Difference between revisions of "TruxtonUSB"

From truxwiki.com
Jump to navigation Jump to search
Line 2: Line 2:
 
=Attributes and Methods=
 
=Attributes and Methods=
  
==<code>deviceid</code>==
+
==<code>deviceid: str</code>==
 
A [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] assigned to the device by Windows.
 
A [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] assigned to the device by Windows.
  
==<code>devicetype</code>==
+
==<code>devicetype: int</code>==
 
This corresponds to the <code>[USBDeviceTypeID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
 
This corresponds to the <code>[USBDeviceTypeID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
 
It should be a value from the <code>[ID]</code> column of the <code>[USBDeviceType]</code> table.
 
It should be a value from the <code>[ID]</code> column of the <code>[USBDeviceType]</code> table.
 
Not used at this time.
 
Not used at this time.
  
==<code>fileid</code>==
+
==<code>fileid: str</code>==
 
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this device came from.
 
The [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this device came from.
 
This corresponds to the <code>[FileID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
 
This corresponds to the <code>[FileID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
  
==<code>id</code>==
+
==<code>id: str</code>==
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the record.
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the record.
 
It becomes non-zero after <code>save()</code> has been called.
 
It becomes non-zero after <code>save()</code> has been called.
 
This corresponds to the <code>[ID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
 
This corresponds to the <code>[ID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
  
==<code>mediaid</code>==
+
==<code>mediaid: str</code>==
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media this device came from.
 
This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the media this device came from.
 
This corresponds to the <code>[MediaID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
 
This corresponds to the <code>[MediaID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
  
==<code>offset</code>==
+
==<code>offset: int</code>==
 
The offset into the file where this device was found.
 
The offset into the file where this device was found.
 
This corresponds to the <code>[Offset]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
 
This corresponds to the <code>[Offset]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
  
==<code>productid</code>==
+
==<code>productid: int</code>==
 
The product id of the device.
 
The product id of the device.
 
This corresponds to the <code>[PID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
 
This corresponds to the <code>[PID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
 
This may contain a value in the <code>[PID]</code> column of the <code>[USBPIDVID]</code> table.
 
This may contain a value in the <code>[PID]</code> column of the <code>[USBPIDVID]</code> table.
  
==<code>revision</code>==
+
==<code>revision: int</code>==
 
The revision of the device.
 
The revision of the device.
  
==<code>save()</code>==
+
==<code>save() -> bool</code>==
 
This will commit the information to the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
 
This will commit the information to the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
 
It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error.
 
It will return [https://docs.python.org/3/library/constants.html#True True] if the record was saved to the database, [https://docs.python.org/3/library/constants.html#False False] if there was an error.
  
==<code>tag(tag, reason, origin)</code>==
+
==<code>tag(tag: str, reason: str, origin: int) -> bool</code>==
 
This creates a tag associated with this device in Truxton.
 
This creates a tag associated with this device in Truxton.
 
The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI.
 
The <code>tag</code> parameter is a short, one or two word, bit of text that will be displayed in the UI.
Line 47: Line 47:
 
[https://docs.python.org/3.8/library/constants.html?highlight=false#True True] if the tag was associated with the device, [https://docs.python.org/3.8/library/constants.html?highlight=false#False False] on failure.
 
[https://docs.python.org/3.8/library/constants.html?highlight=false#True True] if the tag was associated with the device, [https://docs.python.org/3.8/library/constants.html?highlight=false#False False] on failure.
  
==<code>vendorid</code>==
+
==<code>vendorid: int</code>==
 
The [https://en.wikipedia.org/wiki/USB_Implementers_Forum#Obtaining_a_vendor_ID vendor id] (VID) of the device.
 
The [https://en.wikipedia.org/wiki/USB_Implementers_Forum#Obtaining_a_vendor_ID vendor id] (VID) of the device.
 
This corresponds to the <code>[VID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
 
This corresponds to the <code>[VID]</code> column of the <code><nowiki>[</nowiki>[[USBDevice Table|USBDevice]]<nowiki>]</nowiki></code> table.
  
==<code>when</code>==
+
==<code>when: int</code>==
 
The time associated with this device in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks.
 
The time associated with this device in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks.
  

Revision as of 06:08, 29 July 2022

This class lets you add to the [USBDevice] table in Truxton.

Attributes and Methods

deviceid: str

A GUID assigned to the device by Windows.

devicetype: int

This corresponds to the [USBDeviceTypeID] column of the [USBDevice] table. It should be a value from the [ID] column of the [USBDeviceType] table. Not used at this time.

fileid: str

The GUID of the file this device came from. This corresponds to the [FileID] column of the [USBDevice] table.

id: str

This is the GUID of the record. It becomes non-zero after save() has been called. This corresponds to the [ID] column of the [USBDevice] table.

mediaid: str

This is the GUID of the media this device came from. This corresponds to the [MediaID] column of the [USBDevice] table.

offset: int

The offset into the file where this device was found. This corresponds to the [Offset] column of the [USBDevice] table.

productid: int

The product id of the device. This corresponds to the [PID] column of the [USBDevice] table. This may contain a value in the [PID] column of the [USBPIDVID] table.

revision: int

The revision of the device.

save() -> bool

This will commit the information to the [USBDevice] table. It will return True if the record was saved to the database, False if there was an error.

tag(tag: str, reason: str, origin: int) -> bool

This creates a tag associated with this device in Truxton. The tag parameter is a short, one or two word, bit of text that will be displayed in the UI. The reason is a sentence explaining why this device was tagged. The origin is either TAG_ORIGIN_AUTOMATIC (1) or TAG_ORIGIN_HUMAN (2). It will return True if the tag was associated with the device, False on failure.

vendorid: int

The vendor id (VID) of the device. This corresponds to the [VID] column of the [USBDevice] table.

when: int

The time associated with this device in FILETIME ticks.

Sample

import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil

from datetime import datetime
from calendar import timegm
from pathlib import Path

EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000

def date_to_filetime(dt):
  return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)

def ticks(iso8601):
  return date_to_filetime(datetime.fromisoformat(iso8601))

def add_file(parent_truxton_file, filename):
  source_file = open(filename, "rb")
  child = parent_truxton_file.newchild()
  child.name = Path(filename).name
  shutil.copyfileobj(source_file, child)
  source_file.close()
  child.save()
  return child

def add_media(t):
  media = t.newmedia()

  media.name = "Public Documents"
  media.description = "Publicly available documents"
  media.case = "DC-SNAFU-2016.2020"
  media.evidencebag = "EV-0937459386623-a"
  media.originator = "Jeffrey Jensen"
  media.latitude = 38.897661
  media.longitude = -77.036458
  media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
  media.save()

  return media

def add_cs(parent_file ):
  child_file = add_file(parent_file, "480057685-2020-10-13-Submission-SJC-SSCI-Part-2-of-2.pdf")

  # Now add the SanDisk Cruzer Glide 8GB

  thumbdrive = child_file.newusb()
  thumbdrive.vid = 1921
  thumbdrive.pid = 21808
  thumbdrive.when = ticks("2016-12-20T11:00:00-05:00")
  thumbdrive.save()

  return

def main():
  t = truxton.create()

  media = add_media(t)

  root_file = media.addroot()
  root_file.save()

  add_cs(root_file)

if __name__ == "__main__":
  main()