Truxton update investigation type

From truxwiki.com
Revision as of 09:46, 17 August 2021 by Sam (talk | contribs) (Created page with "Sets the type of the investigation. This corresponds to the <code>[InvestigationTypeID]</code> column of the <code>[Investigation]</code> table. It should contain a value from...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

Sets the type of the investigation. This corresponds to the [InvestigationTypeID] column of the [Investigation] table. It should contain a value from the [ID] column from the [InvestigationType] table or a defined constant.

Syntax

void truxton_update_investigation_type( uint64_t truxton_handle, char const * investigation_id, uint64_t investigation_type );

Parameters

truxton_handle

The handle created by the truxton_child_file_create or truxton_file_create_child call.

investigation_id

The string representation of the GUID of the investigation to modify.

investigation_type

The type of the investigation. This should be a value from the [ID] column from the [InvestigationType] table or a defined constant.

Sample

void add_folder( uint64_t truxton, uint64_t parent_file )
{
   truxton_start_adding_files( truxton );

   uint64_t child = truxton_child_file_create( truxton );

   char id[40];

   truxton_file_get_id( parent_file, id, sizeof(id) );
   truxton_child_file_set_parent_id( child, id );
   truxton_child_file_set_type( child, Type_Directory );
   truxton_child_file_set_name( child, "Custom Exploits Folder" );

   FILETIME now;

   GetSystemTimePreciseAsFileTime( &now );

   ULARGE_INTEGER ticks;

   ticks.LowPart = now.dwLowDateTime;
   ticks.HighPart = now.dwHighDateTime;

   truxton_child_file_set_created( child, ticks.QuadPart );
   truxton_child_file_set_accessed( child, ticks.QuadPart );
   truxton_child_file_set_modified( child, ticks.QuadPart );

   truxton_child_file_set_origin( child, ORIGIN_GENERATED );
   truxton_child_file_set_path( child, "Files/This File" );

   if ( truxton_child_file_save( child ) == 0 )
   {
      printf( "Failed to add child to Truxton\n" );
   }

   truxton_child_file_destroy( child );
}