Administration
Administration
Where the detection rules, the indicators, and the definitions that decide how evidence is read all live. Four screens sit under Administration.
TTP detection rules
The rules that find signs of intrusion in loaded evidence. Installing the app seeds a set of them per company; here you edit those or add your own.
The list shows whether each is enabled, its priority, name, description and when it last changed. Click a row and the edit panel opens on the right.
| Field | What it is |
|---|---|
| Enabled | Turn it off and scans skip it |
| Name | Appears in the Rule column of the event list |
| Priority | High, medium or low — the bars in the event list |
| Message template | The event message, and what the grouping is keyed on. See below |
| MITRE ATT&CK techniques | Technique ids such as T1562.001, comma separated |
| Query | The body of the rule |
The message template is the grouping key
The field names you write into the template are where events are cut. A scan sorts the rule's result by those fields and starts a new event wherever the combination changes.
$field— an ASCII field name$field$— a name that is not ASCII, such as Korean, is wrapped in$at both ends
Write Defender real-time protection disabled: $computer and you get one event per computer,
with every record from that computer inside it as evidence. A template with no fields at all
collapses everything the rule matched into a single event.
The query
Written in Logpresso query language. Table names are not spelled out — they are referenced as constants, which the scan replaces with that image's actual tables.
| Constant | What it points at |
|---|---|
$("artifact") | The extracted artifacts |
$("winevent") | Windows event logs |
$("reg") | The registry |
$("mft") | The NTFS master file table |
$("web") | Web logs |
A rule that finds Windows Defender real-time protection being switched off reads like this:
table $("winevent")
| fields time, computer, channel, provider, event_id, level, msg
| search provider == "Microsoft-Windows-Windows Defender" and event_id == 5001
The query is parsed when you save, and a rule that does not parse is refused. That keeps a broken query out of the table, where it would only fail once a scan reached it.
Running a scan
Detection runs by itself once loading finishes, but after editing a rule you run it by hand.
Check the rules to run and click Scan. With nothing checked, every enabled rule runs. Choose a project and an image in the dialog, and progress is shown as it goes.
it, keep in mind that the earlier results are still there.
Indicators
Where you register hashes, addresses and domains already known to be malicious. The
match_forensic_* query functions and the grids' right-click menu compare against what is here.
**Indicators** category in Artifacts, and being found there says nothing about whether a value is
malicious. What you register here is what is already known to be bad.
Click Add and give a type (IP, MD5, SHA1, DOMAIN, URL), the values, and a description. Values go in one per line, as many at a time as you like — paste the list straight out of a report or a threat intelligence feed.
A value already registered for that type is skipped, and you are told how many were added and how many were already there. Pasting an updated list over the top is therefore safe.
Once registered, the value cannot be changed — only the description. The value is the identity of the indicator.
Evidence types
The definitions that decide what a file inside an archive is taken to be. The app ships a full set, so there is usually nothing to do here; you add to it when a collection tool produces a format that needs reading.
| Field | What it is |
|---|---|
| File name pattern | Entries matching this regular expression are taken as this type |
| File signature | Hex bytes in the file header, so a renamed file is still recognized |
| Unzip | Turn on when the load query needs a real file path |
| Load query | The query that reads this evidence into a table |
| Log schema | The field definitions of the loaded records |
Editing a built-in definition marks that row as custom, and restarting the app will not overwrite it afterwards.
Artifact extraction rules
The rules that pull investigation-ready artifacts out of loaded evidence.
| Field | What it is |
|---|---|
| Category | Which intrusion stage it appears under in the artifact tree |
| Evidence type | Which evidence it reads |
| Log schema | The field definitions of the extracted artifacts |
| Query | The extraction query |
Changing the evidence type changes which evidence the rule is attached to. Loading runs the extraction rules attached to an evidence type when that type is recognized, so getting the link wrong means the rule never runs at all.
Next: investigating by query, in Query Commands.