Skip to main content

Artifact

Struct Artifact 

Source
pub struct Artifact { /* private fields */ }
Expand description

Recovered non-script artifact view.

Implementations§

Source§

impl Artifact

Source

pub const fn record_index(&self) -> usize

Returns the source record index.

§Returns

The index of the Record this artifact was recovered from.

Examples found in repository?
examples/dump.rs (line 270)
265fn print_artifacts(artifacts: &[Artifact]) {
266    section(&format!("artifacts ({})", artifacts.len()));
267    for artifact in artifacts {
268        println!(
269            "  record #{} {}",
270            artifact.record_index(),
271            escape_inline(artifact.name())
272        );
273        subfield("subtype", escape_inline(artifact.subtype()));
274        subfield("bytes", artifact.bytes().len().to_string());
275        subfield(
276            "timestamps",
277            format!(
278                "created={} last_write={}",
279                artifact.creation_time(),
280                artifact.last_write_time()
281            ),
282        );
283        subfield("checksum valid", artifact.checksum_valid().to_string());
284        subfield(
285            "decompression",
286            format!("{:?}", artifact.decompression_status()),
287        );
288    }
289}
Source

pub fn subtype(&self) -> &str

Returns the record subtype.

§Returns

The decoded subtype string of the source record.

Examples found in repository?
examples/dump.rs (line 273)
265fn print_artifacts(artifacts: &[Artifact]) {
266    section(&format!("artifacts ({})", artifacts.len()));
267    for artifact in artifacts {
268        println!(
269            "  record #{} {}",
270            artifact.record_index(),
271            escape_inline(artifact.name())
272        );
273        subfield("subtype", escape_inline(artifact.subtype()));
274        subfield("bytes", artifact.bytes().len().to_string());
275        subfield(
276            "timestamps",
277            format!(
278                "created={} last_write={}",
279                artifact.creation_time(),
280                artifact.last_write_time()
281            ),
282        );
283        subfield("checksum valid", artifact.checksum_valid().to_string());
284        subfield(
285            "decompression",
286            format!("{:?}", artifact.decompression_status()),
287        );
288    }
289}
Source

pub fn name(&self) -> &str

Returns the stored record name/path.

§Returns

The decoded name/path string of the source record.

Examples found in repository?
examples/dump.rs (line 271)
265fn print_artifacts(artifacts: &[Artifact]) {
266    section(&format!("artifacts ({})", artifacts.len()));
267    for artifact in artifacts {
268        println!(
269            "  record #{} {}",
270            artifact.record_index(),
271            escape_inline(artifact.name())
272        );
273        subfield("subtype", escape_inline(artifact.subtype()));
274        subfield("bytes", artifact.bytes().len().to_string());
275        subfield(
276            "timestamps",
277            format!(
278                "created={} last_write={}",
279                artifact.creation_time(),
280                artifact.last_write_time()
281            ),
282        );
283        subfield("checksum valid", artifact.checksum_valid().to_string());
284        subfield(
285            "decompression",
286            format!("{:?}", artifact.decompression_status()),
287        );
288    }
289}
Source

pub fn bytes(&self) -> &[u8]

Returns recovered artifact bytes.

§Returns

The best available payload bytes for the source record.

Examples found in repository?
examples/dump.rs (line 274)
265fn print_artifacts(artifacts: &[Artifact]) {
266    section(&format!("artifacts ({})", artifacts.len()));
267    for artifact in artifacts {
268        println!(
269            "  record #{} {}",
270            artifact.record_index(),
271            escape_inline(artifact.name())
272        );
273        subfield("subtype", escape_inline(artifact.subtype()));
274        subfield("bytes", artifact.bytes().len().to_string());
275        subfield(
276            "timestamps",
277            format!(
278                "created={} last_write={}",
279                artifact.creation_time(),
280                artifact.last_write_time()
281            ),
282        );
283        subfield("checksum valid", artifact.checksum_valid().to_string());
284        subfield(
285            "decompression",
286            format!("{:?}", artifact.decompression_status()),
287        );
288    }
289}
Source

pub const fn creation_time(&self) -> u64

Returns creation timestamp as raw Windows FILETIME.

