Difference between revisions of "TruxtonInvestigationEvent"

From truxwiki.com
Jump to navigation Jump to search
(Created page with "This class lets you add an investigation event to Truxton. =Attributes and Methods= ==<code>color: int</code>== Sets the color of the flag to paint on the timeline. This corr...")
 
Line 31: Line 31:
 
The type of investigation event. 1 - Status change, 2 - Comment.
 
The type of investigation event. 1 - Status change, 2 - Comment.
 
This corresponds to the <code>[InvestigationEventTypeID]</code> column of the <code>[InvestigationEvent]</code> table.
 
This corresponds to the <code>[InvestigationEventTypeID]</code> column of the <code>[InvestigationEvent]</code> table.
 +
 +
==<code>when: int</code>==
 +
When the event happened in [https://docs.microsoft.com/en-us/windows/win32/api/minwinbase/ns-minwinbase-filetime FILETIME] ticks.
 +
This corresponds to the <code>[When]</code> column of the <code>[InvestigationEvent]</code> table.
  
  
 
=Sample=
 
=Sample=
<source lang="Python" highlight="56-61,80">
+
<source lang="Python" highlight="22-25" line>
 
import sys
 
import sys
 
sys.path.append('C:/Program Files/Truxton/SDK')
 
sys.path.append('C:/Program Files/Truxton/SDK')
 
import truxton
 
import truxton
import shutil
 
 
from datetime import datetime
 
from calendar import timegm
 
from pathlib import Path
 
 
EPOCH_AS_FILETIME = 116444736000000000
 
HUNDREDS_OF_NANOSECONDS = 10000000
 
 
EVENT_TYPE_FBI = 20001
 
 
def date_to_filetime(dt):
 
  return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)
 
 
def add_file(parent_truxton_file, filename):
 
  source_file = open(filename, "rb")
 
  child = parent_truxton_file.newchild()
 
  child.name = Path(filename).name
 
  shutil.copyfileobj(source_file, child)
 
  source_file.close()
 
  child.save()
 
  return child
 
 
def add_media(t):
 
  media = t.newmedia()
 
 
  media.name = "Public Documents"
 
  media.description = "Publicly available documents"
 
  media.case = "DC-SNAFU-2016.2020"
 
  media.evidencebag = "EV-0937459386623-a"
 
  media.originator = "Jeffrey Jensen"
 
  media.latitude = 38.897661
 
  media.longitude = -77.036458
 
  media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
 
  media.save()
 
 
  return media
 
 
def add_cs(parent_file ):
 
  child_file = add_file(parent_file, "cs.jpg")
 
 
  gps = child_file.newlocation()
 
  gps.type = truxton.LOCATION_TYPE_MEETING
 
  gps.latitude = 51.487329
 
  gps.longitude = -0.124057
 
  gps.label = "HQ"
 
  gps.when= date_to_filetime(datetime.fromisoformat("2016-04-01T12:00:00-05:00"))
 
  gps.save()
 
  
 
def create_investigation(t):
 
def create_investigation(t):
Line 101: Line 57:
 
def main():
 
def main():
 
   t = truxton.create()
 
   t = truxton.create()
 
  new_type = t.neweventtype()
 
  new_type.id = EVENT_TYPE_FBI
 
  new_type.name = "FBI Actions"
 
  new_type.save()
 
  
 
   investigation = create_investigation(t)
 
   investigation = create_investigation(t)
  
   media = add_media(t)
+
   investigation_event = investigation.createevent()
 
+
  investigation_event.text = "I did this"
   root_file = media.addroot()
+
   investigation_event.when = truxton.parsetime("2016-08-15T12:05:00-05:00")
   root_file.save()
+
   investigation_event.save()
 
 
  investigation.addmedia(media.id)
 
  
   add_cs(root_file)
+
   return None
  
 
if __name__ == "__main__":
 
if __name__ == "__main__":
 
   main()
 
   main()
 
</source>
 
</source>

Revision as of 11:13, 25 October 2022

This class lets you add an investigation event to Truxton.

Attributes and Methods

color: int

Sets the color of the flag to paint on the timeline. This corresponds to the [Color] column of the [InvestigationEvent] table.

id: str

A GUID for the investigation. This corresponds to the [ID] column of the [InvestigationEvent] table.

investigationid: str

A GUID for the investigation this event belongs to. This corresponds to the [ID] column of the [Investigation] table and is stored in the [InvestigationID] column of the [InvestigationEvent] table.

status: int

This is the status of the investigation. It should be a value that appears in the [ID] column of a row in the InvestigationStatus table. This corresponds to the [InvestigationStatusID] column of the [InvestigationEvent] table.

save() -> boolean

This will commit the information to the [InvestigationEvent] table. It will return True if the record was saved to the database, False if there was an error.

text: str

The text to display on the event flag. This corresponds to the [Text] column of the [InvestigationEvent] table.

type: int

The type of investigation event. 1 - Status change, 2 - Comment. This corresponds to the [InvestigationEventTypeID] column of the [InvestigationEvent] table.

when: int

When the event happened in FILETIME ticks. This corresponds to the [When] column of the [InvestigationEvent] table.


Sample

 1 import sys
 2 sys.path.append('C:/Program Files/Truxton/SDK')
 3 import truxton
 4 
 5 def create_investigation(t):
 6   investigation = t.newinvestigation()
 7 
 8   investigation.name = "Collusion"
 9   investigation.description = "United States vs. John Smith"
10   investigation.case = "DC-SNAFU-2016.2020"
11   investigation.status = truxton.INVESTIGATION_STATUS_OPEN
12   investigation.type = truxton.INVESTIGATION_TYPE_FRAUD
13   investigation.save()
14 
15   return investigation
16 
17 def main():
18   t = truxton.create()
19 
20   investigation = create_investigation(t)
21 
22   investigation_event = investigation.createevent()
23   investigation_event.text = "I did this"
24   investigation_event.when = truxton.parsetime("2016-08-15T12:05:00-05:00")
25   investigation_event.save()
26 
27   return None
28 
29 if __name__ == "__main__":
30   main()