Logpresso Forensic

Download 0
Last updated Oct 11, 2026

Artifacts

Artifacts

An artifact is something pulled out of the evidence that an investigation can use directly. Instead of reading a registry hive, you read "the programs that ran on this host".

The screen is, from left to right: type tree, timeline, grid, detail panel.

The type tree

Extracted artifacts, grouped by the stage of an intrusion they belong to. The number in parentheses is how many match the current search.

CategoryWhat is in it
Basic informationOS install details, time zone, user accounts — the plain facts about the host
Initial accessBrowser history, USB device connections, and other ways something got in
ExecutionTraces of programs having run
PersistenceAutoruns, scheduled tasks — whatever survives a reboot
IndicatorsIPs, MD5s, SHA1s, domains and URLs harvested from every piece of evidence while loading
LinuxArtifacts collected from Linux hosts

Types with a count of zero are not shown. The tree is meant to say what is actually in this evidence.

Note
The **Indicators** category is different in kind from the others. It collects values that were
found inside the evidence, so being there does not make a value malicious. To compare against
known-bad indicators, register them under
[Administration](/en/apps/forensic/user-guide/admin) and use the `match_forensic_*` functions or
the right-click menu.

The timeline

A bar chart of how many artifacts fall in each slice of the search range, colored by type.

Drag across the chart to keep only that span. It is the fastest way to ask what was happening around a particular moment. The bucket size adjusts itself to the range.

The grid

The matching artifacts, a page at a time.

  • The star in the first column is the tag. Click it to add or edit one
  • The Details column writes out the fields specific to that artifact type as field=value. Types carry different fields, so they cannot have columns of their own — this cell is the only place those values appear
  • Click a row and the detail panel opens on the right

The detail panel

Every field of the selected record, in two tabs.

  • Details — the schema's fields in order, then whatever else the record carries. Below them is where this record came from: project, host, evidence file
  • Tags — the tags on this record with their notes, and who left them when

Condition filters

Right-click a cell to filter on its value. Conditions stack as chips above the grid, and each chip reads as the query it stands for.

Field kindOperators offered
Textequals, not equals, contains, does not contain
Number, timeequals, not equals, ≥, ≤, >, <
Artifact typeequals, not equals

Text columns also offer matches an indicator — MD5, SHA1, domain and IP. These do not use the value in the cell you clicked: they test the whole column against your registered indicators.

Remove a chip with its ✕, or drop them all with Ctrl+Q.

Tags

When a record looks wrong, click the star to mark it. The colors are red (blacklist), yellow (warning) and green (bookmark), and you can attach a note.

A record can carry several colors at once; the star in the list shows the most serious of them. Filter by Tag in the bar at the top to see only what you marked.

Note
Write the note. The star tells you *that* you flagged something; only the note tells you **why**.
Once an investigation runs past a day or two, that difference matters.

Tagging from a query, and collecting what you tagged into a timeline, is covered in Query Commands.

Download

Search results can be downloaded as CSV, JSON and other formats — for a report, or to hand to another tool.

Next: reading the raw evidence, in Evidence Browsers.