Difference between revisions of "TruxtonUSB"
(→Sample) |
|||
| (12 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
| − | This class lets you add to the [[USBDevice Table | USBDevice]] table in Truxton. | + | This class lets you add to the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table in Truxton. |
=Attributes and Methods= | =Attributes and Methods= | ||
| − | ==deviceid== | + | ==<code>addnote(text: str) -> boolean</code>== |
| + | This adds an investigator's note. | ||
| + | The <code>text</code> parameter is the contents of the note. | ||
| + | It will return | ||
| + | [https://docs.python.org/3.10/library/constants.html?highlight=false#True True] if the tag was associated with the device, [https://docs.python.org/3.10/library/constants.html?highlight=false#False False] on failure. | ||
| + | The note is stored in the <code>[InvestigatorNote]</code> table in the database. | ||
| + | |||
| + | ==<code>deviceid: str</code>== | ||
A [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] assigned to the device by Windows. | A [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] assigned to the device by Windows. | ||
| − | ==devicetype== | + | ==<code>devicetype: int</code>== |
| − | This corresponds to the <code>USBDeviceTypeID</code> column of the <code>USBDevice</code> table. | + | This corresponds to the <code>[USBDeviceTypeID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table. |
| − | It should be a value from the <code>ID</code> column of the <code>USBDeviceType</code> table. | + | It should be a value from the <code>[ID]</code> column of the <code>[USBDeviceType]</code> table. |
| + | Not used at this time. | ||
| − | ==<code>fileid</code>== | + | ==<code>fileid: str</code>== |
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this device came from. | The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this device came from. | ||
| − | This corresponds to the <code>FileID</code> column of the [[USBDevice Table | < | + | This corresponds to the <code>[FileID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table. |
| − | ==<code>id</code>== | + | ==<code>id: str</code>== |
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the record. | This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the record. | ||
It becomes non-zero after <code>save()</code> has been called. | It becomes non-zero after <code>save()</code> has been called. | ||
| − | This corresponds to the <code>ID</code> column of the [[USBDevice Table | < | + | This corresponds to the <code>[ID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table. |
| − | ==<code>mediaid</code>== | + | ==<code>mediaid: str</code>== |
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media this device came from. | This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media this device came from. | ||
| − | This corresponds to the <code>MediaID</code> column of the [[USBDevice Table | < | + | This corresponds to the <code>[MediaID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table. |
| − | ==offset== | + | ==<code>offset: int</code>== |
The offset into the file where this device was found. | The offset into the file where this device was found. | ||
| − | This corresponds to the <code>Offset</code> column of the [[USBDevice Table | < | + | This corresponds to the <code>[Offset]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table. |
| − | ==productid== | + | ==<code>productid: int</code>== |
The product id of the device. | The product id of the device. | ||
| − | This corresponds to the <code>PID</code> column of the [[USBDevice Table | < | + | This corresponds to the <code>[PID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table. |
| − | This may contain a value in the <code>PID</code> column of the <code>USBPIDVID</code> table. | + | This may contain a value in the <code>[PID]</code> column of the <code>[USBPIDVID]</code> table. |
| − | ==revision== | + | ==<code>revision: int</code>== |
| + | The revision of the device. | ||
| − | ==<code>save()</code>== | + | ==<code>save() -> boolean</code>== |
| − | This will commit the information to the [[USBDevice Table | < | + | This will commit the information to the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table. |
It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error. | It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error. | ||
| − | ==<code>tag(tag, reason, origin)</code>== | + | ==<code>tag(tag: str, reason: str, origin: int) -> boolean</code>== |
This creates a tag associated with this device in Truxton. | This creates a tag associated with this device in Truxton. | ||
The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI. | The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI. | ||
| − | The <code>reason</code> a sentence explaining why this device was tagged. | + | The <code>reason</code> is a sentence explaining why this device was tagged. |
The <code>origin</code> is either <code>TAG_ORIGIN_AUTOMATIC</code> (1) or <code>TAG_ORIGIN_HUMAN</code> (2). | The <code>origin</code> is either <code>TAG_ORIGIN_AUTOMATIC</code> (1) or <code>TAG_ORIGIN_HUMAN</code> (2). | ||
It will return | It will return | ||
[https://docs.python.org/3.8/library/constants.html?highlight=false#True True] if the tag was associated with the device, [https://docs.python.org/3.8/library/constants.html?highlight=false#False False] on failure. | [https://docs.python.org/3.8/library/constants.html?highlight=false#True True] if the tag was associated with the device, [https://docs.python.org/3.8/library/constants.html?highlight=false#False False] on failure. | ||
| − | ==vendorid== | + | ==<code>vendorid: int</code>== |
