Difference between revisions of "TruxtonChildFileIO"
| Line 44: | Line 44: | ||
=Properties= | =Properties= | ||
| − | ==<code>accessed</code>== | + | ==<code>accessed: int</code>== |
When the file was last accessed in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | When the file was last accessed in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | ||
| − | ==<code>attributes</code>== | + | ==<code>attributes: int</code>== |
An integer value representing the attributes of the file. | An integer value representing the attributes of the file. | ||
For a Microsoft filesystem, it can be a combination of the [https://docs.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants file attribute flags.] | For a Microsoft filesystem, it can be a combination of the [https://docs.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants file attribute flags.] | ||
| − | ==<code>created</code>== | + | ==<code>created: int</code>== |
When the file was created in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | When the file was created in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | ||
| − | ==<code>diskoffset</code>== | + | ==<code>diskoffset: int</code>== |
The offset, in bytes, of the first byte of the contents of the file on the physical disk. | The offset, in bytes, of the first byte of the contents of the file on the physical disk. | ||
| − | ==<code>entropy</code>== | + | ==<code>entropy: float</code>== |
| − | [[Truxton_child_file_get_entropy | Shannon's entropy]] of the contents of the file. | + | [[Truxton_child_file_get_entropy|Shannon's entropy]] of the contents of the file. |
| − | ==<code>hash</code>== | + | ==<code>hash: str</code>== |
The [https://en.wikipedia.org/wiki/MD5 MD5] hash of the contents of the file. | The [https://en.wikipedia.org/wiki/MD5 MD5] hash of the contents of the file. | ||
| − | ==<code>id</code>== | + | ==<code>id: str</code>== |
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file record. | The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file record. | ||
| − | This is valid once <code>save()</code> | + | This is valid once <code>save()</code> has been called. |
| − | ==<code>mediaid</code>== | + | ==<code>mediaid: str</code>== |
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media the child file came from. | The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media the child file came from. | ||
| − | ==<code>modified</code>== | + | ==<code>modified: int</code>== |
When the file was last written in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | When the file was last written in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks. | ||
| − | ==<code>name</code>== | + | ==<code>name: str</code>== |
The name of the file. | The name of the file. | ||
| − | ==<code>origin</code>== | + | ==<code>origin: int</code>== |
Where the file came from. | Where the file came from. | ||
| − | It should be one of the [[Origin | origin values.]] | + | It should be one of the [[Origin|origin values.]] |
| − | ==<code>parentid</code>== | + | ==<code>parentid: str</code>== |
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the parent of this file. | The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the parent of this file. | ||
| − | ==<code>save()</code>== | + | ==<code>save() -> true</code>== |
This will commit the information to the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table. | This will commit the information to the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table. | ||
It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error. | It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error. | ||
| − | ==<code>size</code>== | + | ==<code>size: int</code>== |
The size, in bytes, of the file. | The size, in bytes, of the file. | ||
| − | ==<code>status</code>== | + | ==<code>status: int</code>== |
The status of the contents of the file. | The status of the contents of the file. | ||
| − | It should be one of the [[Content Status | content status values.]] | + | It should be one of the [[Content Status|content status values.]] |
| − | ==<code>type</code>== | + | ==<code>type: int</code>== |
| − | The [[File Types Supported | type ]] of the file. | + | The [[File Types Supported|type]] of the file. |
=Sample= | =Sample= | ||
Revision as of 10:58, 30 July 2022
This class provides a writable file to add to Truxton.
IOBase Methods
From IOBase it implements:
- close()
- closed
- fileno() - Truxton will return ERROR
- flush()
- isatty()
- readable() - Truxton always returns False
- readline() - Do not use, will return ERROR
- readlines() - Do not use, will return ERROR
- seek() - Truxton will return ERROR
- seekable() - Truxton always returns False
- tell()
- truncate()
- writable() - Truxton always returns True
- writelines()
RawIOBase Methods
From RawIOBase it implements:
Truxton Methods
The above methods will let you read from a file in Truxton as if it were any other file in Python. The following methods are also present to make tasks of adding items extracted from a file easier.
- newartifact()
- newchild()
- newcommunication()
- newevent()
- newexif()
- newlocation()
- newrelation()
- newurl()
- newusb()
- tag()
Properties
accessed: int
When the file was last accessed in FILETIME ticks.
attributes: int
An integer value representing the attributes of the file. For a Microsoft filesystem, it can be a combination of the file attribute flags.
created: int
When the file was created in FILETIME ticks.
diskoffset: int
The offset, in bytes, of the first byte of the contents of the file on the physical disk.
entropy: float
Shannon's entropy of the contents of the file.
hash: str
The MD5 hash of the contents of the file.
id: str
The GUID of the file record.
This is valid once save() has been called.
mediaid: str
The GUID of the media the child file came from.
modified: int
When the file was last written in FILETIME ticks.
name: str
The name of the file.
origin: int
Where the file came from. It should be one of the origin values.
parentid: str
The GUID of the parent of this file.
save() -> true
This will commit the information to the [File] table.
It will return True if the record was saved to the database, False if there was an error.
size: int
The size, in bytes, of the file.
status: int
The status of the contents of the file. It should be one of the content status values.
type: int
The type of the file.
Sample
This will retrieve a file from Truxton, print the name and hash as stored in the database then calculate a hash on the contents and print that.
import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil
from pathlib import Path
def add_file(parent_truxton_file, filename):
source_file = open(filename, "rb")
child = parent_truxton_file.newchild()
child.name = Path(filename).name
shutil.copyfileobj(source_file, child)
source_file.close()
child.save()
return child
def main():
t = truxton.create()
file = t.getfileid("5ec2a123-74d6-5da7-0653-4e6800000000")
child = add_file(file, "C:\decrypts\PlainText.txt")
if __name__ == "__main__":
main()