Difference between revisions of "Truxton C API"
(→Media) |
(→URL) |
||
| Line 582: | Line 582: | ||
* [[truxton_url_get_url_offset]] - Retrieves the offset into the parent file where the URL was found | * [[truxton_url_get_url_offset]] - Retrieves the offset into the parent file where the URL was found | ||
* [[truxton_url_set_url_offset]] - Sets the offset into the parent file where the URL was found | * [[truxton_url_set_url_offset]] - Sets the offset into the parent file where the URL was found | ||
| − | * [[truxton_url_get_when]] - Retrieves the date and time of when the URL was visited | + | * [[truxton_url_get_when]] - Retrieves the date and time of when the URL was visited in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks |
| − | * [[truxton_url_set_when]] - Sets the date and time of when the URL was visited | + | * [[truxton_url_set_when]] - Sets the date and time of when the URL was visited in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks |
===Derived Objects=== | ===Derived Objects=== | ||
Revision as of 06:28, 15 February 2021
Truxton functionality is exposed to the C programming world as a DLL named TruxtonCAPI.dll in the C:\Program Files\Truxton\SDK folder.
This DLL can be called from any programming language that has the ability to make operating system calls.
Contents
- 1 Philosophy
- 2 Preparing for Use
- 3 API Groups
- 3.1 Initialization
- 3.2 Functions
- 3.3 Artifacts
- 3.4 Child Files
- 3.5 ETL Application Creation
- 3.6 Event
- 3.7 Event Type
- 3.8 EXIF (Camera Information)
- 3.9 File
- 3.10 File Export
- 3.11 File Type
- 3.12 Geographic Location
- 3.13 Media
- 3.14 Message
- 3.15 Options
- 3.16 Relation
- 3.17 Subject
- 3.18 URL
- 3.19 USB Device
Philosophy
The API is considered to be "flat" in that only integers and ASCII character strings are used in the interface. This was chosen to make it easy for other languages to call the API. The coding convention is all lower case names with underscores separating words. Truxton is a member of the east const posse.
Preparing for Use
Truxton does not ship a linker library for TruxtonCAPI.dll in order to free the developer to use any particular compiler.
If you want to link TruxtonCAPI.dll with your own C/C++ code, you will need to generate a linker library.
Alternatively, you can use a plugin pattern of calling LoadLibrary then many calls to GetProcAddress to get the function pointers.
This is a lot of work and very prone to errors.
Generating a Linker Library for Microsoft Compilers
You can download a free Visual Studio from Microsoft. The steps to produce a LIB file from a DLL are:
- Generate a module definition (DEF) file from
TruxtonCAPI.dll. - Use the DEF file to create the linker library (LIB) file.
Generate a Module Definition File
The following Powershell script will create the DEF file.
$dumpbin = "C:\Program Files (x86)\Microsoft Visual Studio\2019\Community\VC\Tools\MSVC\14.28.29333\bin\Hostx64\x64\dumpbin.exe"
$lines = (& $dumpbin /exports TruxtonCAPI.dll)
Write-Output "EXPORTS"
foreach ( $line in $lines )
{
if ( $line.Contains(" = ") -EQ $true )
{
Write-Output $line.SubString($line.IndexOf(" = ") + 3)
}
}
In your SDK folder, execute the script from Powershell:
MakeDef.ps1 >TruxtonCAPI.defGenerate a LIB File
Now that you have the DEF file, you can create the linker library using lib.exe (which is found in the same folder as dumpbin.exe) in the command window:
lib.exe /def:TruxtonCAPI.def /out:TruxtonCAPI.lib /machine:x64API Groups
The API is broken down into the different areas of Truxton.
Initialization
- truxton_start - Initializes Truxton
- truxton_stop - Uninitializes Truxton
Functions
- truxton_create - Creates a Truxton object
- truxton_destroy - Frees a Truxton object
- truxton_create_tag - Create a new type of tag
- truxton_get_device_id - Retrieves the BIOS Device identifier
- truxton_get_machine_id - Retrieves the Windows Machine identifier
- truxton_get_version - Retrieves the version of Truxton
- truxton_start_adding_files - Prepares Truxton to add files to the database
- truxton_route_message - Send a message to down-stream ETL processors
Artifacts
Artifacts are pieces of information that are also known as entities.
