TruxtonETL

From truxwiki.com
Revision as of 10:29, 26 May 2020 by Sam (talk | contribs) (→‎Syntax)
Jump to navigation Jump to search

This class provides capability to participate in Truxton's ETL pipeline. You can implement your own form of file exploitation. You can subscribe to events...

Properties

depot

This property is used in generating the depot filename.

description

This property

dtype

This property - set only

id

This property - set only

name

This property

poly

This property - set only

queue

This property

stage

This property - set only

version

This property - set only

Methods

addarg

This is used to build the command line arguments for the process. Truxton will automatically parse the command line for you but this allows you to programmatically force command line options.

Syntax

addarg(argument: str)

Arguments

argument

The command line argument to add.

addtype

This method

getmessage

This method

sendmehash

This method

sendmefileid

This method

sendmefiles

This method

sendmelocalfile

This method

Sample

import truxton

def main():
  etl = truxton.etl()
  etl.name = "My New ETL"
  etl.description = "This ETL processes files in the Truxton system"
  etl.queue = "anewetl"
  etl.stage = 40
  etl.id = 9999

  etl.addarg("--verbose")
  etl.addarg("Yes")

  message = etl.getmessage()

  while message is not None:
    file_in_truxton = message.file()

    # YOUR FORENSIC CODE GOES HERE

    line_of_text = file_in_truxton.readline()

    if "[SetupAPI" in line_of_text:
      child = file_in_truxton.newchild()
      child.name = "Child file from New ETL"
      child.write("This is the file you were looking for.")
      child.save()

if __name__ == "__main__":
  main()