TruxtonUSB

From truxwiki.com
Revision as of 07:07, 8 December 2020 by Sam (talk | contribs) (→‎devicetype)
Jump to navigation Jump to search

This class lets you add to the [USBDevice] table in Truxton.

Attributes and Methods

deviceid

A GUID assigned to the device by Windows.

devicetype

This corresponds to the [USBDeviceTypeID] column of the [USBDevice] table. It should be a value from the [ID] column of the [USBDeviceType] table. Not used at this time.

fileid

The GUID of the file this device came from. This corresponds to the [FileID] column of the [USBDevice] table.

id

This is the GUID of the record. It becomes non-zero after save() has been called. This corresponds to the [ID] column of the [USBDevice] table.

mediaid

This is the GUID of the media this device came from. This corresponds to the [MediaID] column of the [USBDevice] table.

offset

The offset into the file where this device was found. This corresponds to the [Offset] column of the [USBDevice] table.

productid

The product id of the device. This corresponds to the [PID] column of the [USBDevice] table. This may contain a value in the [PID] column of the [USBPIDVID] table.

revision

The revision of the device.

save()

This will commit the information to the [USBDevice] table. It will return True if the record was saved to the database, False if there was an error.

tag(tag, reason, origin)

This creates a tag associated with this device in Truxton. The tag parameter is a short, one or two word, bit of text that will be displayed in the UI. The reason is a sentence explaining why this device was tagged. The origin is either TAG_ORIGIN_AUTOMATIC (1) or TAG_ORIGIN_HUMAN (2). It will return True if the tag was associated with the device, False on failure.

vendorid

The vendor id (VID) of the device. This corresponds to the [VID] column of the [USBDevice] table.

when

The time associated with this device in FILETIME ticks.

Sample

import truxton
import shutil

from datetime import datetime
from calendar import timegm
from pathlib import Path

EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000

def date_to_filetime(dt):
  return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)

def add_file(parent_truxton_file, filename):
  source_file = open(filename, "rb")
  child = parent_truxton_file.newchild()
  child.name = Path(filename).name
  shutil.copyfileobj(source_file, child)
  source_file.close()
  child.save()
  return child

def add_media(t):
  media = t.newmedia()

  media.name = "Public Documents"
  media.description = "Publicly available documents"
  media.case = "DC-SNAFU-2016.2020"
  media.evidencebag = "EV-0937459386623-a"
  media.originator = "Jeffrey Jensen"
  media.latitude = 38.897661
  media.longitude = -77.036458
  media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
  media.save()

  return media

def add_cs(parent_file ):
  child_file = add_file(parent_file, "device.db")

  thumbdrive = child_file.newlocation()
  gps.type = truxton.LOCATION_TYPE_MEETING
  gps.latitude = 51.487329
  gps.longitude = -0.124057
  gps.label = "HQ"
  gps.when= date_to_filetime(datetime.fromisoformat("2016-04-01T12:00:00-05:00"))
  gps.save()

def main():
  t = truxton.create()

  media = add_media(t)

  root_file = media.addroot()
  root_file.save()

  add_cs(root_file)

if __name__ == "__main__":
  main()