- truxton_artifact_create - Creates a new artifact object
- truxton_artifact_destroy - Destroys an existing artifact object
- truxton_artifact_save - Saves the artifact to the
[Entity]table in the database - truxton_artifact_get_data_type - Retrieves the raw data type
- truxton_artifact_set_data_type - Sets the raw data type
- truxton_artifact_get_file_id - Retrieves the identifier of the file the artifact was found in
- truxton_artifact_set_file_id - Sets the identifier of the file the artifact was found in
- truxton_artifact_get_id - After saving, retrieves the identifier of the artifact
- truxton_artifact_get_length - Retrieves the number of bytes in the raw data that make up this artifact
- truxton_artifact_set_length - Sets the number of bytes in the raw data that make up this artifact
- truxton_artifact_get_media_id - Retrieves the identifier of the media this artifact is in
- truxton_artifact_set_media_id - Sets the identifier of the media this artifact is in
- truxton_artifact_get_object_id - Retrieves the identifier of the object the artifact came from
- truxton_artifact_set_object_id - Sets the identifier of the object the artifact came from
- truxton_artifact_get_object_type - Retrieves the type of object the artifact came from
- truxton_artifact_set_object_type - Sets the type of object the artifact came from
- truxton_artifact_get_offset - Retrieves the offset in the file where the artifact came from
- truxton_artifact_set_offset - Sets the offset in the file where the artifact came from
- truxton_artifact_get_type - Retrieves the type of artifact
- truxton_artifact_set_type - Sets the type of the artifact
- truxton_artifact_get_value - Retrieves the value of the artifact
- truxton_artifact_set_value - Sets the value of the artifact
Derived Objects
The following APIs are used to create objects with an artifact as their parent.
- truxton_artifact_tag - Associating a tag with this artifact. This data will be saved to the
[Tagged]table.
Child Files
A child file is one that you have created and need to save in Truxton.
- truxton_child_file_create - Create a file object to save to Truxton
- truxton_child_file_destroy - Destroys a file object
- truxton_child_file_clear - Returns a file object to an initial state of all zeroes
- truxton_child_file_get_id - Retrieves the GUID of the child file
- truxton_child_file_set_id - Sets the GUID of the child file
- truxton_child_file_get_parent_id - Retrieves the GUID of the parent file
- truxton_child_file_set_parent_id - Sets the GUID of the parent of the child
- truxton_child_file_get_media_id - Retrieves the GUID of the media this child belongs to
- truxton_child_file_set_media_id - Sets the GUID of the media this child belongs to
- truxton_child_file_get_name - Retrieves the name of the file
- truxton_child_file_set_name - Sets the name of the file
- truxton_child_file_get_path - Retrieves the path of the file
- truxton_child_file_set_path - Sets the path of the file
- truxton_child_file_get_hash - Retrieves the MD5 hash (digital fingerprint) of the file's contents
- truxton_child_file_get_number_of_children - Retrieves the number of child files of this file
- truxton_child_file_set_number_of_children - Sets the number of child files of this file
- truxton_child_file_get_created - Retrieves the date and time of when the file was created in FILETIME ticks
- truxton_child_file_set_created - Sets the date and time of when the file was created in FILETIME ticks
- truxton_child_file_get_accessed - Retrieves the date and time of when the file was accessed in FILETIME ticks
- truxton_child_file_set_accessed - Sets the date and time of when the file was accessed in FILETIME ticks
- truxton_child_file_get_modified - Retrieves the date and time of when the file was modified (last written to) in FILETIME ticks
- truxton_child_file_set_modified - Sets the date and time of when the file was modified (last written to) in FILETIME ticks
- truxton_child_file_get_size - Retrieves the size of the file, in bytes, as reported by the operating system
- truxton_child_file_set_size - Sets the size of the file, in bytes, as reported by the operating system
- truxton_child_file_get_origin - Retrieves the origin of the file
- truxton_child_file_set_origin - Sets the origin of the file
- truxton_child_file_get_content_status - Retrieves the status of the contents of the file
- truxton_child_file_set_content_status - Sets the status of the contents of the file
- truxton_child_file_get_truxton - Retrieves the instance of Truxton this child belongs to
- truxton_child_file_begin_write - Prepares Truxton for writing contents to be associated with this file
- truxton_child_file_end_write - Tells Truxton to finish writing contents
- truxton_child_file_write - Gives Truxton bytes to store as the file contents
- truxton_child_file_save - Commits data to the database
- truxton_child_file_set_type - Sets the type of the file
- truxton_child_file_get_type - Retrieves the type of the file
- truxton_child_file_set_attributes - Sets the attributes of the file
- truxton_child_file_get_attributes - Retrieves the attributes of the file
- truxton_child_file_set_disk_offset - Sets the physical disk offset of the first byte of contents
- truxton_child_file_get_disk_offset - Retrieves the physical disk offset of the first byte of contents
- truxton_child_file_get_entropy - Retrieves the entropy of the file contents
Derived Objects
- truxton_child_file_create_artifact - Creates and associates an artifact with this file. The artifact will be saved to the
[Entity]table. - truxton_child_file_create_event - Creates and associates an event with this file. The event will be saved to the
