Difference between revisions of "TruxtonEXIF"
(→save()) |
(→Sample) |
||
| (13 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
| − | This class lets you add to the [[EXIF Table | EXIF]] table in Truxton. | + | This class lets you add to the <code><nowiki>[</nowiki>[[EXIF Table|EXIF]]<nowiki>]</nowiki></code> table in Truxton. |
| + | Truxton will store any information about an imaging device it can find in this table. | ||
| + | This information may not come from [https://en.wikipedia.org/wiki/Exif Exif] sections of the exploited file. | ||
| + | If the same information is embedded using a different format, the fields of the <code><nowiki>[</nowiki>[[EXIF Table|EXIF]]<nowiki>]</nowiki></code> table will still be filled with that data. | ||
| + | Just because there's a record in the <code><nowiki>[</nowiki>[[EXIF Table|EXIF]]<nowiki>]</nowiki></code> doesn't mean that data came from an [https://en.wikipedia.org/wiki/Exif Exif] blob. | ||
| + | |||
=Attributes and Methods= | =Attributes and Methods= | ||
| + | ==<code>addnote(text: str) -> boolean</code>== | ||
| + | This adds an investigator's note. | ||
| + | The <code>text</code> parameter is the contents of the note. | ||
| + | It will return | ||
| + | [https://docs.python.org/3.10/library/constants.html?highlight=false#True True] if the tag was associated with the EXIF, [https://docs.python.org/3.10/library/constants.html?highlight=false#False False] on failure. | ||
| + | The note is stored in the <code>[InvestigatorNote]</code> table in the database. | ||
| − | + | ==<code>altitude: float</code>== | |
| − | ==<code>altitude</code>== | ||
The altitude in meters. | The altitude in meters. | ||
| − | ==<code>altitudeoffset</code>== | + | ==<code>altitudeoffset: int</code>== |
The offset into the file where the altitude was found. | The offset into the file where the altitude was found. | ||
| − | ==<code>bodyserialnumber</code>== | + | ==<code>bodyserialnumber: str</code>== |
The serial number of the body of the imaging device. | The serial number of the body of the imaging device. | ||
| − | ==<code>bodyserialnumberoffset</code>== | + | ==<code>bodyserialnumberoffset: int</code>== |
The offset into the file where the body serial number was found | The offset into the file where the body serial number was found | ||
| − | ==<code>devicetime</code>== | + | ==<code>devicetime: [https://docs.python.org/3/library/datetime.html datetime]</code>== |
| − | The timestamp of the image taken from the clock of the imaging device | + | The timestamp of the image taken from the clock of the imaging device. |
| + | This value can be set with either a datetime value or an integer representing [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | ||
| − | ==<code>devicetimeoffset</code>== | + | ==<code>devicetimeoffset: int</code>== |
The offset into the file where the device time was found. | The offset into the file where the device time was found. | ||
| − | ==<code>fileid</code>== | + | ==<code>fileid: str</code>== |
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this camera information came from. | The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this camera information came from. | ||
| − | This corresponds to the <code>FileID</code> column of the [[EXIF Table | < | + | This corresponds to the <code>[FileID]</code> column of the <code><nowiki>[</nowiki>[[EXIF Table|EXIF]]<nowiki>]</nowiki></code> table. |
| − | ==<code>focallength</code>== | + | ==<code>focallength: int</code>== |
The focal length of the lens in [https://en.wikipedia.org/wiki/35_mm_equivalent_focal_length 35mm equivalent.] | The focal length of the lens in [https://en.wikipedia.org/wiki/35_mm_equivalent_focal_length 35mm equivalent.] | ||
| − | ==<code>focallengthoffset</code>== | + | ==<code>focallengthoffset: int</code>== |
The offset in the file where focal length was found. | The offset in the file where focal length was found. | ||
| − | ==<code>gpstime</code>== | + | ==<code>gpstime: [https://docs.python.org/3/library/datetime.html datetime]</code>== |
| − | The timestamp from a [https://en.wikipedia.org/wiki/Global_Positioning_System GPS] unit in the imaging device | + | The timestamp from a [https://en.wikipedia.org/wiki/Global_Positioning_System GPS] unit in the imaging device. |
| + | This value can be set with either a datetime value or an integer representing [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | ||
| − | ==<code>gpstimeoffset</code>== | + | ==<code>gpstimeoffset: int</code>== |
The offset in the file where the [https://en.wikipedia.org/wiki/Global_Positioning_System GPS] time was found. | The offset in the file where the [https://en.wikipedia.org/wiki/Global_Positioning_System GPS] time was found. | ||
