Difference between revisions of "TruxtonChildFileIO"

From truxwiki.com
Jump to navigation Jump to search
Line 4: Line 4:
 
From [https://docs.python.org/3/library/io.html#io.IOBase IOBase] it implements:
 
From [https://docs.python.org/3/library/io.html#io.IOBase IOBase] it implements:
  
* [https://docs.python.org/3/library/io.html#io.IOBase.close close()]
+
* [https://docs.python.org/3/library/io.html#io.IOBase.close close()] - Flush and close this stream
* [https://docs.python.org/3/library/io.html#io.IOBase.closed closed]
+
* [https://docs.python.org/3/library/io.html#io.IOBase.closed closed] - [https://docs.python.org/3/library/constants.html#True True] if the stream is closed
 
* [https://docs.python.org/3/library/io.html#io.IOBase.fileno fileno()] - Truxton will return ERROR
 
* [https://docs.python.org/3/library/io.html#io.IOBase.fileno fileno()] - Truxton will return ERROR
* [https://docs.python.org/3/library/io.html#io.IOBase.flush flush()]
+
* [https://docs.python.org/3/library/io.html#io.IOBase.flush flush()] - Flush the write buffers of the stream if applicable
* [https://docs.python.org/3/library/io.html#io.IOBase.isatty isatty()]
+
* [https://docs.python.org/3/library/io.html#io.IOBase.isatty isatty()] - Return [https://docs.python.org/3/library/constants.html#True True] if the stream is interactive
 
* [https://docs.python.org/3/library/io.html#io.IOBase.readable readable()] - Truxton always returns [https://docs.python.org/3/library/constants.html#False False]
 
* [https://docs.python.org/3/library/io.html#io.IOBase.readable readable()] - Truxton always returns [https://docs.python.org/3/library/constants.html#False False]
 
* [https://docs.python.org/3/library/io.html#io.IOBase.readline readline()] - Do not use, will return ERROR
 
* [https://docs.python.org/3/library/io.html#io.IOBase.readline readline()] - Do not use, will return ERROR
Line 14: Line 14:
 
* [https://docs.python.org/3/library/io.html#io.IOBase.seek seek()] - Truxton will return ERROR
 
* [https://docs.python.org/3/library/io.html#io.IOBase.seek seek()] - Truxton will return ERROR
 
* [https://docs.python.org/3/library/io.html#io.IOBase.seekable seekable()] - Truxton always returns [https://docs.python.org/3/library/constants.html#False False]
 
* [https://docs.python.org/3/library/io.html#io.IOBase.seekable seekable()] - Truxton always returns [https://docs.python.org/3/library/constants.html#False False]
* [https://docs.python.org/3/library/io.html#io.IOBase.tell tell()]
+
* [https://docs.python.org/3/library/io.html#io.IOBase.tell tell()] - Return the current stream position
* [https://docs.python.org/3/library/io.html#io.IOBase.truncate truncate()]
+
* [https://docs.python.org/3/library/io.html#io.IOBase.truncate truncate()] - Resize the stream
 
* [https://docs.python.org/3/library/io.html#io.IOBase.writable writable()] - Truxton always returns [https://docs.python.org/3/library/constants.html#True True]
 
* [https://docs.python.org/3/library/io.html#io.IOBase.writable writable()] - Truxton always returns [https://docs.python.org/3/library/constants.html#True True]
* [https://docs.python.org/3/library/io.html#io.IOBase.writelines writelines()]
+
* [https://docs.python.org/3/library/io.html#io.IOBase.writelines writelines()] - Write a list of lines to the stream
  
 
=RawIOBase Methods=
 
=RawIOBase Methods=

Revision as of 06:57, 1 October 2022

This class provides a writable file to add to Truxton.

IOBase Methods

From IOBase it implements:

RawIOBase Methods

From RawIOBase it implements:

Truxton Methods

The above methods will let you read from a file in Truxton as if it were any other file in Python. The following methods are also present to make tasks of adding items extracted from a file easier.

Properties

accessed: int

When the file was last accessed in FILETIME ticks.

attributes: int

An integer value representing the attributes of the file. For a Microsoft filesystem, it can be a combination of the file attribute flags.

created: int

When the file was created in FILETIME ticks.

diskoffset: int

The offset, in bytes, of the first byte of the contents of the file on the physical disk.

entropy: float

Shannon's entropy of the contents of the file.

hash: str

The MD5 hash of the contents of the file.

id: str

The GUID of the file record. This is valid once save() has been called.

mediaid: str

The GUID of the media the child file came from.

modified: int

When the file was last written in FILETIME ticks.

name: str

The name of the file.

origin: int

Where the file came from. It should be one of the origin values.

parentid: str

The GUID of the parent of this file.

save() -> true

This will commit the information to the [File] table. It will return True if the record was saved to the database, False if there was an error.

size: int

The size, in bytes, of the file.

status: int

The status of the contents of the file. It should be one of the content status values.

type: int

The type of the file.

Sample

This will retrieve a file from Truxton, print the name and hash as stored in the database then calculate a hash on the contents and print that.

import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil
from pathlib import Path

def add_file(parent_truxton_file, filename):
  source_file = open(filename, "rb")
  child = parent_truxton_file.newchild()
  child.name = Path(filename).name
  shutil.copyfileobj(source_file, child)
  source_file.close()
  child.save()
  return child

def main():
  t = truxton.create()
  file = t.getfileid("5ec2a123-74d6-5da7-0653-4e6800000000")
  child = add_file(file, "C:\decrypts\PlainText.txt")

if __name__ == "__main__":
  main()