TruxtonObject
Jump to navigation
Jump to search
This class give you access to Truxton at a global level.
Contents
Attributes and Methods
closed
Returns true if closed
etlid
Returns the globally unqiue identifier of the ETL if it is running.
machineid
Returns the globally unique identifier of the machine.
version
Returns the version string.
createtag(name, description)
This will commit the information to the Relation table.
It will return True if the record was saved to the database, False if there was an error.
getfileid(id)
getfilehash(hash)
neweventtype()
newexporter()
newinvestigation()
newrelation()
newmedia()
Sample
import truxton
import shutil
from datetime import datetime
from calendar import timegm
from pathlib import Path
EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000
def date_to_filetime(dt):
return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)
def create_event_type(t, id, name):
event_type = t.neweventtype()
event_type.id = id
event_type.name = name
event_type.save()
def add_file(parent_truxton_file, filename):
source_file = open(filename, "rb")
child = parent_truxton_file.newchild()
child.name = Path(filename).name
shutil.copyfileobj(source_file, child)
source_file.close()
child.save()
return child
def add_media(t):
media = t.newmedia()
media.name = "Public Documents"
media.description = "Publicly available documents"
media.case = "DC-SNAFU-2016.2020"
media.evidencebag = "EV-0937459386623-a"
media.originator = "Jeffrey Jensen"
media.latitude = 38.897661
media.longitude = -77.036458
media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
media.save()
return media
def add_ec(parent_file ):
child_file = add_file(parent_file, "JW-v-DOJ-reply-02743.pdf")
a = child_file.newartifact()
a.type = truxton.ENTITY_TYPE_ACCOUNT
a.value = "r0cker"
a.datatype = truxton.DATA_TYPE_ASCII
a.length = 6
a.save()
b = child_file.newartifact()
b.type = truxton.ENTITY_TYPE_PERSON
b.value = "Bob Smith"
b.datatype = truxton.DATA_TYPE_ASCII
b.length = 9
b.save()
relation = child_file.newrelation()
relation.a = a.id
relation.atype = truxton.OBJECT_TYPE_ENTITY
relation.b = b.id
relation.btype = truxton.OBJECT_TYPE_ENTITY
relation.relation = truxton.RELATION_LOGON_ACCOUNT
relation.save()
def main():
t = truxton.create()
media = add_media(t)
root_file = media.addroot()
root_file.save()
add_ec(root_file)
if __name__ == "__main__":
main()