TruxtonMessage

From truxwiki.com
Revision as of 15:12, 27 January 2024 by Sam (talk | contribs) (→‎depotid: str)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

This class encapsulates the message object that is the basis for the Truxton's ETL pipeline.

Attributes and Methods

depotid: str

This is the GUID of the depot file that stores the contents of the file. This identifier corresponds to the [ID] column of the [Depot] table.

depotlength: int

The number of bytes in the depot file that make up this file's contents. This corresponds to the [Length] column of the [Content] table.

depotname: str

The name of the depot that contains the file's contents. This corresponds to the [Filename] column of the [Depot] table.

depotoffset: int

The offset into the depot where the first byte of the file resides. This corresponds to the [Offset] column of the [Content] table.

dontroute: int

This integer controls whether the message should be further routed through the message bus. This is usually only set when debugging an ETL process.

file() -> TruxtonFileIO

This method will return a read-only file that you can use to read the contents of the file.

fileid: str

This is the GUID of the file. This identifier corresponds to the [ID] column of the [File] table.

filetype: int

The type of the file. This corresponds to the [FileTypeID] column of the [File] table.

hash: str

The MD5 hash of the contents of the file. This corresponds to the [HashID] column of the [File] table.

media() -> TruxtonMedia

Retrieves the media object associated with this message.

mediaid: str

This is the GUID of the file. This identifier corresponds to the [MediaID] column of the [File] table.

parentid: str

This is the GUID of the file. This identifier corresponds to the [ParentID] column of the [File] table.

priority: int

This integer value controls the prioriy of the message. High values have greater priority than lower values.

queueempty: int

This integer tells you if your message queue is empty. When this value is non-zero, the message queue is empty.

route() -> None

This method will send the message using the current route to the message bus.

routeid: int

This integer represents the path that files should take through the exploitation processes. It should be a value in the [LoadConfigurationID] column of the [ETLRoute] table.

send(queue_name: str) -> boolean

This method will send the message to the specified message queue. It will return True if the message was sent, False otherwise.

signature: int

The first four bytes of the file stored as an integer. This corresponds to the [Signature] column of the [File] table.

Sample

import sys
sys.path.append('C:/Program Files/Truxton/SDK')
import truxton

def main():
  etl = truxton.etl()
  etl.name = "My New ETL"
  etl.description = "This ETL processes files in the Truxton system"
  etl.queue = "anewetl"
  etl.stage = 40
  etl.expanderid = 0x05fc0bf6a57726a0
  etl.version = 0
  etl.depot = "thumbnail"
  etl.depotype = truxton.DEPOT_TYPE_THUMBNAILS
  etl.poly = 0

  etl.addarg("--verbose")
  etl.addarg("Yes")

  etl.sendmefileid("5ecbebc4-9937-2b88-f691-91a800000024")
  etl.sendmehash("baa51f0cc8361660df911e06e7637485")
  etl.sendmefiles(truxton.Type_JPEGWithExif, 100)
  etl.sendmefiles(truxton.Type_TIFFWithExif, 500)
  etl.sendmelocalfile( "C:/Test Files/Video/Fragmented/Recovered Video.mp4", truxton.Type_MPEG4Video, 0 )

  message = etl.getmessage()

  while message is not None:
    file_in_truxton = message.file()

    # YOUR FORENSIC CODE GOES HERE

    line_of_text = file_in_truxton.readline()

    if "[SetupAPI" in line_of_text:
      child = file_in_truxton.newchild()
      child.name = "Child file from New ETL"
      child.write("This is the file you were looking for.")
      child.save()

    message.type = 11000;
    message.route()

    # Pause here until we get another message from the "anewetl" message queue
    message = etl.getmessage()

if __name__ == "__main__":
  sys.exit(main())