Origin

From truxwiki.com
Revision as of 16:30, 18 May 2020 by Admin (talk | contribs) (Created page with "When Truxton stores files, it will tell you where the file came from. This is stored in the [Origin] column of the [File] table in the database. {| class="wikitable" ! Name !...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

When Truxton stores files, it will tell you where the file came from. This is stored in the [Origin] column of the [File] table in the database.

Name Value Meaning
ORIGIN_UNKNOWN 0 We don't know where this file came from.
ORIGIN_NORMAL 1 The file came from the media as an overt file. It was a normal entry in the media's filesystem.
ORIGIN_UNDELETED 2 The file is the result of un-deleting it from the source filesystem.
ORIGIN_CARVED 3 The file is the result of searching a byte stream for a file format (carving).
ORIGIN_EXPANDED 4 The file came out of another file in Truxton. Child files of a Zip archive are ORIGIN_EXPANDED
ORIGIN_ASSOCIATED 5 The file was uploaded to Truxton by a user and associated with media.
ORIGIN_GENERATED 6 Truxton generated this file during exploitation. Snippet files are an example.
ORIGIN_EMAIL_BODY 7 The file is the body of an email parsed by Truxton.
ORIGIN_EMAIL_ATTACHMENT 8 The file is an attachment to an email parsed by Truxton.
ORIGIN_VOLUME_SHADOW_COPY 9 The file came from a Volume Shadow in NTFS.
ORIGIN_MMS_ATTACHMENT 10 The file is the payload of an MMS message.
ORIGIN_STITCHED 11 The file was stitched back together from fragments scattered throughout the media free space. It is a de-fragmented carved file.
ORIGIN_SLACK 12 The file came from the slack space of a normal file in the filesystem of the media.