Command Line Interface¶
usage: mrdpf_cli [-h] (-d DIR | -f FILE) -o OUT [--no-recurse] [--clear]
Named Arguments¶
- -d, --dir
Directory to search for compatible files
- -f, --file
File to parse
- -o, --out
Folder to write results to
- --no-recurse
Do not recurse. If input option is not –dir this option is ignored.
Default: False
- --clear
Clear output directory before writing results (will delete all files below out directory)
Default: False
Command Line Interface - Documentation¶
Classes:
|
|
|
An enumeration. |
Functions:
|
Colorize text. |
|
Print colorize text. |
|
Create directory at path. |
|
Create file with name and extension at given base path. |
Create argument parser |
|
|
Write a list of dataclasses to a CSV file at given path with name and extension. |
|
Write a list of dataclasses to a CSV file at path |
|
Write a pandas dataframe to a CSV file at path with name and extension. |
-
mrdpf_cli.create_dir(path)[source]¶ Create directory at path. Returns path to created directory.
If a directory already exists at the provided path, a number will be appended until the directory does not exist.
-
mrdpf_cli.create_file(path, name, extension)[source]¶ Create file with name and extension at given base path.
If a file with the given name and extension already exists, a number will be appended until a file does not exist.
- Returns
Path to created file
-
mrdpf_cli.write_data(path, name, extension, data)[source]¶ Write a list of dataclasses to a CSV file at given path with name and extension.
- Returns
Path to created file or None if data is empty
Parsers¶
Classes:
|
Parses the com.microsoft.rdc.application-data.sqlite database |
|
Models rows in the ZBOOKMARKENTITY table of the com.microsoft.rdc.application-data.sqlite SQLite database |
|
Models rows in the ZBOOKMARKORDERENTITY table of the com.microsoft.rdc.application-data.sqlite SQLite database |
|
Models ClientFolderRedirectionEntity PLIST class |
|
Generic enumeration. |
|
Models rows in the Z_METADATA table of the com.microsoft.rdc.application-data.sqlite SQLite database |
|
Parses the offlinestorageHigh.dat file |
An enumeration. |
|
|
Models the com.microsoft.rdc.macos.plist binary plist file |
|
Parses the com.microsoft.rdc.macos.plist file |
|
Models UserIdHistory PLIST class |
|
The year, month and day arguments are required. |
Functions:
|
Decode the Base64 encoded bytes-like object or ASCII string s. |
|
Encode the bytes-like object s using Base64 and return a bytes object. |
|
Returns the same class as was passed in, with dunder methods added based on the fields defined in the class. |
|
Based on the code in the dataclasses module to handle optional-parens decorators. |
|
Decode byte string into dictionary using provided format. |
|
Read binary plist from file at path. |
|
Decode binary string encoded using NSKeyedArchiver. |
-
class
mrdpf.parsers.AppSupportDbParser(path)[source]¶ Bases:
mrdpf.parsers.BaseParserParses the com.microsoft.rdc.application-data.sqlite database
Methods:
parse()Parse data from file
-
class
mrdpf.parsers.Bookmark(pk: str, ent: str, opt: str, friendly_name: str, hostname: str, zid: str, rdp_string: str, folder_redirection_config: mrdpf.io.plist.ClientFolderRedirectionEntity, last_connected: datetime.datetime, redirect_camera: bool, redirect_folders: bool, redirect_clipboard: bool, redirect_printers: bool, redirect_smartcard: bool, bookmark_folder: int, fok_bookmark_folder: int, credential: int, gateway: int, creation_source: str, authoring_tool: str, admin_mode: bool, audio_capture_enabled: bool, audio_playback: str, auto_reconnect_enabled: bool, color_depth: int, dynamic_resolution_enabled: bool, retina_enabled: bool, input_mode: str, use_all_monitors: bool, screen_type: str, screen_type_height: int, screen_type_width: int, screen_type_resolution: int, screen_type_scale: bool, swap_mouse_button: bool)[source]¶ Bases:
objectModels rows in the ZBOOKMARKENTITY table of the com.microsoft.rdc.application-data.sqlite SQLite database
-
class
mrdpf.parsers.BookmarkOrder(pk: int, ent: int, opt: int, root: str)[source]¶ Bases:
objectModels rows in the ZBOOKMARKORDERENTITY table of the com.microsoft.rdc.application-data.sqlite SQLite database
-
class
mrdpf.parsers.Metadata(version: int, uuid: str, data: str)[source]¶ Bases:
objectModels rows in the Z_METADATA table of the com.microsoft.rdc.application-data.sqlite SQLite database
-
class
mrdpf.parsers.OfflineStorageHighParser(path)[source]¶ Bases:
mrdpf.parsers.BaseParserParses the offlinestorageHigh.dat file
Methods:
parse()Parse data from file
-
class
mrdpf.parsers.Preferences(telemetry_previous_send_diagnostics: bool, nswindow_frame_mainwindow: str, kms_analytics_is_enabled: bool, removed_home_folder_redirection: bool, telemetry_previous_daily_events_time: datetime.datetime, user_id_history: {}, past_devices_key: {}, first_run_experience_launched_version: str, telemetry_device_id: str, ms_install_id: str, telemetry_previous_app_launch_version: str, session_id_history: {})[source]¶ Bases:
