How Truxton Works

From truxwiki.com
Revision as of 12:15, 10 June 2020 by Sam (talk | contribs)
Jump to navigation Jump to search

Truxton was designed to exploit data in a scalable way. You can add more exploitation processes on your loader machine or you can add more machines to the exploitation process.

This article will walk you through the path data takes through Truxton. We will not give an overview of the design of the Truxton Architecture.

The process can be broken down into discrete stages. All processes running at a given stage execute in parallel.

Load

Someone has decided that they have data that needs Truxton exploitation. Let's say it is a hard drive image in the popular E01 format, Bob.E01 This is the first step in exploiting data.

The entry point for Truxton is the Load process.

load.exe T:\Bob.E01

Load will open the file, determine what type it is and navigate it. Load's purpose in life is to find files, identify their type, eliminate their contents based on known-good MD5 hashes, put the meta-data about the file into a database, contents into a depot, then send messages to other ETL processes that have registered to receive that type of file.

Expand

The next stage, which runs in parallel with Load, can produce more files.