[Event]table. - truxton_child_file_create_exif - Creates and associates camera information with this file. The data will be saved to the
[EXIF]table. - truxton_child_file_create_location - Creates and associates a geographic location with this file. The data will be saved to the
[Location]table. - truxton_child_file_create_relation - Creates a relationship with this file as the source. The data will be saved to the
[Relation]table. - truxton_child_file_create_url - Creates a website visit with this file as the source. This data will be saved to the
[WebsiteVisit]table. - truxton_child_file_create_usb - Creates a USB device with this file as the source. This data will be saved to the
[Entity]table. - truxton_child_file_tag - Creates a tag and puts it on this file. This data will be saved to the
[Tagged]table. - truxton_child_file_new_child - Creates a child of this file
ETL Application Creation
- truxton_etl_create - Creates a Truxton ETL object
- truxton_etl_destroy - Destroys a Truxton ETL object
- truxton_etl_add_command_line_argument - Adds a command line argument
- truxton_etl_add_desired_file_type - Tells Truxton what types of files you want to process
- truxton_etl_get_description - Retrieves the human readable description of this exploitation process
- truxton_etl_set_description - Sets a description that has meaning to another human about this exploitation process
- truxton_etl_get_message - Halts the execution of your program until a message arrives from your message queue
- truxton_etl_get_stage_number - Retreives the stage of this exploitation process
- truxton_etl_set_stage_number - Sets the stage at which this exploitation process should run
- truxton_etl_set_application_name - Sets the name of your application
- truxton_etl_set_depot_type - Sets the type of depot you want to use
- truxton_etl_set_depot_type_name - Sets a seed name for the type of depot you want to use
- truxton_etl_set_expander_identifier - Sets an identifier to use during reprocessing
- truxton_etl_set_expander_version - Sets a custom version of your process
- truxton_etl_set_mode - Sets the mode of the application
- truxton_etl_set_queue_name - Sets the name of the message queue for this process
- truxton_etl_set_thread_safe - Tells Truxton if it is safe to use your message handler in a multi-threaded fashion
- truxton_etl_set_poly_file_expander - Tells Truxton you are a file expander that needs multiple source files
Debugging
- truxton_etl_send_me_file_id - Puts a message in your queue given a GUID that matches the
[ID]column of the[File]table. - truxton_etl_send_me_files - Put a specified number messages in your queue of a particular file type.
- truxton_etl_send_me_hash - Put one file that matches an MD5 hash.
- truxton_etl_send_me_local_file - Put a specified file on your system into your message queue.
Event
If you need to save a significant place in time, use the following functions.
The data structure these API encapsulate is similar to the one used in the event message.
These will create a record in the [Event] table.
- truxton_event_create - Creates a new event object
- truxton_event_destroy - Destroys an existing event object
- truxton_event_save - Saves the data in this object to the
[Event]table - truxton_event_get_id - After saving, retrieves the GUID of the event.
- truxton_event_get_title - Gets the short title of the event
- truxton_event_set_title - Sets the short title of the event
- truxton_event_get_description - Gets the long description of the event
- truxton_event_set_description - Sets the long description of the event
- truxton_event_get_start - Gets the beginning of the event in FILETIME ticks
- truxton_event_set_start - Sets the beginning of the event in FILETIME ticks
- truxton_event_get_end - Gets the end of the event in FILETIME ticks
- truxton_event_set_end - Sets the end of the event in FILETIME ticks
- truxton_event_get_type - Gets the type of event
- truxton_event_set_type - Sets the type of event
- truxton_event_get_file_id - Gets the GUID of the file this event came from
- truxton_event_set_file_id - Sets the GUID of the file this event came from
- truxton_event_get_media_id - Gets the GUID of the media this event belongs to
- truxton_event_set_media_id - Sets the GUID of the media this event belongs to
Derived Objects
The following APIs are used to create objects with an event as their parent.
- truxton_event_tag - Creates a tag and puts it on this event. This data will be saved to the
[Tagged]table.
Event Type
This API is used to create custom types of events. If one of the default event types don't suite your purpose, you are free to create your own.
- truxton_event_type_create - Creates a new event type object
- truxton_event_type_destroy - Destroys an existing event type object
- truxton_event_type_save - Saves the data in this object to the
[EventType]table - truxton_event_type_get_id - Retrieves the integer value for the type
- truxton_event_type_set_id - Sets the integer value of the type
- truxton_event_type_get_name - Gets the human readable name of the event type
- truxton_event_type_set_name - Sets the human readable name of the event type
EXIF (Camera Information)
This set if APIs deal with information from the EXIF section of files. The primary file types that contain EXIF are JPG and TIFF. Not all of the fields of this object are stored in the database. Internally, Truxton has one parser for EXIF and uses that information to perform other forensic tasks.
These functions give you access to a data structure equivalent to the one used in EXIF messages.
Persisted in Database
The following APIs deal with things that are stored in the database.
