TruxtonObject

From truxwiki.com
Jump to navigation Jump to search

This class gives you access to Truxton at a global level.

Attributes and Methods

cleandatabase()

This will delete orphaned records from the database.

consolidatedepots()

This will go through the closed depots and merge small depots into larger ones.

closed

It will return True if the the connection to Truxton is closed, False otherwise.

createeverythinghashset(output_filename)

Creates a hash set file from the unique hashes in Truxton.

createinvestigationhashset(investigation_id, output_filename)

Creates a hash set file from the unique hashes in the given investigation.

createmediahashset(media_id, output_filename)

Creates a hash set file from the unique hashes in the given media.

createsubject(name, description)

This will create a subject object.

createtag(name, description)

This will create a new tag in Truxton. After calling this method, you can tag other items using only the name.

deletedepots()

This delete the depot files that have been marked as ToBeDeleted.

deletemedia(media_id)

This will delete a piece of media from Truxton.

etlid

Returns the GUID of the ETL if it is running.

getfilehash(hash)

This will retrieve a file from Truxton based on its MD5 hash.

getfileid(id)

This will retrieve a file from Truxton based on its GUID.

getmediaid(id)

This will retrieve a media from Truxton based on its GUID.

machineid

Returns the GUID of the machine.

newartifacttype()

This will create an artifact type object.

neweventtype()

This will create an event type object.

newexporter()

This will create an exporter object.

newfiletype()

This will create an file type object.

newinvestigation()

This will create an investigation object.

newjurisdiction()

This will create a jurisdiction object.

newmedia()

This will create a media object.

newrelation()

This will create a relation object.

optimizedatabase()

This update the query statistics in the database.

reindexmedia(media_id)

This will send all of the files in a piece of media to the indexer.

version

Returns the version string.

Sample

import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil

from datetime import datetime
from calendar import timegm
from pathlib import Path

EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000

def date_to_filetime(dt):
  return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)

def create_event_type(t, id, name):
  event_type = t.neweventtype()
  event_type.id = id
  event_type.name = name
  event_type.save()

def add_file(parent_truxton_file, filename):
  source_file = open(filename, "rb")
  child = parent_truxton_file.newchild()
  child.name = Path(filename).name
  shutil.copyfileobj(source_file, child)
  source_file.close()
  child.save()

  return child

def add_media(t):
  media = t.newmedia()
  media.name = "Public Documents"
  media.description = "Publicly available documents"
  media.case = "DC-SNAFU-2016.2020"
  media.evidencebag = "EV-0937459386623-a"
  media.originator = "Jeffrey Jensen"
  media.latitude = 38.897661
  media.longitude = -77.036458
  media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
  media.save()

  return media

def add_ec(parent_file ):
  child_file = add_file(parent_file, "JW-v-DOJ-reply-02743.pdf")

  a = child_file.newartifact()
  a.type = truxton.ENTITY_TYPE_ACCOUNT
  a.value = "r0cker"
  a.datatype = truxton.DATA_TYPE_ASCII
  a.length = 6
  a.save()

  b = child_file.newartifact()
  b.type = truxton.ENTITY_TYPE_PERSON
  b.value = "Bob Smith"
  b.datatype = truxton.DATA_TYPE_ASCII
  b.length = 9
  b.save()

  relation = child_file.newrelation()
  relation.a = a.id
  relation.atype = truxton.OBJECT_TYPE_ENTITY
  relation.b = b.id
  relation.btype = truxton.OBJECT_TYPE_ENTITY
  relation.relation = truxton.RELATION_LOGON_ACCOUNT
  relation.save()

def main():
  t = truxton.create()

  print(t.version + '\n' );
  print("Truxton will write to depot files in: " + t.getstring("datadir") + '\n');
  print("The database port is: " + str(t.getint("dbport")) + '\n');
  print("Database was created: " + str(t.getbool("CreateTheDatabase")) + '\n');

  media = add_media(t)

  root_file = media.addroot()
  root_file.save()

  add_ec(root_file)

if __name__ == "__main__":
  main()