Difference between revisions of "TruxtonUrl"

From truxwiki.com
Jump to navigation Jump to search
Line 22: Line 22:
  
 
==<code>localfilename</code>==
 
==<code>localfilename</code>==
 +
The path to the file the browser uses to cache the contents of the page retrieved by the URL.
  
 
==<code>mediaid</code>==
 
==<code>mediaid</code>==

Revision as of 08:49, 28 May 2020

This class lets you add to the Website Visit table in Truxton.

Attributes and Methods

account

The optional account name associated with the URL. Many browsers will record the operating system user that did the surfing.

accountoffset

The offset into the parent file where the account was found.

fileid

The GUID of the file this event came from. This corresponds to the FileID column of the WebsiteVisit table.

format

The format of the raw URL. This can be URL_FORMAT_ASCII (1) or URL_FORMAT_UNICODE (2)

id

This is the GUID of the event. It becomes non-zero after save() has been called.

localfilename

The path to the file the browser uses to cache the contents of the page retrieved by the URL.

mediaid

This is the GUID of the media this event came from. This identifier corresponds to the MediaID of the WebsiteVisit table.

method

offset

save()

This will commit the information to the Event table.

tag(tag, reason, origin)

This creates a tag associated with this event in Truxton. The tag parameter is a short, one or two word, bit of text that will be displayed in the UI. The reason a sentence explaining why this event was tagged. The origin is either TAG_ORIGIN_AUTOMATIC (1) or TAG_ORIGIN_HUMAN (2). It will return True if the tag was associated with the file, False on failure.

type

url

when

When the URL was seen in FILETIME ticks. This corresponds to the Start column of the Event table.

Sample

import truxton
import shutil

from datetime import datetime
from calendar import timegm
from pathlib import Path

EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000

EVENT_TYPE_FBI = 20001

def date_to_filetime(dt):
  return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)

def create_event_type(t, id, name):
  event_type = t.neweventtype()
  event_type.id = id
  event_type.name = name
  event_type.save()

def add_file(parent_truxton_file, filename):
  source_file = open(filename, "rb")
  child = parent_truxton_file.newchild()
  child.name = Path(filename).name
  shutil.copyfileobj(source_file, child)
  source_file.close()
  child.save()
  return child

def add_event(parent_file, start, end, title, description, type):
  event = parent_file.newevent()
  event.start = date_to_filetime(datetime.fromisoformat(start))
  event.end = date_to_filetime(datetime.fromisoformat(end))
  event.title = title
  event.description = description
  event.type = type
  event.save()
  return event

def add_media(t):
  media = t.newmedia()

  media.name = "Public Documents"
  media.description = "Publicly available documents"
  media.case = "DC-SNAFU-2016.2020"
  media.evidencebag = "EV-0937459386623-a"
  media.originator = "Jeffrey Jensen"
  media.latitude = 38.897661
  media.longitude = -77.036458
  media.type = truxton.MEDIA_TYPE_LOGICAL_FILES

  if media.save():
    print("Media saved")
  else:
    print("Media not saved")

  return media

def add_ec(parent_file ):
  child_file = add_file(parent_file, "JW-v-DOJ-reply-02743.pdf")

  url = child_file.newurl()
  url.url = "https://www.judicialwatch.org/documents/jw-v-doj-reply-02743/"
  url.localfilename = "JW-v-DOJ-reply-02743.pdf"
  url.type = truxton.URL_TYPE_FIREFOX
  url.method = truxton.URL_METHOD_TYPE_CLICKED_ON_A_LINK
  url.format = truxton.URL_FORMAT_ASCII
  url.when = date_to_filetime(datetime.fromisoformat("2020-05-20T00:00:00-05:00"))
  url.save()

  add_event( child_file, "2016-07-31T12:00:00-05:00", "2016-07-31T12:00:00-05:00", "Crossfire Hurricane Created", "At FBI HQ", EVENT_TYPE_FBI )
  add_event( child_file, "2016-07-27T12:00:00-05:00", "2016-07-27T12:00:00-05:00", "Legat called needing to meet US ambassador", "In London", EVENT_TYPE_FBI )
  add_event( child_file, "2016-07-29T12:00:00-05:00", "2016-07-29T12:00:00-05:00", "FBI Receives Downer Info from Legat", "Probably legat London", EVENT_TYPE_FBI )

def main():
  t = truxton.create()

  create_event_type(t, EVENT_TYPE_FBI, "FBI Actions" )

  media = add_media(t)

  root_file = media.addroot()
  root_file.save()

  add_ec(root_file)

if __name__ == "__main__":
  main()