- truxton_exif_create - Creates a new EXIF object
- truxton_exif_destroy - Destroys an existing EXIF object
- truxton_exif_save - Saves the data in this object to the
[EXIF]table in the database - truxton_exif_get_id - Retrieves the object's GUID
- truxton_exif_get_file_id - Retrieves the GUID of the file this object came from
- truxton_exif_set_file_id - Sets GUID of the file this object came from
- truxton_exif_get_media_id - Retrieves GUID of the media this object came from
- truxton_exif_set_media_id - Sets the GUID of the media this object came from
- truxton_exif_get_altitude - Retrieves the altitude, in meters, of the location
- truxton_exif_set_altitude - Sets the altitude, in meters, of the location
- truxton_exif_get_body_serial_number - Retrieves the serial number of the body of the imaging device
- truxton_exif_set_body_serial_number - Sets the serial number of the body of the imaging device
- truxton_exif_get_device_time - Retrieves the time, according to the imaging device, of when the image was taken in FILETIME ticks
- truxton_exif_set_device_time - Sets the time, according to the imaging device, of when the image was taken in FILETIME ticks
- truxton_exif_get_focal_length - Retrieves the 35mm focal length of the device
- truxton_exif_set_focal_length - Sets the focal length of the device when the image was taken
- truxton_exif_get_gps_time - Retrieves the time, according to the GPS in the imaging device, of when the image was taken in FILETIME ticks
- truxton_exif_set_gps_time - Sets the time, according to the GPS in the imaging device, of when the image was taken in FILETIME ticks
- truxton_exif_get_heading - Retrieves the direction the device was pointed when the image was taken
- truxton_exif_set_heading - Sets the direction the device was pointed when the image was taken
- truxton_exif_get_latitude - Retrieves the latitude portion of the WGS84 coordinates of the location where the image was taken
- truxton_exif_set_latitude - Sets the latitude portion of the WGS84 coordinates of the location where the image was taken
- truxton_exif_get_lens_serial_number - Retrieves the serial number of the lens attached to the imaging device
- truxton_exif_set_lens_serial_number - Sets the serial number of the lens attached to the imaging device
- truxton_exif_get_longitude - Retrieves the longitude portion of the WGS84 coordinates of the location where the image was taken
- truxton_exif_set_longitude - Sets the longitude portion of the WGS84 coordinates of the location where the image was taken
- truxton_exif_get_make - Retrieves the manufacturer of the imaging device
- truxton_exif_set_make - Sets the manufacturer of the imaging device
- truxton_exif_get_model - Retrieves the model of the imaging device
- truxton_exif_set_model - Sets the model of the imaging device
- truxton_exif_get_offset - Retrieves the offset into the parent file where the EXIF data block began.
- truxton_exif_set_offset - Sets the offset into the parent file where the EXIF data block began.
- truxton_exif_get_shutter_count - Retrieves the number of images taken by this device
- truxton_exif_set_shutter_count - Sets the number of images taken by this device
Not in Database
The following APIs are useful for forensic processing but not saved in the database. Internally, when Truxton finds EXIF data, it will create and populate an object with that information. All forensic processing is performed on that object. The information presented here, while not stored in the database, was used by Truxton to exploit the camera information data.
- truxton_exif_get_gps_time_offset - Retrieves the offset into the parent file where GPS time was found
- truxton_exif_set_gps_time_offset - Sets the offset into the parent file where GPS time was found
- truxton_exif_get_device_time_offset - Retrieves the offset into the parent file where the time from the device's internal clock was stored
- truxton_exif_set_device_time_offset - Sets the offset into the parent file where the time from the device's internal clock is stored
- truxton_exif_get_latitude_offset - Retrieves the offset into the parent file where the latitude value was stored
- truxton_exif_set_latitude_offset - Sets the offset into the parent file where the latitude value is stored
- truxton_exif_get_longitude_offset - Retrieved the offset into the parent file where the longitude value was stored
- truxton_exif_set_longitude_offset - Sets the offset into the parent file where the longitude value is stored
- truxton_exif_get_altitude_offset - Retrieves the offset into the parent file where the altitude value was stored
- truxton_exif_set_altitude_offset - Sets the offset into the parent file where the altitude value is stored
- truxton_exif_get_heading_offset - Retrieves the offset into the parent file where the heading value was stored
- truxton_exif_set_heading_offset - Sets the offset into the parent file where the heading value is stored
- truxton_exif_get_focal_length_offset - Retrieves the offset into the parent file where the focal length value was stored
- truxton_exif_set_focal_length_offset - Sets the offset into the parent file where the focal length value is stored
- truxton_exif_get_shutter_count_offset - Retrieves the offset into the parent file where the shutter count value was stored
- truxton_exif_set_shutter_count_offset - Sets the offset into the parent file where the shutter count value is stored
- truxton_exif_get_thumbnail_offset - Retrieves the offset into the parent file where the thumbnail data was stored
- truxton_exif_set_thumbnail_offset - Sets the offset into the parent file where the thumbnail data is stored
- truxton_exif_get_thumbnail_offset_offset - Retrieves the offset into the parent file where the offset to the thumbnail image was stored
- truxton_exif_set_thumbnail_offset_offset - Sets the offset into the parent file where the thumbnail offset value is stored
- truxton_exif_get_thumbnail_length - Retrieves the number of bytes in the thumbnail image
- truxton_exif_set_thumbnail_length - Sets the number of bytes in the thumbnail image
- truxton_exif_get_thumbnail_length_offset - Retrieves the offset into the parent file where the thumbnail length value was stored
- truxton_exif_set_thumbnail_length_offset - Sets the offset into the parent file where the thumbnail length value is stored
- truxton_exif_get_make_offset - Retrieves the offset into the parent file where the make value was stored
- truxton_exif_set_make_offset - Sets the offset into the parent file where the make value is stored
- truxton_exif_get_model_offset - Retrieves the offset into the parent file where the model value was stored
- truxton_exif_set_model_offset - Sets the offset into the parent file where the model value is stored
- truxton_exif_get_body_serial_number_offset - Retrieves the offset into the parent file where the body serial number value was stored
- truxton_exif_set_body_serial_number_offset - Sets the offset into the parent file where the body serial number value is stored
- truxton_exif_get_lens_serial_number_offset - Retrieves the offset into the parent file where the lens serial number value was stored
- truxton_exif_set_lens_serial_number_offset - Sets the offset into the parent file where the lens serial number value is stored
Derived Objects
- truxton_exif_tag - Creates a tag and puts it on this EXIF object. This data will be saved to the
[Tagged]table.