| − | ==<code>heading</code>== | + | ==<code>heading: float</code>== |
The compass heading of the image. | The compass heading of the image. | ||
The direction the camera was pointing when the image was taken. | The direction the camera was pointing when the image was taken. | ||
| − | ==<code>headingoffset</code>== | + | ==<code>headingoffset: int</code>== |
The offset into the file where the heading was found. | The offset into the file where the heading was found. | ||
| − | ==<code>id</code>== | + | ==<code>id: str</code>== |
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the record. | This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the record. | ||
It becomes non-zero after <code>save()</code> has been called. | It becomes non-zero after <code>save()</code> has been called. | ||
| − | This corresponds to the <code>ID</code> column of the [[EXIF Table | < | + | This corresponds to the <code>[ID]</code> column of the <code><nowiki>[</nowiki>[[EXIF Table|EXIF]]<nowiki>]</nowiki></code> table. |
| − | ==<code>latitude</code>== | + | ==<code>latitude: float</code>== |
The [https://en.wikipedia.org/wiki/Latitude latitude] portion of the geographic coordinate using the [https://en.wikipedia.org/wiki/World_Geodetic_System#WGS84 WGS84] ellipsoid. | The [https://en.wikipedia.org/wiki/Latitude latitude] portion of the geographic coordinate using the [https://en.wikipedia.org/wiki/World_Geodetic_System#WGS84 WGS84] ellipsoid. | ||
| − | ==<code>latitudeoffset</code>== | + | ==<code>latitudeoffset: int</code>== |
The offset into the file where the latitude was found. | The offset into the file where the latitude was found. | ||
| − | ==<code>lensserialnumber</code>== | + | ==<code>lensserialnumber: str</code>== |
The serial number of the lens. | The serial number of the lens. | ||
| − | ==<code>lensserialnumberoffset</code>== | + | ==<code>lensserialnumberoffset: int</code>== |
The offset into the file where the lens serial number was found. | The offset into the file where the lens serial number was found. | ||
| − | ==<code>longitude</code>== | + | ==<code>longitude: float</code>== |
The [https://en.wikipedia.org/wiki/Longitude longitude] portion of the geographic coordinate using the [https://en.wikipedia.org/wiki/World_Geodetic_System#WGS84 WGS84] ellipsoid. | The [https://en.wikipedia.org/wiki/Longitude longitude] portion of the geographic coordinate using the [https://en.wikipedia.org/wiki/World_Geodetic_System#WGS84 WGS84] ellipsoid. | ||
Many thanks go to [https://en.wikipedia.org/wiki/John_Harrison John Harrison] for his work. | Many thanks go to [https://en.wikipedia.org/wiki/John_Harrison John Harrison] for his work. | ||
| − | ==<code>longitudeoffset</code>== | + | ==<code>longitudeoffset: int</code>== |
The offset into the file where longitude was found. | The offset into the file where longitude was found. | ||
| − | ==<code>make</code>== | + | ==<code>make: str</code>== |
The manufacturer of the imaging device. | The manufacturer of the imaging device. | ||
| − | ==<code>makeoffset</code>== | + | ==<code>makeoffset: int</code>== |
The offset into the file where the make was found. | The offset into the file where the make was found. | ||
| − | ==<code>mediaid</code>== | + | ==<code>mediaid: str</code>== |
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media this artifact came from. | This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media this artifact came from. | ||
| − | This corresponds to the <code>[MediaID]</code> column of the <code><nowiki>[</nowiki>[[ | + | This corresponds to the <code>[MediaID]</code> column of the <code><nowiki>[</nowiki>[[EXIF Table|EXIF]]<nowiki>]</nowiki></code> table. |
| − | ==<code>model</code>== | + | ==<code>model: str</code>== |
The model of the imaging device. | The model of the imaging device. | ||
| − | ==<code>modeloffset</code>== | + | ==<code>modeloffset: int</code>== |
The offset into the file where the model was found. | The offset into the file where the model was found. | ||
| − | ==<code>save()</code>== | + | ==<code>save() -> boolean</code>== |
| − | This will commit the information to the <code><nowiki>[</nowiki>[[ | + | This will commit the information to the <code><nowiki>[</nowiki>[[EXIF Table|EXIF]]<nowiki>]</nowiki></code> table. |
It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error. | It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error. | ||
| − | ==<code>shuttercount</code>== | + | ==<code>shuttercount: int</code>== |
The number of times the shutter has been activated on the imaging device. | The number of times the shutter has been activated on the imaging device. | ||
| − | ==<code>shuttercountoffset</code>== | + | ==<code>shuttercountoffset: int</code>== |
