Truxton child file tag

From truxwiki.com
Revision as of 06:25, 13 November 2020 by Sam (talk | contribs)
Jump to navigation Jump to search

This will tag the child file. You can only tag a child file after truxton_child_file_save() has been called.

Syntax

void truxton_child_file_tag( uint64_t child_handle, char const * tag_name, char const * why, uint64_t origin );

Parameters

child_handle

The handle created by the truxton_child_file_create or truxton_file_create_child call.

tag_name

The small bit of text that will serve as the tag. This will show up in the user interface.

why

The reason why this item was tagged.

origin

What produced this tag. If an algorithm produced this tag, it should be set to 1. If you are calling this method because a human told you to, the value should be 2.

Sample

#define TAG_ORIGIN_AUTOMATIC (1)
#define TAG_ORIGIN_HUMAN     (2)

void add_folder(uint64_t truxton, uint64_t parent_file)
{
   truxton_start_adding_files(truxton);

   uint64_t child = truxton_child_file_create(truxton);

   char id[40];

   truxton_file_get_id(parent_file, id, sizeof(id));
   truxton_child_file_set_parent_id(child, id);
   truxton_child_file_set_type(child, Type_Directory);
   truxton_child_file_set_name(child, "Custom Exploits Folder");

   FILETIME now;

   GetSystemTimePreciseAsFileTime(&now);

   ULARGE_INTEGER ticks;

   ticks.LowPart = now.dwLowDateTime;
   ticks.HighPart = now.dwHighDateTime;

   truxton_child_file_set_created(child, ticks.QuadPart);
   truxton_child_file_set_accessed(child, ticks.QuadPart);
   truxton_child_file_set_modified(child, ticks.QuadPart);

   truxton_child_file_set_disk_offset(child, 5464419);
   truxton_child_file_set_path(child, "Files/This File" );

   if ( truxton_child_file_save(child) == 0 )
   {
      printf( "Failed to add child to Truxton\n" );
   }

   truxton_child_file_tag(child, "Malfoy", "Folder for malware", TAG_ORIGIN_AUTOMATIC);

   truxton_child_file_destroy(child);
}