The [https://en.wikipedia.org/wiki/USB_Implementers_Forum#Obtaining_a_vendor_ID vendor id] (VID) of the device. | The [https://en.wikipedia.org/wiki/USB_Implementers_Forum#Obtaining_a_vendor_ID vendor id] (VID) of the device. | ||
| − | This corresponds to the <code>VID</code> column of the [[USBDevice Table | < | + | This corresponds to the <code>[VID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table. |
| − | ==<code>when</code>== | + | ==<code>when: [https://docs.python.org/3/library/datetime.html datetime]</code>== |
| − | The time associated with this device | + | The time associated with this device. |
| + | This value can be set with either a datetime value or an integer representing [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | ||
=Sample= | =Sample= | ||
| − | + | <source lang="Python" highlight="39-43"> | |
| − | < | + | import sys |
| + | sys.path.append('C:/Program Files/Truxton/SDK') | ||
import truxton | import truxton | ||
import shutil | import shutil | ||
| Line 61: | Line 72: | ||
from calendar import timegm | from calendar import timegm | ||
from pathlib import Path | from pathlib import Path | ||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
def add_file(parent_truxton_file, filename): | def add_file(parent_truxton_file, filename): | ||
| Line 93: | Line 98: | ||
def add_cs(parent_file ): | def add_cs(parent_file ): | ||
| − | child_file = add_file(parent_file, " | + | child_file = add_file(parent_file, "480057685-2020-10-13-Submission-SJC-SSCI-Part-2-of-2.pdf") |
| + | |||
| + | # Now add the SanDisk Cruzer Glide 8GB | ||
| + | |||
| + | thumbdrive = child_file.newusb() | ||
| + | thumbdrive.vid = 1921 | ||
| + | thumbdrive.pid = 21808 | ||
| + | thumbdrive.when = datetime.fromisoformat("2016-12-20T11:00:00-05:00") | ||
| + | thumbdrive.save() | ||
| − | + | return None | |
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
def main(): | def main(): | ||
| Line 112: | Line 119: | ||
add_cs(root_file) | add_cs(root_file) | ||
| + | |||
| + | return None | ||
if __name__ == "__main__": | if __name__ == "__main__": | ||
| − | main() | + | sys.exit(main()) |
| − | </ | + | </source> |
Latest revision as of 15:15, 27 January 2024
This class lets you add to the [USBDevice] table in Truxton.
Contents
Attributes and Methods
addnote(text: str) -> boolean
This adds an investigator's note.
The text parameter is the contents of the note.
It will return
True if the tag was associated with the device, False on failure.
The note is stored in the [InvestigatorNote] table in the database.
deviceid: str
A GUID assigned to the device by Windows.
devicetype: int
This corresponds to the [USBDeviceTypeID] column of the [USBDevice] table.
It should be a value from the [ID] column of the [USBDeviceType] table.
Not used at this time.
fileid: str
The GUID of the file this device came from.
This corresponds to the [FileID] column of the [USBDevice] table.
id: str
This is the GUID of the record.
It becomes non-zero after save() has been called.
This corresponds to the [ID] column of the [USBDevice] table.
mediaid: str
This is the GUID of the media this device came from.
This corresponds to the [MediaID] column of the [USBDevice] table.
offset: int
The offset into the file where this device was found.
This corresponds to the [Offset] column of the [USBDevice] table.
productid: int
The product id of the device.
This corresponds to the [PID] column of the [USBDevice] table.
This may contain a value in the [PID] column of the [USBPIDVID] table.
revision: int
The revision of the device.
save() -> boolean
This will commit the information to the [USBDevice] table.
It will return True if the record was saved to the database, False if there was an error.
tag(tag: str, reason: str, origin: int) -> boolean
This creates a tag associated with this device in Truxton.
The tag parameter is a short, one or two word, bit of text that will be displayed in the UI.
The reason is a sentence explaining why this device was tagged.
The origin is either TAG_ORIGIN_AUTOMATIC (1) or TAG_ORIGIN_HUMAN (2).
It will return
True if the tag was associated with the device, False on failure.
vendorid: int
The vendor id (VID) of the device.
This corresponds to the [VID] column of the [USBDevice] table.
when: datetime
The time associated with this device. This value can be set with either a datetime value or an integer representing FILETIME ticks.
Sample
import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil
from datetime import datetime
from calendar import timegm
from pathlib import Path
def add_file(parent_truxton_file, filename):
source_file = open(filename, "rb")
child = parent_truxton_file.newchild()
child.name = Path(filename).name
shutil.copyfileobj(source_file, child)
source_file.close()
child.save()
return child
def add_media(t):
media = t.newmedia()
media.name = "Public Documents"
media.description = "Publicly available documents"
media.case = "DC-SNAFU-2016.2020"
media.evidencebag = "EV-0937459386623-a"
media.originator = "Jeffrey Jensen"
media.latitude = 38.897661
media.longitude = -77.036458
media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
media.save()
return media
def add_cs(parent_file ):
child_file = add_file(parent_file, "480057685-2020-10-13-Submission-SJC-SSCI-Part-2-of-2.pdf")
# Now add the SanDisk Cruzer Glide 8GB
thumbdrive = child_file.newusb()
thumbdrive.vid = 1921
thumbdrive.pid = 21808
thumbdrive.when = datetime.fromisoformat("2016-12-20T11:00:00-05:00")
thumbdrive.save()
return None
def main():
t = truxton.create()
media = add_media(t)
root_file = media.addroot()
root_file.save()
add_cs(root_file)
return None
if __name__ == "__main__":
sys.exit(main())