Difference between revisions of "TruxtonChildFileIO"
(→Sample) |
|||
| (18 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
This class provides a writable file to add to Truxton. | This class provides a writable file to add to Truxton. | ||
| + | =IOBase Methods= | ||
From [https://docs.python.org/3/library/io.html#io.IOBase IOBase] it implements: | From [https://docs.python.org/3/library/io.html#io.IOBase IOBase] it implements: | ||
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.close close()] | + | * [https://docs.python.org/3/library/io.html#io.IOBase.close close()] - Flush and close this stream |
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.closed closed] | + | * [https://docs.python.org/3/library/io.html#io.IOBase.closed closed] - [https://docs.python.org/3/library/constants.html#True True] if the stream is closed |
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.fileno fileno()] - | + | * [https://docs.python.org/3/library/io.html#io.IOBase.fileno fileno()] - Truxton will return ERROR |
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.flush flush()] | + | * [https://docs.python.org/3/library/io.html#io.IOBase.flush flush()] - Flush the write buffers of the stream if applicable |
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.isatty isatty()] | + | * [https://docs.python.org/3/library/io.html#io.IOBase.isatty isatty()] - Return [https://docs.python.org/3/library/constants.html#True True] if the stream is interactive |
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.readable readable()] - | + | * [https://docs.python.org/3/library/io.html#io.IOBase.readable readable()] - Truxton always returns [https://docs.python.org/3/library/constants.html#False False] |
* [https://docs.python.org/3/library/io.html#io.IOBase.readline readline()] - Do not use, will return ERROR | * [https://docs.python.org/3/library/io.html#io.IOBase.readline readline()] - Do not use, will return ERROR | ||
* [https://docs.python.org/3/library/io.html#io.IOBase.readlines readlines()] - Do not use, will return ERROR | * [https://docs.python.org/3/library/io.html#io.IOBase.readlines readlines()] - Do not use, will return ERROR | ||
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.seek seek()] - | + | * [https://docs.python.org/3/library/io.html#io.IOBase.seek seek()] - Truxton will return ERROR |
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.seekable seekable()] - returns | + | * [https://docs.python.org/3/library/io.html#io.IOBase.seekable seekable()] - Truxton always returns [https://docs.python.org/3/library/constants.html#False False] |
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.tell tell()] | + | * [https://docs.python.org/3/library/io.html#io.IOBase.tell tell()] - Return the current stream position |
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.truncate truncate()] | + | * [https://docs.python.org/3/library/io.html#io.IOBase.truncate truncate()] - Resize the stream |
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.writable writable()] - returns | + | * [https://docs.python.org/3/library/io.html#io.IOBase.writable writable()] - Truxton always returns [https://docs.python.org/3/library/constants.html#True True] |
| − | * [https://docs.python.org/3/library/io.html#io.IOBase.writelines writelines()] | + | * [https://docs.python.org/3/library/io.html#io.IOBase.writelines writelines()] - Write a list of lines to the stream |
| + | =RawIOBase Methods= | ||
From [https://docs.python.org/3/library/io.html#io.RawIOBase RawIOBase] it implements: | From [https://docs.python.org/3/library/io.html#io.RawIOBase RawIOBase] it implements: | ||
| Line 25: | Line 27: | ||
* [https://docs.python.org/3/library/io.html#io.RawIOBase.write write()] | * [https://docs.python.org/3/library/io.html#io.RawIOBase.write write()] | ||
| + | =Truxton Methods= | ||
The above methods will let you read from a file in Truxton as if it were any other file in Python. | The above methods will let you read from a file in Truxton as if it were any other file in Python. | ||
The following methods are also present to make tasks of adding items extracted from a file easier. | The following methods are also present to make tasks of adding items extracted from a file easier. | ||
| − | * [[ | + | * [[TruxtonChildFileIO addnote|addnote()]] |
| − | * [[ | + | * [[TruxtonChildFileIO newartifact|newartifact()]] |
| − | * [[ | + | * [[TruxtonChildFileIO newchild|newchild()]] |
| − | * [[ | + | * [[TruxtonChildFileIO newcommunication|newcommunication()]] |
| − | * [[ | + | * [[TruxtonChildFileIO newevent|newevent()]] |
| − | * [[ | + | * [[TruxtonChildFileIO newexif|newexif()]] |
| − | * [[ | + | * [[TruxtonChildFileIO newlocation|newlocation()]] |
| − | * [[ | + | * [[TruxtonChildFileIO newrelation|newrelation()]] |
| + | * [[TruxtonChildFileIO newurl|newurl()]] | ||
| + | * [[TruxtonChildFileIO newusb|newusb()]] | ||
| + | * [[TruxtonChildFileIO tag|tag()]] | ||
| + | =Properties= | ||
| + | |||
| + | ==<code>accessed: [https://docs.python.org/3/library/datetime.html datetime]</code>== | ||
| + | When the file was last accessed. | ||
| + | This value can be set with either a datetime value or an integer representing [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | ||
| + | |||
| + | ==<code>attributes: int</code>== | ||
| + | An integer value representing the attributes of the file. | ||
| + | For a Microsoft filesystem, it can be a combination of the [https://docs.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants file attribute flags.] | ||
| + | |||
| + | ==<code>created: [https://docs.python.org/3/library/datetime.html datetime]</code>== | ||
| + | When the file was created. | ||
| + | This value can be set with either a datetime value or an integer representing [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | ||
| + | |||
| + | ==<code>diskoffset: int</code>== | ||
| + | The offset, in bytes, of the first byte of the contents of the file on the physical disk. | ||
| + | |||
| + | ==<code>entropy: float</code>== | ||
| + | [[Truxton_child_file_get_entropy|Shannon's entropy]] of the contents of the file. | ||
| + | |||
| + | ==<code>hash: str</code>== | ||
