Difference between revisions of "Truxton child file create relation"

From truxwiki.com
Jump to navigation Jump to search
(Created page with "This creates a relation object sourced from this file that you can use in the Relation API. A relation object is how you add records to the <code>...")
 
 
(4 intermediate revisions by the same user not shown)
Line 1: Line 1:
This creates a relation object sourced from this file that you can use in the [[Truxton C API#Relation | Relation API.]]
+
This creates a relation object sourced from this file that you can use in the [[Truxton C API#Relation|Relation API.]]
A relation object is how you add records to the <code>[[Relation Table | Relation]]</code> table.
+
A relation object is how you add records to the <code><nowiki>[</nowiki>[[Relation Table|Relation]]<nowiki>]</nowiki></code> table.
The resulting event object will automatically be associated with the file it was created from and with the media the file belongs to.
+
The resulting object will automatically be associated with the file it was created from and with the media the file belongs to.
  
 
=Syntax=
 
=Syntax=
<syntaxhighlight lang="C">
+
<source lang="C">
 
uint64_t truxton_child_file_create_relation( uint64_t child_handle );
 
uint64_t truxton_child_file_create_relation( uint64_t child_handle );
</syntaxhighlight>
+
</source>
  
 
=Parameters=
 
=Parameters=
 
==<code>child_handle</code>==
 
==<code>child_handle</code>==
 
 
The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call.
 
The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call.
  
Line 17: Line 16:
  
 
=Sample=
 
=Sample=
 
+
<source lang="C" highlight="33">
<syntaxhighlight lang="C" highlight="26">
+
void add_folder( uint64_t truxton, uint64_t parent_file )
void add_folder(uint64_t truxton, uint64_t parent_file)
 
 
{
 
{
   truxton_start_adding_files(truxton);
+
   truxton_start_adding_files( truxton );
  
   uint64_t child = truxton_child_file_create(truxton);
+
   uint64_t child = truxton_child_file_create( truxton );
  
 
   char id[40];
 
   char id[40];
  
   truxton_file_get_id(parent_file, id, sizeof(id));
+
   truxton_file_get_id( parent_file, id, sizeof(id) );
   truxton_child_file_set_parent_id(child, id);
+
   truxton_child_file_set_parent_id( child, id );
   truxton_child_file_set_type(child, Type_Directory);
+
   truxton_child_file_set_type( child, Type_Directory );
   truxton_child_file_set_name(child, "Custom Exploits Folder");
+
   truxton_child_file_set_name( child, "Custom Exploits Folder ");
  
   truxton_child_file_set_origin(child, ORIGIN_GENERATED);
+
   truxton_child_file_set_origin( child, ORIGIN_GENERATED );
  
   if ( truxton_child_file_save(child) == 0 )
+
   if ( truxton_child_file_save( child ) == 0 )
 
   {
 
   {
 
       printf( "Failed to add child to Truxton\n" );
 
       printf( "Failed to add child to Truxton\n" );
 
   }
 
   }
  else
 
  {
 
      ticks.QuadPart = truxton_child_file_get_disk_offset(child_file);
 
      printf( "Physical Disk Offset was %d\n", ticks.QuadPart );
 
  }
 
  
   uint64_t location = truxton_child_file_create_location(child);
+
   uint64_t artifact_1 = truxton_child_file_create_artifact( child );
 +
 
 +
  truxton_artifact_set_type( artifact_1, ENTITY_TYPE_EMAIL_ADDRESS );
 +
  truxton_artifact_set_value( artifact_1, "mdyson@cyberdynesystems.com" );
 +
  truxton_artifact_save( artifact_1 );
 +
 
 +
  uint64_t artifact_2 = truxton_child_file_create_artifact( child );
 +
 
 +
  truxton_artifact_set_type( artifact_2, ENTITY_TYPE_PERSON );
 +
  truxton_artifact_set_value( artifact_2, "Miles Dyson" );
 +
  truxton_artifact_save( artifact_2 );
 +
 
