Truxton update investigation type
Jump to navigation
Jump to search
Sets the type of the investigation.
This corresponds to the [InvestigationTypeID] column of the [Investigation] table.
It should contain a value from the [ID] column from the [InvestigationType] table or a defined constant.
Contents
Syntax
void truxton_update_investigation_type( uint64_t truxton_handle, char const * investigation_id, uint64_t investigation_type );
Parameters
truxton_handle
The Truxton instance that contains this investigation.
This handle comes from calling truxton_create().
investigation_id
The string representation of the GUID of the investigation to modify.
investigation_type
The type of the investigation.
This should be a value from the [ID] column from the [InvestigationType] table or a defined constant.
Sample
void add_folder( uint64_t truxton, uint64_t parent_file )
{
truxton_start_adding_files( truxton );
uint64_t child = truxton_child_file_create( truxton );
char id[40];
truxton_file_get_id( parent_file, id, sizeof(id) );
truxton_child_file_set_parent_id( child, id );
truxton_child_file_set_type( child, Type_Directory );
truxton_child_file_set_name( child, "Custom Exploits Folder" );
FILETIME now;
GetSystemTimePreciseAsFileTime( &now );
ULARGE_INTEGER ticks;
ticks.LowPart = now.dwLowDateTime;
ticks.HighPart = now.dwHighDateTime;
truxton_child_file_set_created( child, ticks.QuadPart );
truxton_child_file_set_accessed( child, ticks.QuadPart );
truxton_child_file_set_modified( child, ticks.QuadPart );
truxton_child_file_set_origin( child, ORIGIN_GENERATED );
truxton_child_file_set_path( child, "Files/This File" );
if ( truxton_child_file_save( child ) == 0 )
{
printf( "Failed to add child to Truxton\n" );
}
truxton_child_file_destroy( child );
}