Difference between revisions of "Truxton file get accessed"

From truxwiki.com
Jump to navigation Jump to search
 
Line 3: Line 3:
  
 
=Syntax=
 
=Syntax=
<syntaxhighlight lang="C">
+
<source lang="C">
 
uint64_t truxton_file_get_accessed( uint64_t file_handle );
 
uint64_t truxton_file_get_accessed( uint64_t file_handle );
</syntaxhighlight>
+
</source>
  
 
=Parameters=
 
=Parameters=
Line 15: Line 15:
  
 
=Sample=
 
=Sample=
<syntaxhighlight lang="C" highlight="10">
+
<source lang="C" highlight="10">
void print_id(uint64_t truxton)
+
void print_id( uint64_t truxton )
 
{
 
{
   uint64_t file = truxton_file_open_md5(truxton, "9ec8fb6095c35eff2b236863b7caaf10");
+
   uint64_t file = truxton_file_open_md5( truxton, "9ec8fb6095c35eff2b236863b7caaf10" );
  
 
   if ( file != 0 )
 
   if ( file != 0 )
Line 32: Line 32:
 
   }
 
   }
  
   truxton_file_free(file);
+
   truxton_file_free( file );
 
}
 
}
</syntaxhighlight>
+
</source>

Latest revision as of 17:36, 10 February 2021

This retrieves the last accessed date of the file. It corresponds to the [LastAccess] column of the [File] table.

Syntax

uint64_t truxton_file_get_accessed( uint64_t file_handle );

Parameters

file_handle

The handle created by the truxton_file_open_id or truxton_file_open_md5 call.

Return value

The last access date of the file in FILETIME ticks.

Sample

void print_id( uint64_t truxton )
{
   uint64_t file = truxton_file_open_md5( truxton, "9ec8fb6095c35eff2b236863b7caaf10" );

   if ( file != 0 )
   {
      return;
   }

   uint64_t ticks = truxton_file_get_accessed( file );

   if ( ticks == 0 )
   {
      printf( "Timestamp was not set\n" );
   }

   truxton_file_free( file );
}