] table.
Sample
import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil
from datetime import datetime
from calendar import timegm
from pathlib import Path
EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000
EVENT_TYPE_FBI = 20001
def date_to_filetime(dt):
return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)
def create_event_type(t, id, name):
event_type = t.neweventtype()
event_type.id = id
event_type.name = name
event_type.save()
def add_file(parent_truxton_file, filename):
source_file = open(filename, "rb")
child = parent_truxton_file.newchild()
child.name = Path(filename).name
shutil.copyfileobj(source_file, child)
source_file.close()
child.save()
return child
def add_event(parent_file, start, end, title, description, type):
event = parent_file.newevent()
event.start = date_to_filetime(datetime.fromisoformat(start))
event.end = date_to_filetime(datetime.fromisoformat(end))
event.title = title
event.description = description
event.type = type
event.save()
return event
def add_media(t):
media = t.newmedia()
media.name = "Public Documents"
media.description = "Publicly available documents"
media.case = "DC-SNAFU-2016.2020"
media.evidencebag = "EV-0937459386623-a"
media.originator = "Jeffrey Jensen"
media.latitude = 38.897661
media.longitude = -77.036458
media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
if media.save():
print("Media saved")
else:
print("Media not saved")
return media
def add_ec(parent_file ):
child_file = add_file(parent_file, "JW-v-DOJ-reply-02743.pdf")
url = child_file.newurl()
url.url = "https://www.judicialwatch.org/documents/jw-v-doj-reply-02743/"
url.localfilename = "JW-v-DOJ-reply-02743.pdf"
url.type = truxton.URL_TYPE_FIREFOX
url.method = truxton.URL_METHOD_TYPE_CLICKED_ON_A_LINK
url.format = truxton.URL_FORMAT_ASCII
url.when = date_to_filetime(datetime.fromisoformat("2020-05-20T00:00:00-05:00"))
url.save()
add_event( child_file, "2016-07-31T12:00:00-05:00", "2016-07-31T12:00:00-05:00", "Crossfire Hurricane Created", "At FBI HQ", EVENT_TYPE_FBI )
add_event( child_file, "2016-07-27T12:00:00-05:00", "2016-07-27T12:00:00-05:00", "Legat called needing to meet US ambassador", "In London", EVENT_TYPE_FBI )
add_event( child_file, "2016-07-29T12:00:00-05:00", "2016-07-29T12:00:00-05:00", "FBI Receives Downer Info from Legat", "Probably legat London", EVENT_TYPE_FBI )
def main():
t = truxton.create()
create_event_type(t, EVENT_TYPE_FBI, "FBI Actions" )
media = add_media(t)
root_file = media.addroot()
root_file.save()
add_ec(root_file)
if __name__ == "__main__":
main()