The offset into the file where shutter count was found. | The offset into the file where shutter count was found. | ||
| − | ==<code>tag(tag, reason, origin)</code>== | + | ==<code>tag(tag: str, reason: str, origin: int) -> boolean</code>== |
This creates a tag associated with this camera information in Truxton. | This creates a tag associated with this camera information in Truxton. | ||
The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI. | The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI. | ||
| Line 100: | Line 112: | ||
The <code>origin</code> is either <code>TAG_ORIGIN_AUTOMATIC</code> (1) or <code>TAG_ORIGIN_HUMAN</code> (2). | The <code>origin</code> is either <code>TAG_ORIGIN_AUTOMATIC</code> (1) or <code>TAG_ORIGIN_HUMAN</code> (2). | ||
It will return | It will return | ||
| − | [https://docs.python.org/3. | + | [https://docs.python.org/3.10/library/constants.html?highlight=false#True True] if the tag was associated with the camera information, [https://docs.python.org/3.10/library/constants.html?highlight=false#False False] on failure. |
| − | ==<code>thumbnaillength</code>== | + | ==<code>thumbnaillength: int</code>== |
The length of the thumbnail of this image. | The length of the thumbnail of this image. | ||
| − | ==<code>thumbnaillengthoffset</code>== | + | ==<code>thumbnaillengthoffset: int</code>== |
The offset in the file where the length of the thumbnail image was found. | The offset in the file where the length of the thumbnail image was found. | ||
| − | ==<code>thumbnailoffset</code>== | + | ==<code>thumbnailoffset: int</code>== |
The offset of the thumbnail image. | The offset of the thumbnail image. | ||
| − | ==<code>thumbnailoffsetoffset</code>== | + | ==<code>thumbnailoffsetoffset: int</code>== |
The offset in the file where thumbnail offset was found. | The offset in the file where thumbnail offset was found. | ||
=Sample= | =Sample= | ||
| − | + | <source lang="Python" highlight="37-43"> | |
| − | < | + | import sys |
| + | sys.path.append('C:/Program Files/Truxton/SDK') | ||
import truxton | import truxton | ||
import shutil | import shutil | ||
| Line 123: | Line 136: | ||
from calendar import timegm | from calendar import timegm | ||
from pathlib import Path | from pathlib import Path | ||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
def add_file(parent_truxton_file, filename): | def add_file(parent_truxton_file, filename): | ||
| − | |||
child = parent_truxton_file.newchild() | child = parent_truxton_file.newchild() | ||
child.name = Path(filename).name | child.name = Path(filename).name | ||
| − | shutil.copyfileobj(source_file, child | + | with open(filename, "rb") as source_file: |
| − | + | shutil.copyfileobj(source_file, child) | |
child.save() | child.save() | ||
| + | |||
return child | return child | ||
| Line 162: | Line 169: | ||
exif.make = "Universal" | exif.make = "Universal" | ||
exif.model = "Minute 16" | exif.model = "Minute 16" | ||
| − | exif.devicetime = | + | exif.devicetime = datetime.fromisoformat("2016-04-01T12:00:00-05:00") |
exif.save() | exif.save() | ||
| Line 176: | Line 183: | ||
if __name__ == "__main__": | if __name__ == "__main__": | ||
| − | main() | + | sys.exit(main()) |
| − | </ | + | </source> |
Latest revision as of 14:17, 11 September 2024
This class lets you add to the [EXIF] table in Truxton.
Truxton will store any information about an imaging device it can find in this table.
This information may not come from Exif sections of the exploited file.
If the same information is embedded using a different format, the fields of the [EXIF] table will still be filled with that data.
Just because there's a record in the [EXIF] doesn't mean that data came from an Exif blob.
Contents
- 1 Attributes and Methods
- 1.1 addnote(text: str) -> boolean
- 1.2 altitude: float
- 1.3 altitudeoffset: int
- 1.4 bodyserialnumber: str
- 1.5 bodyserialnumberoffset: int
- 1.6 devicetime: datetime
- 1.7 devicetimeoffset: int
- 1.8 fileid: str
- 1.9 focallength: int
- 1.10 focallengthoffset: int
- 1.11 gpstime: datetime
- 1.12 gpstimeoffset: int
- 1.13 heading: float
- 1.14 headingoffset: int
- 1.15 id: str
- 1.16 latitude: float
- 1.17 latitudeoffset: int
- 1.18 lensserialnumber: str
- 1.19 lensserialnumberoffset: int
- 1.20 longitude: float
- 1.21 longitudeoffset: int
- 1.22 make: str
- 1.23 makeoffset: int
- 1.24 mediaid: str
- 1.25 model: str
- 1.26 modeloffset: int
- 1.27 save() -> boolean
- 1.28 shuttercount: int
- 1.29 shuttercountoffset: int
- 1.30 tag(tag: str, reason: str, origin: int) -> boolean
- 1.31 thumbnaillength: int
- 1.32 thumbnaillengthoffset: int
- 1.33 thumbnailoffset: int
- 1.34 thumbnailoffsetoffset: int
- 2 Sample
Attributes and Methods
addnote(text: str) -> boolean
This adds an investigator's note.
