TruxtonETL

From truxwiki.com
Jump to navigation Jump to search

This class provides capability to participate in Truxton's ETL pipeling. You can implement your own form of file exploitation. You can subscribe to events...

Properties

  • depot - set id only
  • description -
  • dtype - set only
  • id - set only
  • name -
  • poly - set only
  • queue
  • stage - set only
  • version - set only

Methods

  • addarg
  • addtype
  • getmessage
  • sendmehash
  • sendmefileid
  • sendmefiles
  • sendmelocalfile

Sample

import truxton

def main():
  etl = truxton.etl()
  etl.name = "My New ETL"
  etl.description = "This ETL processes files in the Truxton system"
  etl.queue = "anewetl"
  etl.stage = 40
  etl.id = 9999

  message = etl.getmessage()

  while message is not None:
    file_in_truxton = message.file()

    # YOUR FORENSIC CODE GOES HERE

    line_of_text = file_in_truxton.readline()

    if "[SetupAPI" in line_of_text:
      child = file_in_truxton.newchild()
      child.name = "Child file from New ETL"
      child.write("This is the file you were looking for.")
      child.save()

if __name__ == "__main__":
  main()