Truxton usb set when
Jump to navigation
Jump to search
This sets the date and time of when the the USB device was seen.
It corresponds to the When column of the [USBDevice] table.
Contents
Syntax
void truxton_set_when( uint64_t usb_handle, uint64_t ticks );
Parameters
usb_handle
The handle to the USB object.
This handle comes from calling truxton_usb_create(), truxton_child_file_create_usb(), or truxton_file_create_usb().
ticks
The date in FILETIME ticks.
Sample
void add_thumb_drive( uint64_t truxton, uint64_t media, uint64_t child_file, uint64_t when, uint64_t where )
{
char media_id[ 65 ];
char file_id[ 65 ];
char usb_id[ 65 ];
truxton_media_get_id( media, media_id, sizeof( media_id ) );
truxton_child_file_get_id( child_file, file_id, sizeof( file_id ) );
uint64_t usb = truxton_usb_create( truxton );
truxton_usb_set_file_id( usb, file_id );
truxton_usb_set_media_id( usb, media_id );
truxton_usb_set_when( usb, when );
truxton_usb_set_vendor_id( usb, 0x8EC );
truxton_usb_set_product_id( usb, 0x16 );
truxton_usb_set_file_offset( usb, where );
// Commit the data to the database
if ( truxton_usb_save( usb ) == 0 )
{
printf( "Cannot save USB to the database\n" );
}
else
{
truxton_usb_get_id( usb, usb_id, sizeof( usb_id ) );
printf( "USB information saved to record id %s\n", usb_id );
}
truxton_usb_destroy( usb );
}