Difference between revisions of "TruxtonMessage"

From truxwiki.com
Jump to navigation Jump to search
Line 4: Line 4:
 
==<code>depotid</code>==
 
==<code>depotid</code>==
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the depot file that stores the contents of the file.
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the depot file that stores the contents of the file.
This identifier corresponds to the <code>ID</code> column of the <code>Depot</code> table.
+
This identifier corresponds to the <code>[ID]</code> column of the <code>[Depot]</code> table.
  
 
==<code>depotlength</code>==
 
==<code>depotlength</code>==
 
The number of bytes in the depot file that make up this file's contents.
 
The number of bytes in the depot file that make up this file's contents.
This corresponds to the <code>Length</code> column of the <code>Content</code> table.
+
This corresponds to the <code>[Length]</code> column of the <code>[Content]</code> table.
  
 
==<code>depotname</code>==
 
==<code>depotname</code>==
 
The name of the depot that contains the file's contents.
 
The name of the depot that contains the file's contents.
 +
This corresponds to the <code>[Filename]</code> column of the <code>[Depot]</code> table.
  
 
==<code>depotoffset</code>==
 
==<code>depotoffset</code>==
 
The offset into the depot where the first byte of the file resides.
 
The offset into the depot where the first byte of the file resides.
This corresponds to the <code>Offset</code> column of the <code>Content</code> table.
+
This corresponds to the <code>[Offset]</code> column of the <code>[Content]</code> table.
  
 
==<code>dontroute</code>==
 
==<code>dontroute</code>==
Line 26: Line 27:
 
==<code>fileid</code>==
 
==<code>fileid</code>==
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file.
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file.
This identifier corresponds to the <code>ID</code> column of the <code>File</code> table.
+
This identifier corresponds to the <code>[ID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>filetype</code>==
 
==<code>filetype</code>==
 
The [[File Types Supported|type of the file]].
 
The [[File Types Supported|type of the file]].
This corresponds to the <code>FileTypeID</code> column of the <code>File</code> table.
+
This corresponds to the <code>[FileTypeID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>hash</code>==
 
==<code>hash</code>==
 
The [https://en.wikipedia.org/wiki/MD5 MD5] hash of the contents of the file.
 
The [https://en.wikipedia.org/wiki/MD5 MD5] hash of the contents of the file.
This corresponds to the <code>HashID</code> column of the <code>File</code> table.
+
This corresponds to the <code>[HashID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>media()</code>==
 
==<code>media()</code>==
Line 41: Line 42:
 
==<code>mediaid</code>==
 
==<code>mediaid</code>==
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file.
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file.
This identifier corresponds to the <code>MediaID</code> column of the <code>File</code> table.
+
This identifier corresponds to the <code>[MediaID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>parentid</code>==
 
==<code>parentid</code>==
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file.
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file.
This identifier corresponds to the <code>ParentID</code> column of the <code>File</code> table.
+
This identifier corresponds to the <code>[ParentID]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
==<code>priority</code>==
 
==<code>priority</code>==
Line 60: Line 61:
 
==<code>routeid</code>==
 
==<code>routeid</code>==
 
This integer represents the path that files should take through the exploitation processes.
 
This integer represents the path that files should take through the exploitation processes.
It should be a value in the <code>LoadConfigurationID</code> column of the <code>[[ETLRoute Table | ETLRoute]]</code> table.
+
It should be a value in the <code>[LoadConfigurationID]</code> column of the <code><nowiki>[</nowiki>[[ETLRoute Table|ETLRoute]]<nowiki>]</nowiki></code> table.
  
 
==<code>signature</code>==
 
==<code>signature</code>==
 
The first four bytes of the file stored as an integer.
 
The first four bytes of the file stored as an integer.
This corresponds to the <code>Signature</code> column of the <code>File</code> table.
+
This corresponds to the <code>[Signature]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
=Sample=
 
=Sample=

Revision as of 06:20, 1 December 2020

This class encapsulates the message object that is the basis for the Truxton's ETL pipeline.

Attributes and Methods

depotid

This is the GUID of the depot file that stores the contents of the file. This identifier corresponds to the [ID] column of the [Depot] table.

depotlength

The number of bytes in the depot file that make up this file's contents. This corresponds to the [Length] column of the [Content] table.

depotname

The name of the depot that contains the file's contents. This corresponds to the [Filename] column of the [Depot] table.

depotoffset

The offset into the depot where the first byte of the file resides. This corresponds to the [Offset] column of the [Content] table.

dontroute

This integer controls whether the message should be further routed through the message bus. This is usually only set when debugging an ETL process.

file()

This method will return a read-only file that you can use to read the contents of the file.

fileid

This is the GUID of the file. This identifier corresponds to the [ID] column of the [File] table.

filetype

The type of the file. This corresponds to the [FileTypeID] column of the [File] table.

hash

The MD5 hash of the contents of the file. This corresponds to the [HashID] column of the [File] table.

media()

Retrieves the media object associated with this message.

mediaid

This is the GUID of the file. This identifier corresponds to the [MediaID] column of the [File] table.

parentid

This is the GUID of the file. This identifier corresponds to the [ParentID] column of the [File] table.

priority

This integer value controls the prioriy of the message. High values have greater priority than lower values.

queueempty

This integer tells you if your message queue is empty. When this value is non-zero, the message queue is empty.

route()

This method will send the message using the current route to the message bus.

routeid

This integer represents the path that files should take through the exploitation processes. It should be a value in the [LoadConfigurationID] column of the [ETLRoute] table.

signature

The first four bytes of the file stored as an integer. This corresponds to the [Signature] column of the [File] table.

Sample

import truxton

def main():
  etl = truxton.etl()
  etl.name = "My New ETL"
  etl.description = "This ETL processes files in the Truxton system"
  etl.queue = "anewetl"
  etl.stage = 40
  etl.expanderid = 0x05fc0bf6a57726a0
  etl.version = 0
  etl.depot = "thumbnail"
  etl.depotype = truxton.DEPOT_TYPE_THUMBNAILS
  etl.poly = 0

  etl.addarg("--verbose")
  etl.addarg("Yes")

  etl.sendmefileid("5ecbebc4-9937-2b88-f691-91a800000024")
  etl.sendmehash("baa51f0cc8361660df911e06e7637485")
  etl.sendmefiles(truxton.Type_JPEGWithExif, 100)
  etl.sendmefiles(truxton.Type_TIFFWithExif, 500)
  etl.sendmelocalfile( "C:/Test Files/Video/Fragmented/Recovered Video.mp4", truxton.Type_MPEG4Video, 0 )

  message = etl.getmessage()

  while message is not None:
    file_in_truxton = message.file()

    # YOUR FORENSIC CODE GOES HERE

    line_of_text = file_in_truxton.readline()

    if "[SetupAPI" in line_of_text:
      child = file_in_truxton.newchild()
      child.name = "Child file from New ETL"
      child.write("This is the file you were looking for.")
      child.save()

    message.type = 11000;
    message.route()

    # Pause here until we get another message from the "anewetl" message queue
    message = etl.getmessage()

if __name__ == "__main__":
  main()