Difference between revisions of "Truxton file create event"

From truxwiki.com
Jump to navigation Jump to search
(Created page with "This creates an event from this file that you can use in the Event API. An event object is how you add records to the <code> Event</...")
 
Line 15: Line 15:
 
A handle to an event object.
 
A handle to an event object.
  
=Sample=
+
<syntaxhighlight lang="C" highlight="5">
<syntaxhighlight lang="C" line highlight="14">
 
 
void process_file(uint64_t truxton)
 
void process_file(uint64_t truxton)
 
{
 
{
   truxton_start_adding_files(truxton);
+
   uint64_t file = truxton_file_open_md5(truxton, "9ec8fb6095c35eff2b236863b7caaf10");
  
  uint64_t child = truxton_child_file_create(truxton);
+
   uint64_t event = truxton_file_create_event(file);
 
 
  char id[40];
 
 
 
  truxton_file_get_id(parent_file, id, sizeof(id));
 
  truxton_child_file_set_parent_id(child, id);
 
  truxton_child_file_set_type(child, Type_Directory);
 
  truxton_child_file_set_name(child, "Custom Exploits Folder");
 
 
 
  truxton_child_file_set_origin(child, ORIGIN_GENERATED);
 
 
 
  if ( truxton_child_file_save(child) == 0 )
 
  {
 
      printf( "Failed to add child to Truxton\n" );
 
  }
 
 
 
   uint64_t event = truxton_child_file_create_event(child);
 
  
 
   truxton_event_set_type(event, EVENT_TYPE_POSSIBLE_INFECTION);
 
   truxton_event_set_type(event, EVENT_TYPE_POSSIBLE_INFECTION);
   truxton_event_set_start(event, truxton_file_get_created( parent_file ) );
+
   truxton_event_set_start(event, truxton_file_get_created( file ) );
   truxton_event_set_end(event, truxton_file_get_modified( parent_file ) );
+
   truxton_event_set_end(event, truxton_file_get_modified( file ) );
 
   truxton_event_set_title(event, "Fancy Bear Panda Hurricane" );
 
   truxton_event_set_title(event, "Fancy Bear Panda Hurricane" );
 
   truxton_event_set_description(event, "Russian Malware repurposed by Chinese military used in FBI investigation" );
 
   truxton_event_set_description(event, "Russian Malware repurposed by Chinese military used in FBI investigation" );
Line 47: Line 30:
 
   truxton_event_destroy(event);
 
   truxton_event_destroy(event);
  
   truxton_child_file_destroy(child);
+
   truxton_file_destroy(file);
 
}
 
}
 
</syntaxhighlight>
 
</syntaxhighlight>

Revision as of 17:17, 9 June 2020

This creates an event from this file that you can use in the Event API. An event object is how you add records to the Event table. The resulting event object will automatically be associated with the file it was created from and with the media the file belongs to.

Syntax

uint64_t truxton_file_create_event( uint64_t file_handle );

Parameters

file_handle

The handle created by the truxton_file_open_id or truxton_file_open_md5 call.

Return value

A handle to an event object.

void process_file(uint64_t truxton)
{
   uint64_t file = truxton_file_open_md5(truxton, "9ec8fb6095c35eff2b236863b7caaf10");

   uint64_t event = truxton_file_create_event(file);

   truxton_event_set_type(event, EVENT_TYPE_POSSIBLE_INFECTION);
   truxton_event_set_start(event, truxton_file_get_created( file ) );
   truxton_event_set_end(event, truxton_file_get_modified( file ) );
   truxton_event_set_title(event, "Fancy Bear Panda Hurricane" );
   truxton_event_set_description(event, "Russian Malware repurposed by Chinese military used in FBI investigation" );
   truxton_event_save(event);
   truxton_event_destroy(event);

   truxton_file_destroy(file);
}