File
File Actions
These are things your can do to a file. These are not data items stored in the database.
- truxton_file_change_type - Allows you to change the type of the file
- truxton_file_exists - Allows you to test if a file is in the database
- truxton_file_get_details - Retrieves JSON with details of the file's contents
- truxton_file_get_truxton - Retrieves the Truxton connection used to get this file
File IO
- truxton_file_close - Closes the contents. You will no longer be able to read from the file.
- truxton_file_free - Deallocates any resources allocated for this object. The file is no longer valid after this call.
- truxton_file_tell - Returns the current file pointer position.
- truxton_file_length - Returns the number of bytes in the file's contents.
- truxton_file_is_closed - Tells you if the file has been closed or not.
- truxton_file_seek - Changes the file pointer.
- truxton_file_readline - Reads a single line of text from the file.
- truxton_file_read - Reads bytes from the file.
File Record Fields
- truxton_file_get_accessed - Reads the file's last access timestamp in FILETIME ticks
- truxton_file_get_attributes - Reads the attributes of the file
- truxton_file_get_content_status - Reads the status of the file's contents
- truxton_file_get_created - Reads the file's creation timestamp in FILETIME ticks
- truxton_file_get_depot_id - Reads the GUID of the depot holding the file's contents
- truxton_file_get_depot_length - Reads the number of bytes in the depot taken by this file's contents
- truxton_file_get_depot_name - Reads the file name of the depot holding this file's contents
- truxton_file_get_depot_offset - The offset from the beginning of the depot where this file's contents begin
- truxton_file_get_disk_offset - Reads physical offset of the first byte of the file's contents
- truxton_file_get_entropy - Reads the entropy of the file's contents
- truxton_file_get_hash - Reads the MD5 of the file's contents
- truxton_file_get_id - Retrieves the file's GUID
- truxton_file_get_is_eliminated - Tells you of the file's contents were discarded
- truxton_file_get_is_resident - Tells you if the file's contents exist contiguously within its parent
- truxton_file_get_media_id - Reads the GUID of the file's media
- truxton_file_get_modified - Reads the file's last write timestamp in FILETIME ticks
- truxton_file_get_name - Reads the name of the file
- truxton_file_get_number_of_children - Returns the number of files that have this one as their parent
- truxton_file_get_origin - Reads the origin of the file's contents
- truxton_file_get_parent_id - Reads the GUID of the file's parent
- truxton_file_get_size - Reads the size of the file as recorded in the directory entry for the file
- truxton_file_get_signature - Gets the first four bytes of the contents as an integer
- truxton_file_get_type - Reads the type of the file
Derived Objects
The following APIs are used to create objects with a file as their parent.
- truxton_file_create_artifact - Creates and associates an artifact with this file. The artifact be saved to the
[Entity]table. - truxton_file_create_child - For creating a file.
- truxton_file_create_event - Creates and associates an event with this file. The event will be saved to the
[Event]table. - truxton_file_create_exif - Creates and associates camera information with this file. The data will be saved to the
[EXIF]table. - truxton_file_create_location - Creates and associates a geographic location with this file. The data will be saved to the
[Location]table. - truxton_file_create_relation - Creates a relationship with this file as the source. The data will be saved to the
[Relation]table. - truxton_file_create_url - Creates a website visit with this file as the source. This data will be saved to the
[WebsiteVisit]table. - truxton_file_create_usb - Creates a USB device with this file as the source. This data will be saved to the
[USBDevice]table. - truxton_file_open_id - Retrieves a particular file specified by the file's GUID.
- truxton_file_open_md5 - Retrieves the first file in Truxton whose contents have the given MD5 hash.
- truxton_file_tag - Creates a tag and puts it on this file. This data will be saved to the
[Tagged]table.
File Export
- truxton_file_export_create - Creates a new file export object
- truxton_file_export_destroy - Destroys an existing file export object
- truxton_file_export_execute - Exports the files based on the given criteria and options
- truxton_file_export_add_criteria - Adds a criteria to the export
- truxton_file_export_set_option - Sets options for the export
- truxton_file_export_where_clause - Retrieves the SQL
WHEREclause of the current criteria
File Type
- truxton_file_type_create - Creates a file type object.
- truxton_file_type_destroy - Deallocates any resources assigned to the file object.
- truxton_file_type_get_id - Retrieves the identifier you assigned to this object.
