TruxtonUSB
This class lets you add to the [USBDevice] table in Truxton.
Contents
Attributes and Methods
deviceid
A GUID assigned to the device by Windows.
devicetype
This corresponds to the [USBDeviceTypeID] column of the [USBDevice] table.
It should be a value from the [ID] column of the [USBDeviceType] table.
Not used at this time.
fileid
The GUID of the file this device came from.
This corresponds to the [FileID] column of the [USBDevice] table.
id
This is the GUID of the record.
It becomes non-zero after save() has been called.
This corresponds to the [ID] column of the [USBDevice] table.
mediaid
This is the GUID of the media this device came from.
This corresponds to the [MediaID] column of the [USBDevice] table.
offset
The offset into the file where this device was found.
This corresponds to the [Offset] column of the [USBDevice] table.
productid
The product id of the device.
This corresponds to the [PID] column of the [USBDevice] table.
This may contain a value in the [PID] column of the [USBPIDVID] table.
revision
The revision of the device.
save()
This will commit the information to the [USBDevice] table.
It will return True if the record was saved to the database, False if there was an error.
tag(tag, reason, origin)
This creates a tag associated with this device in Truxton.
The tag parameter is a short, one or two word, bit of text that will be displayed in the UI.
The reason is a sentence explaining why this device was tagged.
The origin is either TAG_ORIGIN_AUTOMATIC (1) or TAG_ORIGIN_HUMAN (2).
It will return
True if the tag was associated with the device, False on failure.
vendorid
The vendor id (VID) of the device.
This corresponds to the [VID] column of the [USBDevice] table.
when
The time associated with this device in FILETIME ticks.
Sample
import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton
import shutil
from datetime import datetime
from calendar import timegm
from pathlib import Path
EPOCH_AS_FILETIME = 116444736000000000
HUNDREDS_OF_NANOSECONDS = 10000000
def date_to_filetime(dt):
return EPOCH_AS_FILETIME + (timegm(dt.timetuple()) * HUNDREDS_OF_NANOSECONDS)
def ticks(iso8601):
return date_to_filetime(datetime.fromisoformat(iso8601))
def add_file(parent_truxton_file, filename):
source_file = open(filename, "rb")
child = parent_truxton_file.newchild()
child.name = Path(filename).name
shutil.copyfileobj(source_file, child)
source_file.close()
child.save()
return child
def add_media(t):
media = t.newmedia()
media.name = "Public Documents"
media.description = "Publicly available documents"
media.case = "DC-SNAFU-2016.2020"
media.evidencebag = "EV-0937459386623-a"
media.originator = "Jeffrey Jensen"
media.latitude = 38.897661
media.longitude = -77.036458
media.type = truxton.MEDIA_TYPE_LOGICAL_FILES
media.save()
return media
def add_cs(parent_file ):
child_file = add_file(parent_file, "480057685-2020-10-13-Submission-SJC-SSCI-Part-2-of-2.pdf")
# Now add the SanDisk Cruzer Glide 8GB
thumbdrive = child_file.newusb()
thumbdrive.vid = 1921
thumbdrive.pid = 21808
thumbdrive.when = ticks("2016-12-20T11:00:00-05:00")
thumbdrive.save()
return
def main():
t = truxton.create()
media = add_media(t)
root_file = media.addroot()
root_file.save()
add_cs(root_file)
if __name__ == "__main__":
main()