| + | The [https://en.wikipedia.org/wiki/MD5 MD5] hash of the contents of the file. | ||
| + | |||
| + | ==<code>id: str</code>== | ||
| + | The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file record. | ||
| + | This is valid once <code>save()</code> has been called. | ||
| + | |||
| + | ==<code>mediaid: str</code>== | ||
| + | The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media the child file came from. | ||
| + | |||
| + | ==<code>modified: [https://docs.python.org/3/library/datetime.html datetime]</code>== | ||
| + | When the file was last written. | ||
| + | This value can be set with either a datetime value or an integer representing [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | ||
| + | |||
| + | ==<code>name: str</code>== | ||
| + | The name of the file. | ||
| + | |||
| + | ==<code>origin: int</code>== | ||
| + | Where the file came from. | ||
| + | It should be one of the [[Origin|origin values.]] | ||
| + | |||
| + | ==<code>parentid: str</code>== | ||
| + | The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the parent of this file. | ||
| + | |||
| + | ==<code>save() -> true</code>== | ||
| + | This will commit the information to the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table. | ||
| + | It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error. | ||
| + | |||
| + | ==<code>size: int</code>== | ||
| + | The size, in bytes, of the file. | ||
| + | |||
| + | ==<code>status: int</code>== | ||
| + | The status of the contents of the file. | ||
| + | It should be one of the [[Content Status|content status values.]] | ||
| + | |||
| + | ==<code>type: int</code>== | ||
| + | The [[File Types Supported|type]] of the file. | ||
=Sample= | =Sample= | ||
This will retrieve a file from Truxton, print the name and hash as stored in the database then calculate a hash on the contents and print that. | This will retrieve a file from Truxton, print the name and hash as stored in the database then calculate a hash on the contents and print that. | ||
| − | < | + | <source lang="Python"> |
| + | import sys | ||
| + | sys.path.append('C:/Program Files/Truxton/SDK') | ||
import truxton | import truxton | ||
| − | import | + | import shutil |
| + | from pathlib import Path | ||
| + | |||
| + | def add_file(parent_truxton_file, filename): | ||
| + | child = parent_truxton_file.newchild() | ||
| + | with open(filename, "rb") as source_file: | ||
| + | child.name = Path(filename).name | ||
| + | shutil.copyfileobj(source_file, child) | ||
| + | child.save() | ||
| + | return child | ||
def main(): | def main(): | ||
t = truxton.create() | t = truxton.create() | ||
| − | + | with t.getfileid("66e0fd95-aafe-b0a4-dade-fde000000065") as file: | |
| − | + | child = add_file(file, "C:/decrypts/PlainText.txt") | |
| − | |||
| − | |||
| − | |||
if __name__ == "__main__": | if __name__ == "__main__": | ||
| − | main() | + | sys.exit(main()) |
| − | </ | + | </source> |
Latest revision as of 14:10, 11 September 2024
This class provides a writable file to add to Truxton.
IOBase Methods
From IOBase it implements:
- close() - Flush and close this stream
- closed - True if the stream is closed
- fileno() - Truxton will return ERROR
- flush() - Flush the write buffers of the stream if applicable
- isatty() - Return True if the stream is interactive
- readable() - Truxton always returns False
- readline() - Do not use, will return ERROR
- readlines() - Do not use, will return ERROR
- seek() - Truxton will return ERROR
- seekable() - Truxton always returns False
- tell() - Return the current stream position
- truncate() - Resize the stream
- writable() - Truxton always returns True
- writelines() - Write a list of lines to the stream
RawIOBase Methods
From RawIOBase it implements:
Truxton Methods
The above methods will let you read from a file in Truxton as if it were any other file in Python. The following methods are also present to make tasks of adding items extracted from a file easier.
- addnote()
- newartifact()
- newchild()
- newcommunication()
- newevent()
- newexif()
- newlocation()
- newrelation()
- newurl()
- newusb()
- tag()
Properties
accessed: datetime
When the file was last accessed. This value can be set with either a datetime value or an integer representing FILETIME ticks.
attributes: int
An integer value representing the attributes of the file. For a Microsoft filesystem, it can be a combination of the file attribute flags.
created: datetime
When the file was created. This value can be set with either a datetime value or an integer representing FILETIME ticks.
diskoffset: int
The offset, in bytes, of the first byte of the contents of the file on the physical disk.
entropy: float
Shannon's entropy of the contents of the file.
hash: str
The MD5 hash of the contents of the file.
id: str
The GUID of the file record.
This is valid once save() has been called.
mediaid: str
The GUID of the media the child file came from.
modified: datetime
When the file was last written. This value can be set with either a datetime value or an integer representing FILETIME ticks.
name: str
The name of the file.
origin: int
Where the file came from. It should be one of the origin values.
parentid: str
The GUID of the parent of this file.
save() -> true
This will commit the information to the [File] table.
It will return True if the record was saved to the database, False if there was an error.
size: int
The size, in bytes, of the file.
status: int
The status of the contents of the file. It should be one of the content status values.
type: int
The type of the file.
Sample
This will retrieve a file from Truxton, print the name and hash as stored in the database then calculate a hash on the contents and print that.
import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil
from pathlib import Path
def add_file(parent_truxton_file, filename):
child = parent_truxton_file.newchild()
with open(filename, "rb") as source_file:
child.name = Path(filename).name
shutil.copyfileobj(source_file, child)
child.save()
return child
def main():
t = truxton.create()
with t.getfileid("66e0fd95-aafe-b0a4-dade-fde000000065") as file:
child = add_file(file, "C:/decrypts/PlainText.txt")
if __name__ == "__main__":
sys.exit(main())