Difference between revisions of "TruxtonEvent"

From truxwiki.com
Jump to navigation Jump to search
(Created page with "This class lets you add to the Event table in Truxton. =Attributes and Methods= ==<code>id</code>== This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GU...")
 
Line 8: Line 8:
 
The longer description of the event.
 
The longer description of the event.
  
==<code>depotname</code>==
 
The name of the depot that contains the file's contents.
 
  
 
==<code>end</code>==
 
==<code>end</code>==
 
When the event ended.
 
When the event ended.
 
==<code>dontroute</code>==
 
This integer controls whether the message should be further routed through the message bus.
 
This is usually only set when debugging an ETL process.
 
  
 
==<code>file()</code>==
 
==<code>file()</code>==
Line 22: Line 16:
  
 
==<code>fileid</code>==
 
==<code>fileid</code>==
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file.
+
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this event came from.
 
This identifier corresponds to the <code>ID</code> of the <code>File</code> table.
 
This identifier corresponds to the <code>ID</code> of the <code>File</code> table.
 
==<code>filetype</code>==
 
The [[File Types Supported | type of the file.
 
This corresponds to the <code>FileTypeID</code> column of the <code>File</code> table.
 
 
==<code>hash</code>==
 
The [https://en.wikipedia.org/wiki/MD5 MD5] hash of the contents of the file.
 
This corresponds to the <code>HashID</code> column of the <code>File</code> table.
 
  
 
==<code>mediaid</code>==
 
==<code>mediaid</code>==
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file.
+
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the event.
 
This identifier corresponds to the <code>MediaID</code> of the <code>File</code> table.
 
This identifier corresponds to the <code>MediaID</code> of the <code>File</code> table.
  
==<code>parentid</code>==
+
==<code>start</code>==
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file.
 
This identifier corresponds to the <code>ParentID</code> of the <code>File</code> table.
 
 
 
==<code>priority</code>==
 
This integer value controls the prioriy of the message.
 
High values have greater priority than lower values.
 
 
 
==<code>queueempty</code>==
 
This integer tells you if your message queue is empty.
 
When this value is non-zero, the message queue is empty.
 
  
==<code>routeid</code>==
+
==<code>title</code>==
This integer represents the path that files should take through the exploitation processes.
 
It should be a value in the <code>LoadConfigurationID</code> column of the <code>[[ETLRoute Table | ETLRoute]]</code> table.
 
  
==<code>signature</code>==
+
==<code>type</code>==
The first four bytes of the file stored as an integer.
 
This corresponds to the <code>Signature</code> column of the <code>File</code> table.
 
  
 
=Sample=
 
=Sample=

Revision as of 16:58, 27 May 2020

This class lets you add to the Event table in Truxton.

Attributes and Methods

id

This is the GUID of the event. It becomes non-zero after save() has been called.

description

The longer description of the event.


end

When the event ended.

file()

This method will return a read-only file that you can use to read the contents of the file.

fileid

This is the GUID of the file this event came from. This identifier corresponds to the ID of the File table.

mediaid

This is the GUID of the event. This identifier corresponds to the MediaID of the File table.

start

title

type

Sample

 1 import truxton
 2 
 3 def main():
 4   etl = truxton.etl()
 5   etl.name = "My New ETL"
 6   etl.description = "This ETL processes files in the Truxton system"
 7   etl.queue = "anewetl"
 8   etl.stage = 40
 9   etl.expanderid = 0x05fc0bf6a57726a0
10   etl.version = 0
11   etl.depot = "thumbnail"
12   etl.depotype = truxton.DEPOT_TYPE_THUMBNAILS
13   etl.poly = 0
14 
15   etl.addarg("--verbose")
16   etl.addarg("Yes")
17 
18   etl.sendmefileid("5ecbebc4-9937-2b88-f691-91a800000024")
19   etl.sendmehash("baa51f0cc8361660df911e06e7637485")
20   etl.sendmefiles(truxton.Type_JPEGWithExif, 100)
21   etl.sendmefiles(truxton.Type_TIFFWithExif, 500)
22   etl.sendmelocalfile( "C:/Test Files/Video/Fragmented/Recovered Video.mp4", truxton.Type_MPEG4Video, 0 )
23 
24   message = etl.getmessage()
25 
26   while message is not None:
27     file_in_truxton = message.file()
28 
29     # YOUR FORENSIC CODE GOES HERE
30 
31     line_of_text = file_in_truxton.readline()
32 
33     if "[SetupAPI" in line_of_text:
34       child = file_in_truxton.newchild()
35       child.name = "Child file from New ETL"
36       child.write("This is the file you were looking for.")
37       child.save()
38 
39 if __name__ == "__main__":
40   main()