Difference between revisions of "TruxtonObject"
| Line 5: | Line 5: | ||
==<code>closed</code>== | ==<code>closed</code>== | ||
It will return [https://docs.python.org/3/library/constants.html#True True] if the the connection to Truxton is closed, [https://docs.python.org/3/library/constants.html#False False] otherwise. | It will return [https://docs.python.org/3/library/constants.html#True True] if the the connection to Truxton is closed, [https://docs.python.org/3/library/constants.html#False False] otherwise. | ||
| + | |||
| + | ==<code>createtag(name, description)</code>== | ||
| + | This will create a new tag in Truxton. | ||
| + | After calling this method, you can tag other items using only the <code>name</code>. | ||
==<code>etlid</code>== | ==<code>etlid</code>== | ||
Returns the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the ETL if it is running. | Returns the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the ETL if it is running. | ||
| − | ==<code> | + | ==<code>getbool(name)</code>== |
| − | + | This will retrieve a boolean [[Configuration System | setting]] from Truxton based on its name. | |
| − | ==<code> | + | ==<code>getfilehash(hash)</code>== |
| − | + | This will retrieve a [[TruxtonFileIO | file]] from Truxton based on its [https://en.wikipedia.org/wiki/MD5 MD5] hash. | |
| − | |||
| − | |||
| − | This will | ||
| − | |||
==<code>getfileid(id)</code>== | ==<code>getfileid(id)</code>== | ||
This will retrieve a [[TruxtonFileIO | file]] from Truxton based on its [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID.] | This will retrieve a [[TruxtonFileIO | file]] from Truxton based on its [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID.] | ||
| − | ==<code> | + | ==<code>getint(name)</code>== |
| − | This will retrieve | + | This will retrieve an integer [[Configuration System | setting]] from Truxton based on its name. |
==<code>getmediaid(id)</code>== | ==<code>getmediaid(id)</code>== | ||
This will retrieve a [[TruxtonMedia | media]] from Truxton based on its [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID.] | This will retrieve a [[TruxtonMedia | media]] from Truxton based on its [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID.] | ||
| + | |||
| + | ==<code>getstring(name)</code>== | ||
| + | This will retrieve a string [[Configuration System | setting]] from Truxton based on its name. | ||
| + | |||
| + | ==<code>machineid</code>== | ||
| + | Returns the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the machine. | ||
==<code>neweventtype()</code>== | ==<code>neweventtype()</code>== | ||
| Line 36: | Line 42: | ||
==<code>newinvestigation()</code>== | ==<code>newinvestigation()</code>== | ||
This will create an [[TruxtonInvestigation | investigation]] object. | This will create an [[TruxtonInvestigation | investigation]] object. | ||
| + | |||
| + | ==<code>newmedia()</code>== | ||
| + | This will create a [[TruxtonMedia | media]] object. | ||
==<code>newrelation()</code>== | ==<code>newrelation()</code>== | ||
This will create a [[TruxtonRelation | relation]] object. | This will create a [[TruxtonRelation | relation]] object. | ||
| − | ==<code> | + | ==<code>version</code>== |
| − | + | Returns the version string. | |
=Sample= | =Sample= | ||
Revision as of 06:22, 27 June 2020
This class give you access to Truxton at a global level.
Contents
Attributes and Methods
closed
It will return True if the the connection to Truxton is closed, False otherwise.
createtag(name, description)
This will create a new tag in Truxton.
After calling this method, you can tag other items using only the name.
etlid
Returns the GUID of the ETL if it is running.
getbool(name)
This will retrieve a boolean setting from Truxton based on its name.
getfilehash(hash)
This will retrieve a file from Truxton based on its MD5 hash.
getfileid(id)
This will retrieve a file from Truxton based on its GUID.
getint(name)
This will retrieve an integer setting from Truxton based on its name.
getmediaid(id)
This will retrieve a media from Truxton based on its GUID.
getstring(name)
This will retrieve a string setting from Truxton based on its name.
machineid
Returns the GUID of the machine.
neweventtype()
This will create an event type object.
newexporter()
This will create an exporter object.
newinvestigation()
This will create an investigation object.
newmedia()
This will create a media object.
newrelation()
This will create a relation object.
version
Returns the version string.
Sample
import truxton
import shutil
from datetime import datetime
from calendar import timegm
from pathlib import Path
EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000
def date_to_filetime(dt):
return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)
def create_event_type(t, id, name):
event_type = t.neweventtype()
event_type.id = id
event_type.name = name
event_type.save()
def add_file(parent_truxton_file, filename):
source_file = open(filename, "rb")
child = parent_truxton_file.newchild()
child.name = Path(filename).name
shutil.copyfileobj(source_file, child)
source_file.close()
child.save()
return child
def add_media(t):
media = t.newmedia()
media.name = "Public Documents"
media.description = "Publicly available documents"
media.case = "DC-SNAFU-2016.2020"
media.evidencebag = "EV-0937459386623-a"
media.originator = "Jeffrey Jensen"
media.latitude = 38.897661
media.longitude = -77.036458
media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
media.save()
return media
def add_ec(parent_file ):
child_file = add_file(parent_file, "JW-v-DOJ-reply-02743.pdf")
a = child_file.newartifact()
a.type = truxton.ENTITY_TYPE_ACCOUNT
a.value = "r0cker"
a.datatype = truxton.DATA_TYPE_ASCII
a.length = 6
a.save()
b = child_file.newartifact()
b.type = truxton.ENTITY_TYPE_PERSON
b.value = "Bob Smith"
b.datatype = truxton.DATA_TYPE_ASCII
b.length = 9
b.save()
relation = child_file.newrelation()
relation.a = a.id
relation.atype = truxton.OBJECT_TYPE_ENTITY
relation.b = b.id
relation.btype = truxton.OBJECT_TYPE_ENTITY
relation.relation = truxton.RELATION_LOGON_ACCOUNT
relation.save()
def main():
t = truxton.create()
media = add_media(t)
root_file = media.addroot()
root_file.save()
add_ec(root_file)
if __name__ == "__main__":
main()