The text parameter is the contents of the note.
It will return
True if the tag was associated with the EXIF, False on failure.
The note is stored in the [InvestigatorNote] table in the database.
altitude: float
The altitude in meters.
altitudeoffset: int
The offset into the file where the altitude was found.
bodyserialnumber: str
The serial number of the body of the imaging device.
bodyserialnumberoffset: int
The offset into the file where the body serial number was found
devicetime: datetime
The timestamp of the image taken from the clock of the imaging device. This value can be set with either a datetime value or an integer representing FILETIME ticks.
devicetimeoffset: int
The offset into the file where the device time was found.
fileid: str
The GUID of the file this camera information came from.
This corresponds to the [FileID] column of the [EXIF] table.
focallength: int
The focal length of the lens in 35mm equivalent.
focallengthoffset: int
The offset in the file where focal length was found.
gpstime: datetime
The timestamp from a GPS unit in the imaging device. This value can be set with either a datetime value or an integer representing FILETIME ticks.
gpstimeoffset: int
The offset in the file where the GPS time was found.
heading: float
The compass heading of the image. The direction the camera was pointing when the image was taken.
headingoffset: int
The offset into the file where the heading was found.
id: str
This is the GUID of the record.
It becomes non-zero after save() has been called.
This corresponds to the [ID] column of the [EXIF] table.
latitude: float
The latitude portion of the geographic coordinate using the WGS84 ellipsoid.
latitudeoffset: int
The offset into the file where the latitude was found.
lensserialnumber: str
The serial number of the lens.
lensserialnumberoffset: int
The offset into the file where the lens serial number was found.
longitude: float
The longitude portion of the geographic coordinate using the WGS84 ellipsoid. Many thanks go to John Harrison for his work.
longitudeoffset: int
The offset into the file where longitude was found.
make: str
The manufacturer of the imaging device.
makeoffset: int
The offset into the file where the make was found.
mediaid: str
This is the GUID of the media this artifact came from.
This corresponds to the [MediaID] column of the [EXIF] table.
model: str
The model of the imaging device.
modeloffset: int
The offset into the file where the model was found.
save() -> boolean
This will commit the information to the [EXIF] table.
It will return True if the record was saved to the database, False if there was an error.
shuttercount: int
The number of times the shutter has been activated on the imaging device.
shuttercountoffset: int
The offset into the file where shutter count was found.
tag(tag: str, reason: str, origin: int) -> boolean
This creates a tag associated with this camera information in Truxton.
The tag parameter is a short, one or two word, bit of text that will be displayed in the UI.
The reason a sentence explaining why this camera information was tagged.
The origin is either TAG_ORIGIN_AUTOMATIC (1) or TAG_ORIGIN_HUMAN (2).
It will return
True if the tag was associated with the camera information, False on failure.
thumbnaillength: int
The length of the thumbnail of this image.
thumbnaillengthoffset: int
The offset in the file where the length of the thumbnail image was found.
thumbnailoffset: int
The offset of the thumbnail image.
thumbnailoffsetoffset: int
The offset in the file where thumbnail offset was found.
Sample
import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil
from datetime import datetime
from calendar import timegm
from pathlib import Path
def add_file(parent_truxton_file, filename):
child = parent_truxton_file.newchild()
child.name = Path(filename).name
with open(filename, "rb") as source_file:
shutil.copyfileobj(source_file, child)
child.save()
return child
def add_media(t):
media = t.newmedia()
media.name = "Public Documents"
media.description = "Publicly available documents"
media.case = "DC-SNAFU-2016.2020"
media.evidencebag = "EV-0937459386623-a"
media.originator = "Jeffrey Jensen"
media.latitude = 38.897661
media.longitude = -77.036458
media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
media.save()
return media
def add_cs(parent_file ):
child_file = add_file(parent_file, "cs.jpg")
exif = child_file.newexif()
exif.latitude = 51.487329
exif.longitude = -0.124057
exif.make = "Universal"
exif.model = "Minute 16"
exif.devicetime = datetime.fromisoformat("2016-04-01T12:00:00-05:00")
exif.save()
def main():
t = truxton.create()
media = add_media(t)
root_file = media.addroot()
root_file.save()
add_cs(root_file)
if __name__ == "__main__":
sys.exit(main())