TruxtonMedia
This class represents a piece of media in Truxton.
Contents
Attributes and Methods
case
A case number for this media.
Even though media came in under one case doesn't mean it can't be part of another.
This corresponds to the CaseNumber column of the Media table.
configid
This is the path the media took through the exploitation process.
This corresponds to the LoadConfigurationID column of the Media table.
It should be set to one of the values in the ID column of the LoadConfiguration table or a predefined constant.
description
A description of the investigation.
This corresponds to the Description column of the Investigation table.
id
A GUID for the investigation.
This corresponds to the ID column of the Investigation table.
jurisdiction
The jurisdiction for whom this investigation is being conducted.
This corresponds to the Name column of the Jurisdiction table.
name
The name of this investigation.
This corresponds to the Name column of the Investigation table.
removemedia(id)
Removes the given media from this investigation.
The id parameter is the GUID of the media to remove.
This is valid only after a call to save() and does not delete the media.
save()
This will commit the information to the Investigation table.
It will return True if the record was saved to the database, False if there was an error.
status
The name of this investigation.
This corresponds to the InvestigationStatusID column of the Investigation table.
It should contain a value from the ID column of the InvestigationStatus table.
type
The type of the investigation.
This corresponds to the InvestigationTypeID column of the Investigation table or it can be a predefined constant.
It should contain a value from the ID column of the InvestigationType table.
Sample
import truxton
import shutil
from datetime import datetime
from calendar import timegm
from pathlib import Path
EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000
EVENT_TYPE_FBI = 20001
def date_to_filetime(dt):
return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)
def add_file(parent_truxton_file, filename):
source_file = open(filename, "rb")
child = parent_truxton_file.newchild()
child.name = Path(filename).name
shutil.copyfileobj(source_file, child)
source_file.close()
child.save()
return child
def add_media(t):
media = t.newmedia()
media.name = "Public Documents"
media.description = "Publicly available documents"
media.case = "DC-SNAFU-2016.2020"
media.evidencebag = "EV-0937459386623-a"
media.originator = "Jeffrey Jensen"
media.latitude = 38.897661
media.longitude = -77.036458
media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
media.save()
return media
def add_cs(parent_file ):
child_file = add_file(parent_file, "cs.jpg")
gps = child_file.newlocation()
gps.type = truxton.LOCATION_TYPE_MEETING
gps.latitude = 51.487329
gps.longitude = -0.124057
gps.label = "HQ"
gps.when= date_to_filetime(datetime.fromisoformat("2016-04-01T12:00:00-05:00"))
gps.save()
def create_investigation(t):
investigation = t.newinvestigation()
investigation.name = "Collusion"
investigation.description = "United States vs. John Smith"
investigation.case = "DC-SNAFU-2016.2020"
investigation.status = truxton.INVESTIGATION_STATUS_OPEN
investigation.type = truxton.INVESTIGATION_TYPE_FRAUD
investigation.save()
return investigation
def main():
t = truxton.create()
new_type = t.neweventtype()
new_type.id = EVENT_TYPE_FBI
new_type.name = "FBI Actions"
new_type.save()
investigation = create_investigation(t)
media = add_media(t)
root_file = media.addroot()
root_file.save()
investigation.addmedia(media.id)
add_cs(root_file)
if __name__ == "__main__":
main()