- truxton_file_type_set_id - Sets the unique identifier. This corresponds to the
[ID]column of the[FileType]table. - truxton_file_type_get_parent_id - Retrieves the parent identifier you assigned to this object.
- truxton_file_type_set_parent_id - Sets the more generic type of the file. This corresponds to the
[ParentFileTypeID]column of the[FileType]table. - truxton_file_type_get_short_name - Retrieves the short name you assigned to this object.
- truxton_file_type_set_short_name - Sets the short name to use for this file type. This corresponds to the
[ShortName]column of the[FileType]table. - truxton_file_type_get_long_name - Retrieves the longer description you assigned to this object.
- truxton_file_type_set_long_name - Sets the longer description of the file type. This corresponds to the
[LongName]column of the[FileType]table. - truxton_file_type_get_extension - Retrieves the file name extension you assigned to this object.
- truxton_file_type_set_extension - Sets the file name extension for this object.
- truxton_file_type_get_mime_type - Retrieves the MIME type you assigned to this object. This corresponds to the
[Extension]column of the[FileType]table. - truxton_file_type_set_mime_type - Sets the MIME type. This corresponds to the
[MIME]column of the[FileType]table. - truxton_file_type_save - This will write the information in the object to the
[FileType]table.
Geographic Location
- truxton_location_create - Creates geographic location. The data will be saved to the
[Location]table - truxton_location_destroy - Destroys the location object
- truxton_location_save - Saves the information in the object to the
[Location]table - truxton_location_get_id - After saving, retrieves the GUID of the event
- truxton_location_get_file_id - Retrieves the GUID of the file the location came from
- truxton_location_set_file_id - Sets the GUID of the file this location came from
- truxton_location_get_media_id - Retrieves the GUID of the media this location came from
- truxton_location_set_media_id - Sets the GUID of the media this location came from
- truxton_location_get_altitude - Retrieves the altitude, in meters, of this location
- truxton_location_set_altitude - Sets the altitude, in meters, of this location
- truxton_location_get_label - Retrieves the short title of this location
- truxton_location_set_label - Sets the short description of this location
- truxton_location_get_latitude - Retrieves the latitude portion of the WGS84 coordinates of this location
- truxton_location_set_latitude - Sets the latitude portion of the WGS84 coordinates of this location
- truxton_location_get_longitude - Retrieves the longitude portion of the WGS84 coordinates of this location
- truxton_location_set_longitude - Sets the longitude portion of the WGS84 coordinates of this location
- truxton_location_get_type - Retrieves the type of the location
- truxton_location_set_type - Sets the type of the location
- truxton_location_get_when - Retrieves the date and time associated with this location in FILETIME ticks
- truxton_location_set_when - Sets the date and time associated with this location in FILETIME ticks
Derived Objects
The following APIs are used to create objects with a location as their parent.
- truxton_location_tag - Associating a tag with this media. This data will be saved to the
[Tagged]table.
Media
These are the API's that allow you to add to the Media table in the database.
- truxton_media_create - Creates a new media object
- truxton_media_open_id - Opens an existing media in the database given the media's GUID.
- truxton_media_destroy - Frees any resources allocated to this object
- truxton_media_get_id - Retrieves the GUID of the media
- truxton_media_set_id - Sets the GUID of the media
- truxton_media_get_name - Retrieves the name of the media
- truxton_media_set_name - Sets the name of the media
- truxton_media_get_description - Retrieves the longer description of the media
- truxton_media_set_description - Sets the description of the media
- truxton_media_get_case_number - Retrieves the case identifier of the media
- truxton_media_set_case_number - Sets the case identifier of the media
- truxton_media_get_originator - Retrieves who asked you to process the media
- truxton_media_set_originator - Sets the origin of the media
- truxton_media_get_evidence_bag - Retrieves the identifier of the evidence bag the media is being kept in
- truxton_media_set_evidence_bag - Records the identifier of the evidence bag the media is stored in.
- truxton_media_get_status - Retrieves the status of the media
- truxton_media_set_status - Sets the status of the media
- truxton_media_get_type - Retrieves the type of the media
- truxton_media_set_type - Sets the type of the media
- truxton_media_get_created - Retrieves when the media was created in FILETIME ticks
- truxton_media_set_created - Sets when the media was created in FILETIME ticks
- truxton_media_get_last_updated - Retrieves when the media was last updated in FILETIME ticks
- truxton_media_set_last_updated - Sets when the media was last updated in FILETIME ticks
- truxton_media_get_expires - Retrieves the expiration date of the media
- truxton_media_set_expires - Sets the expiration date of the media
- truxton_media_get_percent_complete - Retrieves the completeness the processing of this media
- truxton_media_set_percent_complete - Sets the completeness the processing of this media
- truxton_media_get_load_configuration_id - Retrieves the load configuration of this media
- truxton_media_set_load_configuration_id - Sets the load configuration of this media
- truxton_media_get_size - Retrieves the size, in bytes, of the original media
- truxton_media_set_size - Sets the size, in bytes, of the original media
- truxton_media_get_latitude - Retrieves the latitude portion of the WGS84 coordinates of where the media was seized.
