Difference between revisions of "TruxtonMedia"
| Line 2: | Line 2: | ||
=Attributes and Methods= | =Attributes and Methods= | ||
| + | ==<code>addnote(text: str) -> boolean</code>== | ||
| + | This adds an investigator's note. | ||
| + | The <code>text</code> parameter is the contents of the note. | ||
| + | It will return | ||
| + | [https://docs.python.org/3.10/library/constants.html?highlight=false#True True] if the tag was associated with the media, [https://docs.python.org/3.10/library/constants.html?highlight=false#False False] on failure. | ||
| + | The note is stored in the <code>[InvestigatorNote]</code> table in the database. | ||
| + | |||
==<code>addroot() -> [[TruxtonChildFileIO]]</code>== | ==<code>addroot() -> [[TruxtonChildFileIO]]</code>== | ||
This method will create a root file in the media. | This method will create a root file in the media. | ||
Revision as of 07:27, 1 October 2022
This class represents a piece of media in Truxton.
Contents
- 1 Attributes and Methods
- 1.1 addnote(text: str) -> boolean
- 1.2 addroot() -> TruxtonChildFileIO
- 1.3 case: str
- 1.4 configid: int
- 1.5 created: int
- 1.6 description: str
- 1.7 evidencebag: str
- 1.8 expires: int
- 1.9 finished()
- 1.10 id: str
- 1.11 latitude: float
- 1.12 longitude: float
- 1.13 name: str
- 1.14 originator: str
- 1.15 percentcomplete: int
- 1.16 save() -> str
- 1.17 status: int
- 1.18 tag(tag: str, reason: str, origin: int) -> boolean
- 1.19 type: int
- 1.20 updated: int
- 2 Sample
Attributes and Methods
addnote(text: str) -> boolean
This adds an investigator's note.
The text parameter is the contents of the note.
It will return
True if the tag was associated with the media, False on failure.
The note is stored in the [InvestigatorNote] table in the database.
addroot() -> TruxtonChildFileIO
This method will create a root file in the media. All other files will ultimately be children of this file. The return value of this method is a child file object.
case: str
A case number for this media.
Even though media came in under one case doesn't mean it can't be part of another.
This corresponds to the [CaseNumber] column of the [Media] table.
configid: int
This is the path the media took through the exploitation process.
This corresponds to the [LoadConfigurationID] column of the [Media] table.
It should be set to one of the values in the [ID] column of the [LoadConfiguration] table or a predefined constant.
created: int
When the media was created in FILETIME ticks.
This corresponds to the [Created] column of the [Media] table.
description: str
A description of the media.
This corresponds to the [Description] column of the [Media] table.
evidencebag: str
A description of the media.
This corresponds to the [EvidenceBag] column of the [Media] table.
expires: int
When the media should be automatically purged from Truxton in FILETIME ticks.
This corresponds to the [Expires] column of the [Media] table.
By default, the expiration date of media is 99 years from the creation of the media.
finished()
Once media has been saved, if you have added any files to the media, call this method. It will update paths and child file counts.
id: str
A GUID for the media.
This corresponds to the [ID] column of the [Media] table.
latitude: float
The latitude portion of the geographic coordinate using the WGS84 ellipsoid of where this media was seized.
This corresponds to the [Latitude] column of the [Media] table.
longitude: float
The longitude portion of the geographic coordinate using the WGS84 ellipsoid of where this media was seized.
Many thanks go to John Harrison for his work.
This corresponds to the [Longitude] column of the [Media] table.
name: str
This is a human friendly name for the media.
This corresponds to the [Name] column of the [Media] table.
originator: str
The name of the organization or person who is responsible for this media.
For example, if you are a regional center, this would identify the originating organization that asked you to look at the media.
This corresponds to the [Originator] column of the [Media] table.
percentcomplete: int
An estimation of how far along the system is in the exploitation of this media.
This corresponds to the [PercentComplete] column of the [Media] table.
save() -> str
This will commit the information to the [Media] table.
It will return True if the record was saved to the database, False if there was an error.
status: int
The represents the status of the media.
This corresponds to the [MediaStatusID] column of the [Media] table.
It should be a value from the [ID] column of the [MediaStatus] table or a predefined constant.
tag(tag: str, reason: str, origin: int) -> boolean
This creates a tag associated with this media in Truxton.
The tag parameter is a short, one or two word, bit of text that will be displayed in the UI.
The reason a sentence explaining why this media was tagged.
The origin is either TAG_ORIGIN_AUTOMATIC (1) or TAG_ORIGIN_HUMAN (2).
It will return
True if the tag was associated with the media, False on failure.
type: int
The is an identifier for the type of media that was loaded.
This corresponds to the [MediaTypeID] column of the [Media] table.
It should be a value from the [ID] column of the [MediaType] table or a predefined constant.
updated: int
When the media was last updated in FILETIME ticks.
This corresponds to the [LastUpdated] column of the [Media] table.
Sample
import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil
from datetime import datetime
from calendar import timegm
from pathlib import Path
EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000
EVENT_TYPE_FBI = 20001
def date_to_filetime(dt):
return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)
def add_file(parent_truxton_file, filename):
source_file = open(filename, "rb")
child = parent_truxton_file.newchild()
child.name = Path(filename).name
shutil.copyfileobj(source_file, child)
source_file.close()
child.save()
return child
def add_media(t):
media = t.newmedia()
media.name = "Public Documents"
media.description = "Publicly available documents"
media.case = "DC-SNAFU-2016.2020"
media.evidencebag = "EV-0937459386623-a"
media.originator = "Jeffrey Jensen"
media.latitude = 38.897661
media.longitude = -77.036458
media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
media.save()
return media
def add_cs(parent_file ):
child_file = add_file(parent_file, "cs.jpg")
gps = child_file.newlocation()
gps.type = truxton.LOCATION_TYPE_MEETING
gps.latitude = 51.487329
gps.longitude = -0.124057
gps.label = "HQ"
gps.when= date_to_filetime(datetime.fromisoformat("2016-04-01T12:00:00-05:00"))
gps.save()
def create_investigation(t):
investigation = t.newinvestigation()
investigation.name = "Collusion"
investigation.description = "United States vs. John Smith"
investigation.case = "DC-SNAFU-2016.2020"
investigation.status = truxton.INVESTIGATION_STATUS_OPEN
investigation.type = truxton.INVESTIGATION_TYPE_FRAUD
investigation.save()
return investigation
def main():
t = truxton.create()
new_type = t.neweventtype()
new_type.id = EVENT_TYPE_FBI
new_type.name = "FBI Actions"
new_type.save()
investigation = create_investigation(t)
media = add_media(t)
root_file = media.addroot()
root_file.save()
investigation.addmedia(media.id)
add_cs(root_file)
if __name__ == "__main__":
main()