Logpresso Forensic imports collected evidence and extracts Windows and Linux artifacts by intrusion stage. It tags suspicious artifacts by matching them against indicators of compromise, raises events from TTP detection rules, and builds the intrusion timeline.