- truxton_media_set_latitude - Sets the latitude portion of the WGS84 coordinates of where the media was seized.
- truxton_media_get_longitude - Retrieves the longitude portion of the WGS84 coordinates of where the media was seized.
- truxton_media_set_longitude - Sets the longitude portion of the WGS84 coordinates of where the media was seized.
- truxton_media_get_generated_files_folder_id - Retrieves the GUID of the Generated Files folder in the media
- truxton_media_get_root_file_id - Retrieves the GUID of the top level file in the media
- truxton_media_save - Saves the media information to the database
Derived Objects
The following APIs are used to create objects with a media as their parent.
- truxton_media_add_child - Created a child file object belonging to this media.
- truxton_media_tag - Associating a tag with this media. This data will be saved to the
[Tagged]table.
Message
This is the message sent on the message bus between the ETL processes.
- truxton_message_create - Creates a new message object
- truxton_message_destroy - Destroys the message object
- truxton_message_get_queue_is_empty - Tells you if the message queue is empty
- truxton_message_set_queue_is_empty - Sets the empty-queue attribute
- truxton_message_get_route_id - Retrieves the route this message is taking
- truxton_message_set_route_id - Sets the route the message should take
- truxton_message_get_priority - Retrieves the priority of the message
- truxton_message_set_priority - Sets the priority of the message
- truxton_message_get_file_id - Retrieves the identifier of the file
- truxton_message_set_file_id - Sets the identifier of the file
- truxton_message_get_parent_id - Retrieves the parent file identifier
- truxton_message_set_parent_id - Sets the parent file identifier
- truxton_message_get_media_id - Retrieves the media identifier
- truxton_message_set_media_id - Sets the media identifier
- truxton_message_get_depot_id - Retrieves the depot identifier
- truxton_message_set_depot_id - Sets the depot identifier
- truxton_message_get_depot_offset - Retrieves the offset into the depot of the first byte of the file's contents
- truxton_message_set_depot_offset - Sets the offset into the depot of the first byte of the file's contents
- truxton_message_get_depot_length - Retrieves the number of bytes in the depot for this file's contents
- truxton_message_set_depot_length - Sets the number of bytes in the depot for this file's contents
- truxton_message_get_hash - Retrieves the MD5 hash (digital fingerprint) of the file's contents
- truxton_message_set_hash - Sets the MD5 hash (digital fingerprint) of the file's contents
- truxton_message_get_signature - Retrieves the first four bytes of the contents as an integer
- truxton_message_set_signature - Sets the first four bytes of the contents as an integer
- truxton_message_get_file_type - Retrieves the type of the file
- truxton_message_set_file_type - Sets the type of the file
- truxton_message_get_depot_name - Retrieves the name of the file that stores this file's contents
- truxton_message_set_depot_name - Sets the name of the file that stores this file's contents
- truxton_message_get_dont_route - Retrieves the Don't Route flag
- truxton_message_set_dont_route - Sets the Don't Route flag
- truxton_message_get_truxton - Retrieves the Truxton handle
- truxton_message_set_truxton - Sets the Truxton handle
Derived Objects
The following APIs are used to create objects from the given message.
- truxton_message_get_file - Created a child file object belonging to this media.
Options
Truxton "options" are otherwise known as configuration settings, command line options, etc. They are configuration items that your program can use.
- truxton_options_create - Creates the options object
- truxton_options_destroy - Frees any resources allocated by the options
- truxton_option_get_boolean - Reads a named boolean value
- truxton_option_get_integer - Reads a named integer value
- truxton_option_get_string - Reads a named string value
Relation
These functions let you add to the [Relation] table in Truxton.
This is how to establish some sort of relationship between items in Truxton to create a graph.
Relations in Truxton adhere to the form of "A is a XXX of B"
Truxton is not focused on exploring graphs (cliques anyone?) but needed a way to establish simple relationships between objects.
- truxton_relation_create - Creates a new relationship object
- truxton_relation_destroy - Destroys an existing relationship object
- truxton_relation_save - Saves the information in the object to the
[Relation]table - truxton_relation_get_a_id - Retrieves the GUID of the A object
- truxton_relation_set_a_id - Sets the GUID of the A object
- truxton_relation_get_b_id - Retrieves the GUID of the B object
- truxton_relation_set_b_id - Sets the GUID of the B object
- truxton_relation_get_source_id - Retrieves the GUID of the object this relation came from
- truxton_relation_set_source_id - Sets the GUID of the object this relation came from
- truxton_relation_get_a_type - Gets the type of A's object id
- truxton_relation_set_a_type - Sets the type of A's object id
- truxton_relation_get_b_type - Gets the type of B's object id
- truxton_relation_set_b_type - Sets the type of B's object id
- truxton_relation_get_source_type - Gets the type of the source's object id
- truxton_relation_set_source_type - Sets the type of the source's object id
- truxton_relation_get_relation - Retrieves the type of the relation
- truxton_relation_set_relation - Sets the type of the relation
Subject
These are the API's that allow you to add an investigative subject to Truxton.