objectModels the com.microsoft.rdc.macos.plist binary plist file
Core¶
Classes:
|
Parses the com.microsoft.rdc.application-data.sqlite database |
|
Parses the offlinestorageHigh.dat file |
|
|
|
An enumeration. |
|
Parses the com.microsoft.rdc.macos.plist file |
Functions:
|
Returns the same class as was passed in, with dunder methods added based on the fields defined in the class. |
Parser Definitions¶
Data:
Defines parameters extracted from offlinestorageHigh.dat by OfflineStorageHighParser |
-
mrdpf.parser_definitions.OFFLINE_STORAGE_PARAMETERS= [b'AppInfo.Id', b'AppInfo.Language', b'AppInfo.Version', b'DeviceInfo.Id', b'DeviceInfo.Make', b'DeviceInfo.Model', b'DeviceInfo.NetworkType', b'DeviceInfo.OsBuild', b'DeviceInfo.OsName', b'DeviceInfo.OsVersion', b'DeviceInfo.SDKUid', b'EventInfo.InitId', b'EventInfo.Name', b'EventInfo.SdkVersion', b'EventInfo.Sequence', b'EventInfo.Source', b'EventInfo.Time', b'S_e', b'S_j', b'S_k', b'S_p', b'S_t', b'S_v', b'TenantId', b'UserInfo.Id', b'UserInfo.Language', b'UserInfo.TimeZone', b'eventpriority', b'records_received_count', b'high_priority_records_sent_count', b'high_priority_records_tried_to_send_count', b'n_r_count', b'n_r_inv', b'normal_priority_records_received_count', b'r_count', b'r_inv', b'high_priority_records_received_count', b'records_sent_count', b'records_tried_to_send_count', b'AppLifeCycle.State', b'Session.Duration', b'Session.DurationBucket', b'Session.FirstLaunchTime', b'Session.Id', b'Session.State', b'h_inol', b'inol', b'h_inq']¶ Defines parameters extracted from offlinestorageHigh.dat by OfflineStorageHighParser
Helpers¶
Classes:
|
-
class
mrdpf.helpers.DataclassJSONEncoder(*, skipkeys=False, ensure_ascii=True, check_circular=True, allow_nan=True, sort_keys=False, indent=None, separators=None, default=None)[source]¶ Methods:
default(obj)Implement this method in a subclass such that it returns a serializable object for
o, or calls the base implementation (to raise aTypeError).-
default(obj)[source]¶ Implement this method in a subclass such that it returns a serializable object for
o, or calls the base implementation (to raise aTypeError).For example, to support arbitrary iterators, you could implement default like this:
def default(self, o): try: iterable = iter(o) except TypeError: pass else: return list(iterable) # Let the base class default method raise the TypeError return JSONEncoder.default(self, o)
-
I/O - PLIST¶
Classes:
|
Models BookmarkOrderItemEntity PLIST class |
|
Models ClientFolderRedirectionEntity PLIST class |
|
Helper to easily map python dataclasses (PEP557) to archived objects. |
|
Models Device PLIST class |
|
Models DeviceHistoryInfo PLIST class |
|
Models SessionHistoryInfo PLIST class |
|
Models UserIdHistory PLIST class |
|
The year, month and day arguments are required. |
Functions:
|
Based on the code in the dataclasses module to handle optional-parens decorators. |
|
Decode byte string into dictionary using provided format. |
|
Read binary plist from file at path. |
|
Decode binary string encoded using NSKeyedArchiver. |
|
Read plaintext XML plist from file at path. |
-
class
mrdpf.io.plist.BookmarkOrderItemEntity(id: str, children: list)[source]¶ Models BookmarkOrderItemEntity PLIST class
-
class
mrdpf.io.plist.ClientFolderRedirectionEntity(readOnly: bool, path: str, name: str, id: str)[source]¶ Models ClientFolderRedirectionEntity PLIST class
-
class
mrdpf.io.plist.Device(model: str, sdkVersion: str, osBuild: str, appVersion: str, timeZoneOffset: str, osVersion: str, locale: str, liveUpdatePackageHash: str, liveUpdateReleaseLabel: str, liveUpdateDeploymentKey: str, osApiLevel: str, wrapperRuntimeVersion: str, wrapperSdkVersion: str, carrierCountry: str, appNamespace: str, sdkName: str, appBuild: str, wrapperSdkName: str, screenSize: str, osName: str, carrierName: str, oemName: str)[source]¶ Models Device PLIST class
-
class
mrdpf.io.plist.DeviceHistoryInfo(deviceKey: str, timestampKey: str)[source]¶ Models DeviceHistoryInfo PLIST class
-
class
mrdpf.io.plist.SessionHistoryInfo(sessionIdKey: str, timestampKey: str)[source]¶ Models SessionHistoryInfo PLIST class
-
class
mrdpf.io.plist.UserIdHistoryInfo(userIdKey: str, timestampKey: str)[source]¶ Models UserIdHistory PLIST class
-
mrdpf.io.plist.decode_plist(data: bytes, format: plistlib.PlistFormat = <PlistFormat.FMT_BINARY: 2>) → dict[source]¶ Decode byte string into dictionary using provided format.
- Returns
Parsed PLIST
- Rtye
dict
-
mrdpf.io.plist.read_bplist(path: str) → dict[source]¶ Read binary plist from file at path.
- Returns
Parsed PLIST
- Rtye
dict