§Returns

The raw 64-bit Windows FILETIME creation timestamp from the source record.

Examples found in repository?
examples/dump.rs (line 279)
265fn print_artifacts(artifacts: &[Artifact]) {
266    section(&format!("artifacts ({})", artifacts.len()));
267    for artifact in artifacts {
268        println!(
269            "  record #{} {}",
270            artifact.record_index(),
271            escape_inline(artifact.name())
272        );
273        subfield("subtype", escape_inline(artifact.subtype()));
274        subfield("bytes", artifact.bytes().len().to_string());
275        subfield(
276            "timestamps",
277            format!(
278                "created={} last_write={}",
279                artifact.creation_time(),
280                artifact.last_write_time()
281            ),
282        );
283        subfield("checksum valid", artifact.checksum_valid().to_string());
284        subfield(
285            "decompression",
286            format!("{:?}", artifact.decompression_status()),
287        );
288    }
289}
Source

pub const fn last_write_time(&self) -> u64

Returns last-write timestamp as raw Windows FILETIME.

§Returns

The raw 64-bit Windows FILETIME last-write timestamp from the source record.

Examples found in repository?
examples/dump.rs (line 280)
265fn print_artifacts(artifacts: &[Artifact]) {
266    section(&format!("artifacts ({})", artifacts.len()));
267    for artifact in artifacts {
268        println!(
269            "  record #{} {}",
270            artifact.record_index(),
271            escape_inline(artifact.name())
272        );
273        subfield("subtype", escape_inline(artifact.subtype()));
274        subfield("bytes", artifact.bytes().len().to_string());
275        subfield(
276            "timestamps",
277            format!(
278                "created={} last_write={}",
279                artifact.creation_time(),
280                artifact.last_write_time()
281            ),
282        );
283        subfield("checksum valid", artifact.checksum_valid().to_string());
284        subfield(
285            "decompression",
286            format!("{:?}", artifact.decompression_status()),
287        );
288    }
289}
Source

pub const fn checksum_valid(&self) -> bool

Returns checksum validation status from the source record.

§Returns

true if the source record’s stored checksum validated, false otherwise.

Examples found in repository?
examples/dump.rs (line 283)
265fn print_artifacts(artifacts: &[Artifact]) {
266    section(&format!("artifacts ({})", artifacts.len()));
267    for artifact in artifacts {
268        println!(
269            "  record #{} {}",
270            artifact.record_index(),
271            escape_inline(artifact.name())
272        );
273        subfield("subtype", escape_inline(artifact.subtype()));
274        subfield("bytes", artifact.bytes().len().to_string());
275        subfield(
276            "timestamps",
277            format!(
278                "created={} last_write={}",
279                artifact.creation_time(),
280                artifact.last_write_time()
281            ),
282        );
283        subfield("checksum valid", artifact.checksum_valid().to_string());
284        subfield(
285            "decompression",
286            format!("{:?}", artifact.decompression_status()),
287        );
288    }
289}
Source

pub const fn decompression_status(&self) -> DecompressionStatus

Returns decompression status from the source record.

§Returns

The DecompressionStatus recorded for the source record.

Examples found in repository?
examples/dump.rs (line 286)
265fn print_artifacts(artifacts: &[Artifact]) {
266    section(&format!("artifacts ({})", artifacts.len()));
267    for artifact in artifacts {
268        println!(
269            "  record #{} {}",
270            artifact.record_index(),
271            escape_inline(artifact.name())
272        );
273        subfield("subtype", escape_inline(artifact.subtype()));
274        subfield("bytes", artifact.bytes().len().to_string());
275        subfield(
276            "timestamps",
277            format!(
278                "created={} last_write={}",
279                artifact.creation_time(),
280                artifact.last_write_time()
281            ),
282        );
283        subfield("checksum valid", artifact.checksum_valid().to_string());
284        subfield(
285            "decompression",
286            format!("{:?}", artifact.decompression_status()),
287        );
288    }
289}

Trait Implementations§

Source§

impl Clone for Artifact

Source§

fn clone(&self) -> Artifact

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Artifact

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for Artifact

Source§

impl PartialEq for Artifact

Source§

fn eq(&self, other: &Artifact) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for Artifact

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.