These will add records to the [Suspect] table.
- truxton_subject_create - Creates a new investigative subject
- truxton_subject_destroy - Destroys the subject
- truxton_subject_get_id - Retrieves the GUID of the subject
- truxton_subject_set_id - Sets the GUID of the subject
- truxton_subject_set_name - Retrieves the name of the subject
- truxton_subject_get_name - Sets the name of the subject
- truxton_subject_get_description - Retrieves the description of the subject
- truxton_subject_set_description - Sets the description of the subject
- truxton_subject_get_picture - Retrieves the picture of the subject
- truxton_subject_set_picture - Sets the picture of the subject
- truxton_subject_get_custom - Retrieves the custom data of the subject
- truxton_subject_set_custom - Sets the custom data of the subject
- truxton_subject_get_birthday - Retrieves the birthday of the subject in FILETIME ticks
- truxton_subject_set_birthday - Sets the birthday of the subject in FILETIME ticks
- truxton_subject_save - Will commit the information in the subject object to the
[Suspect]table.
Derived Objects
The following APIs are used to create objects with a subject as their parent.
- truxton_subject_tag - Associating a tag with this subject. This data will be saved to the
[Tagged]table.
URL
These functions encapsulate a data structure similar to the one used in the Website Visit message.
- truxton_url_create - Creates a new URL object
- truxton_url_destroy - Destroys an existing URL object
- truxton_url_save - Saves the information in the object to the
[WebsiteVisit]table - truxton_url_get_account - Retrieves the account in use when the URL was visited
- truxton_url_set_account - Sets the account in use when the URL was visited
- truxton_url_get_account_offset - Retrieves the offset into the parent file where the account was found
- truxton_url_set_account_offset - Sets the offset into the parent file where the account was found
- truxton_url_get_file_id - Retrieves the identifier of the file this URL came from
- truxton_url_set_file_id - Sets the identifier of the file this URL came from
- truxton_url_get_format - Retrieves the format of the URL
- truxton_url_set_format - Sets the format of the URL
- truxton_url_get_id - Retrieves the identifier of the URL after it has been saved
- truxton_url_get_local_filename - Retrieves the name of the file the URL was cached to
- truxton_url_set_local_filename - Sets the name of the file the URL was cached to
- truxton_url_get_media_id - Retrieves the identifier of the media this URL belongs to
- truxton_url_set_media_id - Sets the identifier of the media this URL belongs to
- truxton_url_get_method - Retrieves the method used to visit the URL
- truxton_url_set_method - Sets the method used to visit the URL
- truxton_url_get_type - Retrieves the type of the URL
- truxton_url_set_type - Sets the type of the URL
- truxton_url_get_url - Retrieves the URL that was visited
- truxton_url_set_url - Sets the URL that was visited
- truxton_url_get_url_offset - Retrieves the offset into the parent file where the URL was found
- truxton_url_set_url_offset - Sets the offset into the parent file where the URL was found
- truxton_url_get_when - Retrieves the date and time of when the URL was visited in FILETIME ticks
- truxton_url_set_when - Sets the date and time of when the URL was visited in FILETIME ticks
Derived Objects
The following APIs are used to create objects with an event as their parent.
- truxton_url_tag - Creates a tag and puts it on this location. This data will be saved to the
[Tagged]table.
USB Device
- truxton_usb_create - Creates a new USB object
- truxton_usb_destroy - Destroys an existing USB object
- truxton_usb_save - Saves the information in the object to the
[USBDevice]table - truxton_usb_get_device_id - Retrieves the identifier of the USB device as assigned by Windows
- truxton_usb_set_device_id - Sets the identifier of the USB device as assigned by Windows
- truxton_usb_get_device_type - Retrieves the type of the USB device
- truxton_usb_set_device_type - Sets the type of the USB device
- truxton_usb_get_file_id - Retrieves the identifier of the file this USB came from
- truxton_usb_set_file_id - Sets the identifier of the file this USB came from
- truxton_usb_get_id - Retrieves the identifier of the USB after it has been saved
- truxton_usb_get_media_id - Retrieves the identifier of the media this USB belongs to
- truxton_usb_set_media_id - Sets the identifier of the media this USB belongs to
- truxton_usb_get_file_offset - Retrieves the offset into the parent file where the USB was found
- truxton_usb_set_file_offset - Sets the offset into the parent file where the USB was found
- truxton_usb_get_product_id - Retrieves the product identifier (PID) of the USB device
- truxton_usb_set_product_id - Sets the product identifier (PID) of the USB device
- truxton_usb_get_revision - Retrieves the revision number of the device
- truxton_usb_set_revision - Sets the revision number of the device
- truxton_usb_get_vendor_id - Retrieves the vendor identifier (VID) of the USB device
- truxton_usb_set_vendor_id - Sets the vendor identifier (VID) of the USB device
- truxton_usb_get_when - Retrieves the date and time of when the USB was seen
- truxton_usb_set_when - Sets the date and time of when the USB was seen
Derived Objects
- truxton_usb_tag - Associate a tag with this USB device. This data will be saved to the
[Tagged]table.