Default ETL Options

From truxwiki.com
Jump to navigation Jump to search

Any exploitation program created by using the Truxton SDK will have the following options built-in. These may be specified in a variety of ways, command line or configuration file.

Name Data Type Minimum Value Maximum Value Default Value Description
aci integer 1000 86400000 10007 The number of milliseconds to wait before checking the [Media] table for the abort-load code
alert_email_from_address string Truxton@localhost The default email address to send notifications from
alert_email_subject string [Truxton Alert] The string to prepend to email subjects when Alerts are generated
carve boolean 0 1 1 Set to true if you want to carve free space for files
carvedroot guid The root file GUID to be the parent of any carved files
carvemode integer 0 2 0 Carving mode. The default of zero means carve on sector boundaries and high value types sub-sector, 1 means (fastest) means only on sector boundaries, 2 means exhaustive sub-sector carving
carveoffset integer 0 18446744073709551615 65536 Carving offset. The offset into the file to begin carving. Depots have a 65536 byte header
carve_threads integer 1 4294967296 1 The number of threads to use when carving files
carveunknown boolean 0 1 0 Set to true if you want to carve unknown file types for files. This can significantly increase load times
case string The case number to associate with this investigation
cmid boolean 0 1 0 Calculate the media for disk images and single files
config string The name of the configuration file
controlledby integer 0 18446744073709551615 0 Used by the Truxton Service to identify ETL process it controls
cunk boolean 0 1 0 Set to true if you want to carve files out of the contents of unidentified files
cws integer 0 4294967296 10485760 Carving window size in bytes. This is the number of bytes the carvers can handle at a time
datadir string The Data directory. This is the root of the default directories for things like HashSets or Depot
dbconnectionstring string The connection string for connecting to the Truxton database
dbflavor integer 1 2 1 The variant of PostgreSQL that should be used. 1 is normal PostgreSQL while 2 is for Yellowbrick
debugfileidmapping boolean 0 1 0 Controls the debugging of the mapping of file system entry identifiers to Truxton GUIDs
dedupemessages boolean 0 1 0 Set to true if you want to have only unique communications in the loaded media. If false, all copies of messages will show up in communications.
deepsleep integer 1000 864000000 45007 The number of milliseconds of inactivity before this ETL goes into deep sleep and disconnects from the database.
deletedfiles boolean 0 1 1 Set to true if you want to process deleted files. If set to false, deleted files will not be recovered
depotdir string Depot directory
depotmaxsize integer 65536 9223372036854775807 1099511627776 The desired maximum size of a depot file
depotpagesize integer 512 1048576 4096 The page boundary where new entries in a depot file will begin
depotshare string The share name of the folder where depot files are stored
differential guid GUID specifying the media that this load should be appended to. A Prism load will first make a hash set of the specified media and use it to eliminate files from this load
ds boolean 0 1 0 Delete setting. When set to true, if this load specified a setting from the database, that setting will be deleted at the end of the load
ecf string %PROGRAMDATA%\Truxton\ETL Control ETL Control Folder
ee boolean 0 1 0 Eliminate Everything. All file contents will be eliminated. Useful for debugging
evb string The label of the evidence bag
excludefilesbytype boolean 0 1 0 Files of a given type(s) should be ignored by the loader
excludes integer 0 65536 0 Comma separated file types to be ignored by the loader
fct integer 306 1000000 306 File Commit Threshold. This is the number of file records that will be sent per commit to the database
fileid guid The GUID of a file in Truxton to load. The contents of the file will not be duplicated
fileslack boolean 0 1 1 Set to true if you want to process the slack space of files. If set to false, slack space will be ignored
filetype integer 0 65536 0 The type of file that should be used to process the file
fqhi integer 4294967296 65536 7500 The file queue high water mark. If more than this number of file records are waiting to be inserted into the database, loading will pause until the database catches up
fqlo integer 4294967296 65536 100 After loading pauses for the database to catch up, the loading will resume when this number of file records are waiting to be inserted into the database
freedepotdir string The Free Depot directory
freedepotshare string The Free Depot share name
globaldedupe bool 0 1 0 Only add unique file contents to Truxton. This is a global check and will slow down loads.
hashset string The name of a hash set file or a comma separated list of hash set file names
hashsetall boolean 0 1 0 When true, create a hash set of all hashes in Truxton and use it as a temporary hash set to eliminate files from this load
hashsetdir string The directory where hash sets are stored
hashseti guid The GUID of the investigation to use as a temporary hash set to eliminate files from this load
hashsetm guid The GUID of the media to use as a temporary hash set to eliminate files from this load
ides string A description of the investigation
iei boolean 0 1 1 Ignore encrypted images. If a partition or filesystem is encrypted, do not process it
iid guid The GUID of the existing investigation to attach this media to
imagelength integer 0 -1 -1 The number of bytes in the disk image to process. -1 is infinite
imageoffset integer 0 9223372036854775807 0 The offset into the disk image to begin processing
in string The name of the investigation
includefilesbytype boolean 0 1 0 Only files of a given type(s) should be processed by the loader
includes integer 0 65536 0 Comma separated file types to be exclusively loaded. All other types of files will be eliminated
investigation guid The GUID of the investigation to create to associate this media with
io datetime The date when this investigation was opened
istatus integer 0 4294967296 1 The status of the investigation. Valid values are in the InvestigationStatus table
itype integer 0 4294967296 1 The type of investigation
jd string A description of the jurisdiction
jurisdiction string The organization on behalf of which this investigation is taking place
justcarve string Take the contents of the given filename and do nothing other than file carving. Treat the given file as free space that needs carving
largedepotdir string The Large Depot directory
