Difference between revisions of "TruxtonUSB"
| Line 32: | Line 32: | ||
==revision== | ==revision== | ||
| + | The revision of the device. | ||
==<code>save()</code>== | ==<code>save()</code>== | ||
Revision as of 04:06, 29 May 2020
This class lets you add to the USBDevice table in Truxton.
Contents
Attributes and Methods
deviceid
A GUID assigned to the device by Windows.
devicetype
This corresponds to the USBDeviceTypeID column of the USBDevice table.
It should be a value from the ID column of the USBDeviceType table.
fileid
The GUID of the file this device came from.
This corresponds to the FileID column of the USBDevice table.
id
This is the GUID of the record.
It becomes non-zero after save() has been called.
This corresponds to the ID column of the USBDevice table.
mediaid
This is the GUID of the media this device came from.
This corresponds to the MediaID column of the USBDevice table.
offset
The offset into the file where this device was found.
This corresponds to the Offset column of the USBDevice table.
productid
The product id of the device.
This corresponds to the PID column of the USBDevice table.
This may contain a value in the PID column of the USBPIDVID table.
revision
The revision of the device.
save()
This will commit the information to the USBDevice table.
It will return True if the record was saved to the database, False if there was an error.
tag(tag, reason, origin)
This creates a tag associated with this device in Truxton.
The tag parameter is a short, one or two word, bit of text that will be displayed in the UI.
The reason a sentence explaining why this device was tagged.
The origin is either TAG_ORIGIN_AUTOMATIC (1) or TAG_ORIGIN_HUMAN (2).
It will return
True if the tag was associated with the device, False on failure.
vendorid
The vendor id (VID) of the device.
This corresponds to the VID column of the USBDevice table.
when
The time associated with this device in FILETIME ticks.
Sample
import truxton
import shutil
from datetime import datetime
from calendar import timegm
from pathlib import Path
EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000
def date_to_filetime(dt):
return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)
def add_file(parent_truxton_file, filename):
source_file = open(filename, "rb")
child = parent_truxton_file.newchild()
child.name = Path(filename).name
shutil.copyfileobj(source_file, child)
source_file.close()
child.save()
return child
def add_media(t):
media = t.newmedia()
media.name = "Public Documents"
media.description = "Publicly available documents"
media.case = "DC-SNAFU-2016.2020"
media.evidencebag = "EV-0937459386623-a"
media.originator = "Jeffrey Jensen"
media.latitude = 38.897661
media.longitude = -77.036458
media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
media.save()
return media
def add_cs(parent_file ):
child_file = add_file(parent_file, "cs.jpg")
gps = child_file.newlocation()
gps.type = truxton.LOCATION_TYPE_MEETING
gps.latitude = 51.487329
gps.longitude = -0.124057
gps.label = "HQ"
gps.when= date_to_filetime(datetime.fromisoformat("2016-04-01T12:00:00-05:00"))
gps.save()
def main():
t = truxton.create()
media = add_media(t)
root_file = media.addroot()
root_file.save()
add_cs(root_file)
if __name__ == "__main__":
main()