Difference between revisions of "TruxtonObject"

From truxwiki.com
Jump to navigation Jump to search
Line 112: Line 112:
 
Removes a record in the <code>[DatabaseTableName]</code> table used to [[Identifying Databases|identify a database file]].
 
Removes a record in the <code>[DatabaseTableName]</code> table used to [[Identifying Databases|identify a database file]].
  
==<code>taghash(hash: str, tag: str, description: str) -> bool</code>==
+
==<code>taghash(hash: object, tag: str, description: str) -> bool</code>==
 
This will add a tag to all files that have contents matching the given hash.
 
This will add a tag to all files that have contents matching the given hash.
  

Revision as of 13:45, 28 July 2022

This class gives you access to Truxton at a global level.

Contents

Attributes and Methods

adddatabaseid(file_type_id: int, table_and_column: str)

Creates a record in the [DatabaseTableName] table to help identify a database file.

cleandatabase() -> bool

This send a message to the maintenance ETL to go through the tables looking for unreferenced (orphaned) records and delete them. It will return True if the message was sent, False otherwise.

closed: bool

It will be True if the connection to Truxton is closed, False otherwise.

connnectionstring: str

This will return the database connection string. Use this if you want to query the database directly.

consolidatedepots() -> bool

This send a message to the maintenance ETL to go through closed depots and merge the smaller ones into the larger ones. What you will be left with is few very large depot files instead of many smaller ones. It will return True if the message was sent, False otherwise.

createeverythinghashset(output_filename: str)

Creates a hash set file from the unique hashes in Truxton.

createinvestigationhashset(investigation_id: object, output_filename: str)

Creates a hash set file from the unique hashes in the given investigation.

createmediahashset(media_id: object, output_filename: str)

Creates a hash set file from the unique hashes in the given media.

createtag(name: str, description: str)

This will create a new tag in Truxton. After calling this method, you can tag other items using only the name.

deletedepots() -> bool

This will send a message to the maintenance ETL to delete any depot files that have been marked as ToBeDeleted. It will return True if the message was sent, False otherwise.

deletemedia(media_id: object) -> bool

This will delete a piece of media from Truxton given its identifier. It will return True on success, False on failure.

etlid: str

Returns the GUID of the ETL as a string if it is running.

fileexists(file_id: str) -> bool

This looks in the [File] for a record with the given file_id. If a record is found with that globally unique identifier, True is returned.

getfilehash(hash: str) -> TruxtonFileIO

This will retrieve a file from Truxton based on its MD5 hash.

getfileid(file_id: str) -> TruxtonFileIO

This will retrieve a file from Truxton based on its GUID.

getmediaid(media_id: str) -> TruxtonMedia

This will retrieve a media from Truxton based on its GUID.

getsensitivesitelistid(list_id: object) -> TruxtonSensitiveSiteList

This will retrieve a sensitive site list from Truxton based on its GUID.

machineid: str

Returns the GUID of the machine. When Truxton is installed, this identifier is generated with the most significant 64-bits being a Windows FILETIME and the lower 64-bits being random.

newartifact() -> TruxtonArtifact

This will create an artifact object.

newartifacttype() -> TruxtonArtifactType

This will create an artifact type object.

newbolo() -> TruxtonBolo

This will create a BOLO object.

neweventtype() -> TruxtonEventType

This will create an event type object.

newexporter() -> TruxtonExporter

This will create an exporter object.

newfiletype() -> TruxtonFileType

This will create an file type object.

newinvestigation() -> TruxtonInvestigation

This will create an investigation object.

newjurisdiction() -> TruxtonJurisdiction

This will create a jurisdiction object.

newmedia() -> TruxtonMedia

This will create a media object.

newmessageaddress()

This will create a message address object.

newrelation() -> TruxtonRelation

This will create a relation object.

newsensitivesitelist() -> TruxtonSensitiveSiteList

This will create a sensitive site list object.

newsubject() -> TruxtonSubject

This will create a subject object.

optimizedatabase() -> bool

This update the query statistics in the database.

reindexmedia(media_id: object) -> bool

This will send all of the files in a piece of media to the indexer.

removedatabaseid(file_type_id: int, table_and_column: str) -> bool

Removes a record in the [DatabaseTableName] table used to identify a database file.

taghash(hash: object, tag: str, description: str) -> bool

This will add a tag to all files that have contents matching the given hash.

updateinvestigationtype(investigation_id: object, type: int) -> bool

This will add a tag to all files that have contents matching the given hash.

updatemediatype(media_id: object, type: int) ->

Sets the type of the media. This update the [MediaTypeID] column of the [Media] table. It can be one of the defined constants but it must be one of the values in the [ID] column of the [MediaType] table.

updatemediaphotohash(media_id: object, hash: object) -> bool

Associates the photo with the given MD5 hash with the Media.

version: str

Returns the version string.

Sample

import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil

from datetime import datetime
from calendar import timegm
from pathlib import Path

EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000

def date_to_filetime(dt):
  return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)

def create_event_type(t, id, name):
  event_type = t.neweventtype()
  event_type.id = id
  event_type.name = name
  event_type.save()

def add_file(parent_truxton_file, filename):
  source_file = open(filename, "rb")
  child = parent_truxton_file.newchild()
  child.name = Path(filename).name
  shutil.copyfileobj(source_file, child)
  source_file.close()
  child.save()

  return child

def add_media(t):
  media = t.newmedia()
  media.name = "Public Documents"
  media.description = "Publicly available documents"
  media.case = "DC-SNAFU-2016.2020"
  media.evidencebag = "EV-0937459386623-a"
  media.originator = "Jeffrey Jensen"
  media.latitude = 38.897661
  media.longitude = -77.036458
  media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
  media.save()

  return media

def add_ec(parent_file ):
  child_file = add_file(parent_file, "JW-v-DOJ-reply-02743.pdf")

  a = child_file.newartifact()
  a.type = truxton.ENTITY_TYPE_ACCOUNT
  a.value = "r0cker"
  a.datatype = truxton.DATA_TYPE_ASCII
  a.length = 6
  a.save()

  b = child_file.newartifact()
  b.type = truxton.ENTITY_TYPE_PERSON
  b.value = "Bob Smith"
  b.datatype = truxton.DATA_TYPE_ASCII
  b.length = 9
  b.save()

  relation = child_file.newrelation()
  relation.a = a.id
  relation.atype = truxton.OBJECT_TYPE_ENTITY
  relation.b = b.id
  relation.btype = truxton.OBJECT_TYPE_ENTITY
  relation.relation = truxton.RELATION_LOGON_ACCOUNT
  relation.save()

def main():
  t = truxton.create()

  print(t.version + '\n' );
  print("Truxton will write to depot files in: " + t.getstring("datadir") + '\n');
  print("The database port is: " + str(t.getint("dbport")) + '\n');
  print("Database was created: " + str(t.getbool("CreateTheDatabase")) + '\n');

  media = add_media(t)

  root_file = media.addroot()
  root_file.save()

  add_ec(root_file)

if __name__ == "__main__":
  main()