Difference between revisions of "TruxtonEXIF"

From truxwiki.com
Jump to navigation Jump to search
Line 87: Line 87:
 
The offset into the file where the model was found.
 
The offset into the file where the model was found.
  
==<code>save() -> bool</code>==
+
==<code>save() -> boolean</code>==
 
This will commit the information to the <code><nowiki>[</nowiki>[[EXIF Table|EXIF]]<nowiki>]</nowiki></code> table.
 
This will commit the information to the <code><nowiki>[</nowiki>[[EXIF Table|EXIF]]<nowiki>]</nowiki></code> table.
 
It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error.
 
It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error.
Line 97: Line 97:
 
The offset into the file where shutter count was found.
 
The offset into the file where shutter count was found.
  
==<code>tag(tag: str, reason: str, origin: int) -> bool</code>==
+
==<code>tag(tag: str, reason: str, origin: int) -> boolean</code>==
 
This creates a tag associated with this camera information in Truxton.
 
This creates a tag associated with this camera information in Truxton.
 
The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI.
 
The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI.

Revision as of 16:59, 16 September 2022

This class lets you add to the [EXIF] table in Truxton. Truxton will store any information about an imaging device it can find in this table. This information may not come from Exif sections of the exploited file. If the same information is embedded using a different format, the fields of the [EXIF] table will still be filled with that data. Just because there's a record in the [EXIF] doesn't mean that data came from an Exif blob.

Attributes and Methods

altitude: float

The altitude in meters.

altitudeoffset: int

The offset into the file where the altitude was found.

bodyserialnumber: str

The serial number of the body of the imaging device.

bodyserialnumberoffset: int

The offset into the file where the body serial number was found

devicetime: int

The timestamp of the image taken from the clock of the imaging device in FILETIME ticks.

devicetimeoffset: int

The offset into the file where the device time was found.

fileid: str

The GUID of the file this camera information came from. This corresponds to the [FileID] column of the [EXIF] table.

focallength: int

The focal length of the lens in 35mm equivalent.

focallengthoffset: int

The offset in the file where focal length was found.

gpstime: int

The timestamp from a GPS unit in the imaging device in FILETIME ticks.

gpstimeoffset: int

The offset in the file where the GPS time was found.

heading: float

The compass heading of the image. The direction the camera was pointing when the image was taken.

headingoffset: int

The offset into the file where the heading was found.

id: str

This is the GUID of the record. It becomes non-zero after save() has been called. This corresponds to the [ID] column of the [EXIF] table.

latitude: float

The latitude portion of the geographic coordinate using the WGS84 ellipsoid.

latitudeoffset: int

The offset into the file where the latitude was found.

lensserialnumber: str

The serial number of the lens.

lensserialnumberoffset: int

The offset into the file where the lens serial number was found.

longitude: float

The longitude portion of the geographic coordinate using the WGS84 ellipsoid. Many thanks go to John Harrison for his work.

longitudeoffset: int

The offset into the file where longitude was found.

make: str

The manufacturer of the imaging device.

makeoffset: int

The offset into the file where the make was found.

mediaid: str

This is the GUID of the media this artifact came from. This corresponds to the [MediaID] column of the [EXIF] table.

model: str

The model of the imaging device.

modeloffset: int

The offset into the file where the model was found.

save() -> boolean

This will commit the information to the [EXIF] table. It will return True if the record was saved to the database, False if there was an error.

shuttercount: int

The number of times the shutter has been activated on the imaging device.

shuttercountoffset: int

The offset into the file where shutter count was found.

tag(tag: str, reason: str, origin: int) -> boolean

This creates a tag associated with this camera information in Truxton. The tag parameter is a short, one or two word, bit of text that will be displayed in the UI. The reason a sentence explaining why this camera information was tagged. The origin is either TAG_ORIGIN_AUTOMATIC (1) or TAG_ORIGIN_HUMAN (2). It will return True if the tag was associated with the camera information, False on failure.

thumbnaillength: int

The length of the thumbnail of this image.

thumbnaillengthoffset: int

The offset in the file where the length of the thumbnail image was found.

thumbnailoffset: int

The offset of the thumbnail image.

thumbnailoffsetoffset: int

The offset in the file where thumbnail offset was found.

Sample

import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil

from datetime import datetime
from calendar import timegm
from pathlib import Path

EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000

def date_to_filetime(dt):
  return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)

def add_file(parent_truxton_file, filename):
  source_file = open(filename, "rb")
  child = parent_truxton_file.newchild()
  child.name = Path(filename).name
  shutil.copyfileobj(source_file, child)
  source_file.close()
  child.save()
  return child

def add_media(t):
  media = t.newmedia()

  media.name = "Public Documents"
  media.description = "Publicly available documents"
  media.case = "DC-SNAFU-2016.2020"
  media.evidencebag = "EV-0937459386623-a"
  media.originator = "Jeffrey Jensen"
  media.latitude = 38.897661
  media.longitude = -77.036458
  media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
  media.save()

  return media

def add_cs(parent_file ):
  child_file = add_file(parent_file, "cs.jpg")

  exif = child_file.newexif()
  exif.latitude = 51.487329
  exif.longitude = -0.124057
  exif.make = "Universal"
  exif.model = "Minute 16"
  exif.devicetime = date_to_filetime(datetime.fromisoformat("2016-04-01T12:00:00-05:00"))
  exif.save()

def main():
  t = truxton.create()

  media = add_media(t)

  root_file = media.addroot()
  root_file.save()

  add_cs(root_file)

if __name__ == "__main__":
  main()