Difference between revisions of "Truxton group set created"

From truxwiki.com
Jump to navigation Jump to search
(Created page with "This sets the time the group was created. This corresponds to the <code>[Created]</code> column of the <code>[Group]</code> table. =Syntax= <source lang="C"> void truxton_gro...")
 
 
Line 15: Line 15:
  
 
=Sample=
 
=Sample=
<source lang="C" highlight="34">
+
<source lang="C" highlight="25">
 
void create_my_things(uint64_t investigation_handle)
 
void create_my_things(uint64_t investigation_handle)
 
{
 
{
Line 40: Line 40:
 
     }
 
     }
  
    FILETIME now;
+
     truxton_group_set_created( group_handle, truxton_time_now() );
 
 
    GetSystemTimePreciseAsFileTime( &now );
 
 
 
    ULARGE_INTEGER ticks;
 
 
 
    ticks.LowPart = now.dwLowDateTime;
 
    ticks.HighPart = now.dwHighDateTime;
 
 
 
     truxton_group_set_created( group_handle, ticks.QuadPart );
 
 
 
 
     truxton_group_destroy( group_handle );
 
     truxton_group_destroy( group_handle );
 
}
 
}
 
</source>
 
</source>

Latest revision as of 17:00, 13 April 2024

This sets the time the group was created. This corresponds to the [Created] column of the [Group] table.

Syntax

void truxton_group_set_created( uint64_t group_handle, uint64_t ticks );

Parameters

group_handle

The handle created by truxton_group_create() or truxton_investigation_create_group().

ticks

The date in FILETIME ticks.

Sample

void create_my_things(uint64_t investigation_handle)
{
    if (investigation_handle == 0)
    {
        return;
    }

    uint64_t truxton_handle = truxton_investigation_get_truxton( investigation_handle );
    uint64_t group_handle = truxton_group_create( truxton_handle );
 
    truxton_group_set_id( group_handle, "47726F75-7020-5361-6D70-6C65636F6465" );
    truxton_group_set_name( group_handle, "My Things" );
    truxton_group_set_description( group_handle, "These are my things" );
    truxton_group_set_is_default( group_handle, 1 );
    truxton_group_set_type( group_handle, GROUP_TYPE_USER );

    if ( truxton_group_save( group_handle ) != 0 )
    {
        char guid[MINIMUM_GUID_STRING_BUFFER_SIZE + 5];

        truxton_group_get_id( group_handle, guid, sizeof(guid) );
        truxton_investigation_set_active_group_id( investigation_handle, guid );
    }

    truxton_group_set_created( group_handle, truxton_time_now() );
    truxton_group_destroy( group_handle );
}