Logpresso Forensic

Download 0
Last updated Oct 11, 2026

Administration

Administration

Where the detection rules, the indicators, and the definitions that decide how evidence is read all live. Four screens sit under Administration.

TTP detection rules

The rules that find signs of intrusion in loaded evidence. Installing the app seeds a set of them per company; here you edit those or add your own.

The list shows whether each is enabled, its priority, name, description and when it last changed. Click a row and the edit panel opens on the right.

FieldWhat it is
EnabledTurn it off and scans skip it
NameAppears in the Rule column of the event list
PriorityHigh, medium or low — the bars in the event list
Message templateThe event message, and what the grouping is keyed on. See below
MITRE ATT&CK techniquesTechnique ids such as T1562.001, comma separated
QueryThe body of the rule

The message template is the grouping key

The field names you write into the template are where events are cut. A scan sorts the rule's result by those fields and starts a new event wherever the combination changes.

  • $field — an ASCII field name
  • $field$ — a name that is not ASCII, such as Korean, is wrapped in $ at both ends

Write Defender real-time protection disabled: $computer and you get one event per computer, with every record from that computer inside it as evidence. A template with no fields at all collapses everything the rule matched into a single event.

The query

Written in Logpresso query language. Table names are not spelled out — they are referenced as constants, which the scan replaces with that image's actual tables.

ConstantWhat it points at
$("artifact")The extracted artifacts
$("winevent")Windows event logs
$("reg")The registry
$("mft")The NTFS master file table
$("web")Web logs

A rule that finds Windows Defender real-time protection being switched off reads like this:

table $("winevent")
| fields time, computer, channel, provider, event_id, level, msg
| search provider == "Microsoft-Windows-Windows Defender" and event_id == 5001

The query is parsed when you save, and a rule that does not parse is refused. That keeps a broken query out of the table, where it would only fail once a scan reached it.

Running a scan

Detection runs by itself once loading finishes, but after editing a rule you run it by hand.

Check the rules to run and click Scan. With nothing checked, every enabled rule runs. Choose a project and an image in the dialog, and progress is shown as it goes.

Note
Scanning the same image again **accumulates**. If you have been iterating on a rule and rerunning
it, keep in mind that the earlier results are still there.

Indicators

Where you register hashes, addresses and domains already known to be malicious. The match_forensic_* query functions and the grids' right-click menu compare against what is here.

Note
This is not the same as what is **found** in evidence while loading. Those collect under the
**Indicators** category in Artifacts, and being found there says nothing about whether a value is
malicious. What you register here is what is already known to be bad.

Click Add and give a type (IP, MD5, SHA1, DOMAIN, URL), the values, and a description. Values go in one per line, as many at a time as you like — paste the list straight out of a report or a threat intelligence feed.

A value already registered for that type is skipped, and you are told how many were added and how many were already there. Pasting an updated list over the top is therefore safe.

Once registered, the value cannot be changed — only the description. The value is the identity of the indicator.

Evidence types

The definitions that decide what a file inside an archive is taken to be. The app ships a full set, so there is usually nothing to do here; you add to it when a collection tool produces a format that needs reading.

FieldWhat it is
File name patternEntries matching this regular expression are taken as this type
File signatureHex bytes in the file header, so a renamed file is still recognized
UnzipTurn on when the load query needs a real file path
Load queryThe query that reads this evidence into a table
Log schemaThe field definitions of the loaded records

Editing a built-in definition marks that row as custom, and restarting the app will not overwrite it afterwards.

Artifact extraction rules

The rules that pull investigation-ready artifacts out of loaded evidence.

FieldWhat it is
CategoryWhich intrusion stage it appears under in the artifact tree
Evidence typeWhich evidence it reads
Log schemaThe field definitions of the extracted artifacts
QueryThe extraction query

Changing the evidence type changes which evidence the rule is attached to. Loading runs the extraction rules attached to an evidence type when that type is recognized, so getting the link wrong means the rule never runs at all.

Next: investigating by query, in Query Commands.