 +
  uint64_t relation = truxton_child_file_create_relation( child_file );
 +
 
 +
  char identifier[40];
 +
 
 +
  truxton_artifact_get_id( artifact_1, identifier, sizeof(identifier) );
 +
  truxton_relation_set_a_id( relation, identifier );
 +
  truxton_relation_set_a_type( relation, OBJECT_TYPE_ENTITY );
 +
 
 +
  truxton_artifact_get_id( artifact_2, identifier, sizeof(identifier) );
 +
  truxton_relation_set_b_id( relation, identifier );
 +
  truxton_relation_set_b_type( relation, OBJECT_TYPE_ENTITY );
 +
 
 +
  truxton_relation_set_relation( relation, RELATION_MESSAGE_ADDRESS );
  
   truxton_location_set_latitude(location, 18.30305549975252);
+
   truxton_relation_save( relation );
  truxton_location_set_longitude(location, -64.824006192214);
 
  truxton_location_set_altitude(location, 1.1);
 
  truxton_location_set_type(location, LOCATION_TYPE_GOPRO_VIDEO);
 
  truxton_location_save(location);
 
  truxton_location_destroy(location);
 
  
   truxton_child_file_destroy(child);
+
  truxton_relation_destroy( relation );
 +
  truxton_artifact_destroy( artifact_1 );
 +
  truxton_artifact_destroy( artifact_2 );
 +
   truxton_child_file_destroy( child );
 
}
 
}
</syntaxhighlight>
+
</source>

Latest revision as of 04:27, 13 February 2021

This creates a relation object sourced from this file that you can use in the Relation API. A relation object is how you add records to the [Relation] table. The resulting object will automatically be associated with the file it was created from and with the media the file belongs to.

Syntax

uint64_t truxton_child_file_create_relation( uint64_t child_handle );

Parameters

child_handle

The handle created by the truxton_child_file_create or truxton_file_create_child call.

Return value

A handle to relation object.

Sample

void add_folder( uint64_t truxton, uint64_t parent_file )
{
   truxton_start_adding_files( truxton );

   uint64_t child = truxton_child_file_create( truxton );

   char id[40];

   truxton_file_get_id( parent_file, id, sizeof(id) );
   truxton_child_file_set_parent_id( child, id );
   truxton_child_file_set_type( child, Type_Directory );
   truxton_child_file_set_name( child, "Custom Exploits Folder ");

   truxton_child_file_set_origin( child, ORIGIN_GENERATED );

   if ( truxton_child_file_save( child ) == 0 )
   {
      printf( "Failed to add child to Truxton\n" );
   }

   uint64_t artifact_1 = truxton_child_file_create_artifact( child );

   truxton_artifact_set_type( artifact_1, ENTITY_TYPE_EMAIL_ADDRESS );
   truxton_artifact_set_value( artifact_1, "mdyson@cyberdynesystems.com" );
   truxton_artifact_save( artifact_1 );

   uint64_t artifact_2 = truxton_child_file_create_artifact( child );

   truxton_artifact_set_type( artifact_2, ENTITY_TYPE_PERSON );
   truxton_artifact_set_value( artifact_2, "Miles Dyson" );
   truxton_artifact_save( artifact_2 );

   uint64_t relation = truxton_child_file_create_relation( child_file );

   char identifier[40];

   truxton_artifact_get_id( artifact_1, identifier, sizeof(identifier) );
   truxton_relation_set_a_id( relation, identifier );
   truxton_relation_set_a_type( relation, OBJECT_TYPE_ENTITY );

   truxton_artifact_get_id( artifact_2, identifier, sizeof(identifier) );
   truxton_relation_set_b_id( relation, identifier );
   truxton_relation_set_b_type( relation, OBJECT_TYPE_ENTITY );

   truxton_relation_set_relation( relation, RELATION_MESSAGE_ADDRESS );

   truxton_relation_save( relation );

   truxton_relation_destroy( relation );
   truxton_artifact_destroy( artifact_1 );
   truxton_artifact_destroy( artifact_2 );
   truxton_child_file_destroy( child );
}