largedepotshare string The Large Depot share name
logdir string The name of the directory to write log files
loadas integer 0 65536 0 Force the loader to load the given file as this type. Don't bother attempting to identify the file, just use this type
loader integer 0 65536 0 The type of file that should be used to locate the loader
lq string load The name of the message queue to receive load messages from
maxdate string The latest date that a file will be considered to load
maxsleep integer 1000 864000000 600101 The maximum number of milliseconds to sleep between polling the database
mcsn string The case number for this media
md string A description of the media
media guid The GUID for this media
medialist guid A comma separated list of media GUIDs for use when reprocessing
mediumdepotdir string The Medium Depot directory
mediumdepotshare string The Medium Depot share name
metacarve boolean 0 1 1 Use information from inside a carved file to fill out meta data like name and dates
mi guid The GUID of the investigation this media belongs to
mindate string The earliest date that a file will be considered to load
minsleep integer 1 60000 3011 The minimum number of milliseconds to sleep between polling the database
mlat double -90 90 0 The WGS84 latitude coordinate of where this media was seized
mlong double -180 180 0 The WGS84 longitude coordinate of where this media was seized
mn string The short name of the media
mqconcentrator boolean 0 1 0 Use a concentrator to talk to the message bus
mbconnectionstring string The connection string for connecting to the Truxton Message Bus
mr integer 0 4294967296 0 The route that messages should take. This is a load configuration (ID column of the LoadConfiguration table
mt integer 0 65535 0 The type of media. It should be one of the defined constants
net integer 0 65535 0 Never Eliminate Type. A comma separated list of file types to never eliminate even if the hash appears in a hash set
nocontents boolean 0 1 0 Do not process file contents. This will cause only meta data to be processed
nohashsets boolean 0 1 0 Do not use hash sets to eliminate file contents
norouting boolean 0 1 0 Turn off routing. Do not send any files out for further processing
nostartdelay boolean 0 1 0 When set to true, immediately start ETL processing, otherwise, wait up two seconds before beginning to process messages from the message bus
nostore boolean 0 1 0 File contents are processed (hashed) but never stored
numberofbuffers integer 0 2147483647 2048 The number of buffers to use for disk image reads
numberofbytesperbuffer integer 0 2147483647 65536 The number of bytes in each buffer used to read disk images
numberoffiles integer 0 9223372036854775807 9223372036854775807 The number of files to process
originator string The originator of this media
otherdepotdir string The Other Depot directory
otherdepotshare string The Other Depot share name
parent guid The GUID of a file in Truxton to be the root of this load. The Media GUID associated with this file will become this load's media id
pfiles boolean 0 1 1 Process files
pfree boolean 0 1 1 Process free space
pp string The name of the file containing the Primary Photo of the media
priority integer 0 2147483647 1000 The priority of the data in the load, a high number means this load is more important
prism guid GUID specifying the media that this load should be appended to. A Prism load will first make a hash set of the specified media and use it to eliminate files from this load
queues string A comma separated list of queue names to send files to during reprocessing
random string Debugging option that populates the database with random (but repeatable) data based upon the word given. Longer words produce more data. If you specify an integer, that exact number of files will be produced
rapid boolean 0 1 0 Ultra Rapid Mode. Load is allowed to execute in a limited amount of time targeting only certain files in the media
recovery boolean Perform a quick data recovery load to retrieve photos, videos, documents, etc. All forensic processing is skipped
remoteloader string The full path to the executable to use as a remote loader (overrides loader and loades)
reprocess boolean 0 1 0 When set to true, it will take all file types listed in the includes parameter and send them to the ETL layer
root guid The root file GUID for this load
setting guid The GUID in the ID column of the Setting table. The XML in that record will be parsed as options
skipdupmedia boolean 0 1 0 Ignore duplicate media. Abort the load if the calculated media id already exists in Truxton. Don't load the same disk image twice
slackdepotdir string The Slack space Depot directory
slackdepotshare string The Slack space Depot share name
smalldepotdir string The Small Depot directory
smalldepotshare string The Small Depot share name
smtp_server string localhost The name of the SMTP server to use to send email
startatmft integer 0 9223372036854775807 0 The NTFS MFT entry number to begin the load. This is usually used to debug the loader
suspect string The name of the suspect in this investigation
syslog string The name or IP address of the syslog server to send lots and lots of detailed log messages to
syslogport integer 0 65536 514 The port number of the syslog server
tempdir string The name of the directory to write any temporary files
textindexerdir string C:\Truxton Data The path to override where the text indexer stores its binaries and content. *NOTE* In TruxtonService.xml the string $TextIndexerData$ will be replaced with this value.
timeout integer 0 9223372036854775807 120 The number of seconds the load process is allowed to collect data. Used in conjuction with the rapid option
tinydepotdir string The Tiny Depot directory
tinydepotshare string The Tiny Depot share name
triage boolean 0 1 0 Perform a quick load to get an idea of the value of the media being loaded. Most forensic processing is skipped for speed
tsk_verbose boolean 0 1 0 When using TSK to navigate media, set the verbose mode
updatemedianumberofchildren boolean 0 1 1 When the initial load completes, update the number of children in the database
updatepathid boolean 0 1 1 When the initial load completes, update the path of files in the database
verbose boolean 0 1 0 Controls how much information is logged during a load
wait string "Key" will wait for a keystroke from the user before exiting the program. "TerminateETL" will cause load to wait until all ETLs have finished processing then shut them down. "None" will disable waiting for anything."
xorcarve boolean 0 1 1 Not currently implemented. When carving for files, XOR the contents with 0xFF in addition to carving raw contents