Difference between revisions of "TruxtonObject"

From truxwiki.com
Jump to navigation Jump to search
Line 4: Line 4:
  
 
==<code>closed</code>==
 
==<code>closed</code>==
Returns true if closed
+
It will return [https://docs.python.org/3/library/constants.html#True True] if the the connection to Truxton is closed, [https://docs.python.org/3/library/constants.html#False False] otherwise.
  
 
==<code>etlid</code>==
 
==<code>etlid</code>==
Returns the globally unqiue identifier of the ETL if it is running.
+
Returns the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the ETL if it is running.
  
 
==<code>machineid</code>==
 
==<code>machineid</code>==
Returns the globally unique identifier of the machine.
+
Returns the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the machine.
  
 
==<code>version</code>==
 
==<code>version</code>==
Line 16: Line 16:
  
 
==<code>createtag(name, description)</code>==
 
==<code>createtag(name, description)</code>==
This will commit the information to the [[Relation Table | <code>Relation</code>]] table.
+
This will create a new tag in Truxton.
It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error.
+
After calling this method, you can tag other items using only the <code>name</code>.
  
 
==<code>getfileid(id)</code>==
 
==<code>getfileid(id)</code>==
 +
This will retrieve a [[TruxtonFileIO | file]] from Truxton based on its [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID.]
 +
 
==<code>getfilehash(hash)</code>==
 
==<code>getfilehash(hash)</code>==
 +
This will retrieve a [[TruxtonFileIO | file]] from Truxton based on its [https://en.wikipedia.org/wiki/MD5 MD5] hash.
 +
 
==<code>neweventtype()</code>==
 
==<code>neweventtype()</code>==
 +
This will create an [[TruxtonEventType | event type]] object.
 +
 
==<code>newexporter()</code>==
 
==<code>newexporter()</code>==
 +
This will create an [[TruxtonExporter | exporter]] object.
 +
 
==<code>newinvestigation()</code>==
 
==<code>newinvestigation()</code>==
 +
This will create an [[TruxtonInvestigation | investigation]] object.
 +
 
==<code>newrelation()</code>==
 
==<code>newrelation()</code>==
 +
This will create a [[TruxtonRelation | relation]] object.
 +
 
==<code>newmedia()</code>==
 
==<code>newmedia()</code>==
 +
This will create a [[TruxtonMedia | media]] object.
  
 
=Sample=
 
=Sample=

Revision as of 11:23, 29 May 2020

This class give you access to Truxton at a global level.

Attributes and Methods

closed

It will return True if the the connection to Truxton is closed, False otherwise.

etlid

Returns the GUID of the ETL if it is running.

machineid

Returns the GUID of the machine.

version

Returns the version string.

createtag(name, description)

This will create a new tag in Truxton. After calling this method, you can tag other items using only the name.

getfileid(id)

This will retrieve a file from Truxton based on its GUID.

getfilehash(hash)

This will retrieve a file from Truxton based on its MD5 hash.

neweventtype()

This will create an event type object.

newexporter()

This will create an exporter object.

newinvestigation()

This will create an investigation object.

newrelation()

This will create a relation object.

newmedia()

This will create a media object.

Sample

import truxton
import shutil

from datetime import datetime
from calendar import timegm
from pathlib import Path

EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000

def date_to_filetime(dt):
  return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)

def create_event_type(t, id, name):
  event_type = t.neweventtype()
  event_type.id = id
  event_type.name = name
  event_type.save()

def add_file(parent_truxton_file, filename):
  source_file = open(filename, "rb")
  child = parent_truxton_file.newchild()
  child.name = Path(filename).name
  shutil.copyfileobj(source_file, child)
  source_file.close()
  child.save()

  return child

def add_media(t):
  media = t.newmedia()
  media.name = "Public Documents"
  media.description = "Publicly available documents"
  media.case = "DC-SNAFU-2016.2020"
  media.evidencebag = "EV-0937459386623-a"
  media.originator = "Jeffrey Jensen"
  media.latitude = 38.897661
  media.longitude = -77.036458
  media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
  media.save()

  return media

def add_ec(parent_file ):
  child_file = add_file(parent_file, "JW-v-DOJ-reply-02743.pdf")

  a = child_file.newartifact()
  a.type = truxton.ENTITY_TYPE_ACCOUNT
  a.value = "r0cker"
  a.datatype = truxton.DATA_TYPE_ASCII
  a.length = 6
  a.save()

  b = child_file.newartifact()
  b.type = truxton.ENTITY_TYPE_PERSON
  b.value = "Bob Smith"
  b.datatype = truxton.DATA_TYPE_ASCII
  b.length = 9
  b.save()

  relation = child_file.newrelation()
  relation.a = a.id
  relation.atype = truxton.OBJECT_TYPE_ENTITY
  relation.b = b.id
  relation.btype = truxton.OBJECT_TYPE_ENTITY
  relation.relation = truxton.RELATION_LOGON_ACCOUNT
  relation.save()

def main():
  t = truxton.create()

  media = add_media(t)

  root_file = media.addroot()
  root_file.save()

  add_ec(root_file)

if __name__ == "__main__":
  main()