Difference between revisions of "Truxton file get accessed"

From truxwiki.com
Jump to navigation Jump to search
Line 1: Line 1:
 
This retrieves the last accessed date of the file.
 
This retrieves the last accessed date of the file.
It corresponds to the <code>LastAccess</code> column of the <code>File</code> table.
+
It corresponds to the <code>LastAccess</code> column of the <code>[[File Table | File]]</code> table.
  
 
=Syntax=
 
=Syntax=
Line 15: Line 15:
  
 
=Sample=
 
=Sample=
 
 
<syntaxhighlight lang="C" highlight="10">
 
<syntaxhighlight lang="C" highlight="10">
 
int print_id(uint64_t truxton)
 
int print_id(uint64_t truxton)

Revision as of 06:29, 10 June 2020

This retrieves the last accessed date of the file. It corresponds to the LastAccess column of the File table.

Syntax

uint64_t truxton_file_get_accessed( uint64_t file_handle );

Parameters

file_handle

The handle created by the truxton_file_open_id or truxton_file_open_md5 call.

Return value

The last access date of the file in FILETIME ticks.

Sample

int print_id(uint64_t truxton)
{
   uint64_t file = truxton_file_open_md5(truxton, "9ec8fb6095c35eff2b236863b7caaf10");

   if ( file != 0 )
   {
      return(0);
   }

   uint64_t ticks = truxton_file_get_accessed( file );

   if ( ticks == 0 )
   {
      printf( "Timestamp was not set\n" );
   }
}