Logpresso Forensic

Download 0
Last updated Oct 11, 2026

User Guide

Overview

Logpresso Forensic is where an incident responder uploads collected evidence and takes it apart. Give it an evidence archive and it works out what is inside — registry hives, the NTFS master file table and USN journal, Windows event logs, web and firewall logs, Linux artifacts — loads each into its own table, and extracts the artifacts an investigation actually asks about.

Those artifacts are grouped by the stage of an intrusion they belong to: initial access, execution, persistence. The point is that an investigator asking "what ran on this host" should not have to remember several hundred registry key names to find out.

When loading finishes, the TTP detection rules run by themselves and group whatever they match into events. You start from an event, dig into the artifacts behind it, and tag the records that look wrong with a note. Those tags become the timeline of the case.

Before you start

Three things must be in place. The Install Guide covers them in detail.

  • The File Store app — where evidence archives are kept
  • A cluster administrator account — loading and detection run as it
  • A license — without the forensic feature you get one project

How it flows

The basic flow is register evidence → load → detect → investigate → tag → timeline.

Evidence is registered per host under a case (a project). Keeping several hosts' evidence in one case is what lets the browsing screens search across them.

Menus

MenuWhat it isManual
ProjectsRegister evidence per case and start loadingGetting Started
EventsWhat the TTP detection rules found, and the records behind itEvents
ArtifactsInvestigate extracted artifacts by intrusion stageArtifacts
File SystemWalk the NTFS master file table as a folder treeEvidence Browsers
RegistryWalk registry hives as a key treeEvidence Browsers
LogsRead the raw logs — Windows events, web, firewallEvidence Browsers
AdministrationDetection rules, indicators, evidence types, extraction rulesAdministration

The filter bar

The five browsing screens — Events, Artifacts, File System, Registry, Logs — share one filter bar at the top. It survives navigation, so you can settle on a host and a time range once and then look at that same scope from several angles.

  • Time range — defaults to 1970 through the end of today. Forensic records routinely carry timestamps from years back, so the default is deliberately wide
  • Project/Host — which hosts to read. Nothing is returned until you pick at least one
  • Keyword — several words separated by spaces match records containing all of them

What is in this manual

PageContents
Getting StartedOne investigation, from creating a project to closing it
EventsReading a detection and checking what it was based on
ArtifactsThe tree, the timeline, filters and tags
Evidence BrowsersThe three screens for reading raw evidence
AdministrationDetection rules, indicators, evidence definitions
Query CommandsInvestigating by query, and leaving tags behind
Note
The browsing screens show whatever has landed so far, even while an import is still running. You
do not have to wait for it to finish before looking at the evidence that arrived first.

If this is your first time, start with Getting Started.