User Guide
Overview
Logpresso Forensic is where an incident responder uploads collected evidence and takes it apart. Give it an evidence archive and it works out what is inside — registry hives, the NTFS master file table and USN journal, Windows event logs, web and firewall logs, Linux artifacts — loads each into its own table, and extracts the artifacts an investigation actually asks about.
Those artifacts are grouped by the stage of an intrusion they belong to: initial access, execution, persistence. The point is that an investigator asking "what ran on this host" should not have to remember several hundred registry key names to find out.
When loading finishes, the TTP detection rules run by themselves and group whatever they match into events. You start from an event, dig into the artifacts behind it, and tag the records that look wrong with a note. Those tags become the timeline of the case.
Before you start
Three things must be in place. The Install Guide covers them in detail.
- The File Store app — where evidence archives are kept
- A cluster administrator account — loading and detection run as it
- A license — without the
forensicfeature you get one project
How it flows
The basic flow is register evidence → load → detect → investigate → tag → timeline.
Evidence is registered per host under a case (a project). Keeping several hosts' evidence in one case is what lets the browsing screens search across them.
Menus
| Menu | What it is | Manual |
|---|---|---|
| Projects | Register evidence per case and start loading | Getting Started |
| Events | What the TTP detection rules found, and the records behind it | Events |
| Artifacts | Investigate extracted artifacts by intrusion stage | Artifacts |
| File System | Walk the NTFS master file table as a folder tree | Evidence Browsers |
| Registry | Walk registry hives as a key tree | Evidence Browsers |
| Logs | Read the raw logs — Windows events, web, firewall | Evidence Browsers |
| Administration | Detection rules, indicators, evidence types, extraction rules | Administration |
The filter bar
The five browsing screens — Events, Artifacts, File System, Registry, Logs — share one filter bar at the top. It survives navigation, so you can settle on a host and a time range once and then look at that same scope from several angles.
- Time range — defaults to 1970 through the end of today. Forensic records routinely carry timestamps from years back, so the default is deliberately wide
- Project/Host — which hosts to read. Nothing is returned until you pick at least one
- Keyword — several words separated by spaces match records containing all of them
What is in this manual
| Page | Contents |
|---|---|
| Getting Started | One investigation, from creating a project to closing it |
| Events | Reading a detection and checking what it was based on |
| Artifacts | The tree, the timeline, filters and tags |
| Evidence Browsers | The three screens for reading raw evidence |
| Administration | Detection rules, indicators, evidence definitions |
| Query Commands | Investigating by query, and leaving tags behind |
do not have to wait for it to finish before looking at the evidence that arrived first.
If this is your first time, start with Getting Started.