Difference between revisions of "Truxton child file create artifact"

From truxwiki.com
Jump to navigation Jump to search
(Created page with "This creates an artifact from this file that you can use in the Artifact API. =Syntax= <syntaxhighlight lang="C"> uint64_t truxton_child_file_cre...")
 
 
(5 intermediate revisions by the same user not shown)
Line 1: Line 1:
 
This creates an artifact from this file that you can use in the [[Truxton C API#Artifacts | Artifact API.]]
 
This creates an artifact from this file that you can use in the [[Truxton C API#Artifacts | Artifact API.]]
 +
An artifact object is how you add records to the <code><nowiki>[</nowiki>[[Entity Table|Entity]]<nowiki>]</nowiki></code> table.
 +
 
=Syntax=
 
=Syntax=
<syntaxhighlight lang="C">
+
<source lang="C">
 
uint64_t truxton_child_file_create_artifact( uint64_t child_handle );
 
uint64_t truxton_child_file_create_artifact( uint64_t child_handle );
</syntaxhighlight>
+
</source>
  
 
=Parameters=
 
=Parameters=
 
==<code>child_handle</code>==
 
==<code>child_handle</code>==
 
 
The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call.
 
The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call.
  
 
=Return value=
 
=Return value=
 
A handle to an artifact object.
 
A handle to an artifact object.
 +
 
=Sample=
 
=Sample=
 
+
<source lang="C" highlight="27">
<syntaxhighlight lang="C" highlight="39">
+
void add_folder( uint64_t truxton, uint64_t parent_file )
void add_folder(uint64_t truxton, uint64_t parent_file)
 
 
{
 
{
   truxton_start_adding_files(truxton);
+
   truxton_start_adding_files( truxton );
  
   uint64_t child = truxton_child_file_create(truxton);
+
   uint64_t child = truxton_child_file_create( truxton );
  
 
   char id[40];
 
   char id[40];
  
   truxton_file_get_id(parent_file, id, sizeof(id));
+
   truxton_file_get_id( parent_file, id, sizeof(id) );
   truxton_child_file_set_parent_id(child, id);
+
   truxton_child_file_set_parent_id( child, id );
   truxton_child_file_set_type(child, Type_Directory);
+
   truxton_child_file_set_type( child, Type_Directory );
   truxton_child_file_set_name(child, "Custom Exploits Folder");
+
   truxton_child_file_set_name( child, "Custom Exploits Folder" );
  
   FILETIME now;
+
   uint64_t now = truxton_time_now();
  
   GetSystemTimeAsFileTime(&now);
+
   truxton_child_file_set_created( child, now );
 +
  truxton_child_file_set_accessed( child, now );
 +
  truxton_child_file_set_modified( child, now );
  
   ULARGE_INTEGER ticks;
+
   truxton_child_file_set_origin( child, ORIGIN_GENERATED );
  
  ticks.LowPart = now.dwLowDateTime;
+
   if ( truxton_child_file_save( child ) == 0 )
  ticks.HighPart = now.dwHighDateTime;
 
 
 
  truxton_child_file_set_created(child, ticks.QuadPart);
 
  truxton_child_file_set_accessed(child, ticks.QuadPart);
 
  truxton_child_file_set_modified(child, ticks.QuadPart);
 
 
 
  truxton_child_file_set_origin(child, ORIGIN_GENERATED);
 
 
 
   if ( truxton_child_file_save(child) == 0 )
 
 
   {
 
   {
 
       printf( "Failed to add child to Truxton\n" );
 
       printf( "Failed to add child to Truxton\n" );
  }
 
  else
 
  {
 
      ticks.QuadPart = truxton_child_file_get_disk_offset(child_file);
 
      printf( "Physical Disk Offset was %d\n", ticks.QuadPart );
 
 
   }
 
   }
  
   uint64_t artifact = truxton_child_file_create_artifact(child);
+
   uint64_t artifact = truxton_child_file_create_artifact( child );
  
   truxton_artifact_set_type(artifact, ENTITY_TYPE_SERIAL_NUMBER);
+
   truxton_artifact_set_type( artifact, ENTITY_TYPE_SERIAL_NUMBER );
   truxton_artifact_set_value(artifact, "1234" );
+
   truxton_artifact_set_value( artifact, "1234" );
   truxton_artifact_save(artifact);
+
   truxton_artifact_save( artifact );
 +
  truxton_artifact_destroy( artifact );
  
   truxton_child_file_destroy(child);
+
   truxton_child_file_destroy( child );
 
}
 
}
</syntaxhighlight>
+
</source>

Latest revision as of 02:47, 14 April 2024

This creates an artifact from this file that you can use in the Artifact API. An artifact object is how you add records to the [Entity] table.

Syntax

uint64_t truxton_child_file_create_artifact( uint64_t child_handle );

Parameters

child_handle

The handle created by the truxton_child_file_create or truxton_file_create_child call.

Return value

A handle to an artifact object.

Sample

void add_folder( uint64_t truxton, uint64_t parent_file )
{
   truxton_start_adding_files( truxton );

   uint64_t child = truxton_child_file_create( truxton );

   char id[40];

   truxton_file_get_id( parent_file, id, sizeof(id) );
   truxton_child_file_set_parent_id( child, id );
   truxton_child_file_set_type( child, Type_Directory );
   truxton_child_file_set_name( child, "Custom Exploits Folder" );

   uint64_t now = truxton_time_now();

   truxton_child_file_set_created( child, now );
   truxton_child_file_set_accessed( child, now );
   truxton_child_file_set_modified( child, now );

   truxton_child_file_set_origin( child, ORIGIN_GENERATED );

   if ( truxton_child_file_save( child ) == 0 )
   {
      printf( "Failed to add child to Truxton\n" );
   }

   uint64_t artifact = truxton_child_file_create_artifact( child );

   truxton_artifact_set_type( artifact, ENTITY_TYPE_SERIAL_NUMBER );
   truxton_artifact_set_value( artifact, "1234" );
   truxton_artifact_save( artifact );
   truxton_artifact_destroy( artifact );

   truxton_child_file_destroy( child );
}