TruxtonFileIO

From truxwiki.com
Jump to navigation Jump to search

This class provides read-only access to a file's contents in Truxton.

IOBase Methods

From IOBase it implements:

RawIOBase

From RawIOBase it implements:

Truxton Methods

The above methods will let you read from a file in Truxton as if it were any other file in Python. The following methods are also present to make tasks of adding items extracted from a file easier.

Properties

accessed

When the file was last accessed in FILETIME ticks. This corresponds to the LastAccess column of the File table.

attributes

An integer value representing the attributes of the file. For a Microsoft filesystem, it can be a combination of the file attribute flags. This corresponds to the Attributes column of the File table.

created

When the file was created in FILETIME ticks. This corresponds to the Created column of the File table.

diskoffset

The offset, in bytes, of the first byte of the contents of the file on the physical disk. This corresponds to the PhysicalDiskOffset column of the File table.

entropy

Shannon's entropy of the contents of the file. This corresponds to the RawEntropy column of the File table.

hash

The MD5 hash of the contents of the file. This corresponds to the HashID column of the File table.

id

The GUID of the file record. This corresponds to the ID column of the File table.

mediaid

The GUID of the media the child file came from. This corresponds to the MediaID column of the File table.

modified

When the file was last written in FILETIME ticks. This corresponds to the LastWrite column of the File table.

name

The name of the file.

origin

Where the file came from. It should be one of the origin values. This corresponds to the OriginID column of the File table.

parentid

The GUID of the parent of this file. This corresponds to the ParentFileID column of the File table.

size

The size, in bytes, of the file. This corresponds to the OSLength column of the File table.

status

The status of the contents of the file. It should be one of the content status values. This corresponds to the ContentStatusID column of the File table.

type

The type of the file. This corresponds to the FileTypeID column of the File table.

Sample

This will retrieve a file from Truxton, print the name and hash as stored in the database then calculate a hash on the contents and print that.

import truxton
import hashlib

def main():
  t = truxton.create()
  file = t.getfileid("5ec2a123-74d6-5da7-0653-4e6800000000")
  print(file.hash + " is the hash in the database for " + file.name )
  bytes = file.readall()
  readable_hash = hashlib.md5(bytes).hexdigest()
  print(readable_hash + " is the calculated hash of the contents")

if __name__ == "__main__":
  main()