Artifacts
Artifacts
An artifact is something pulled out of the evidence that an investigation can use directly. Instead of reading a registry hive, you read "the programs that ran on this host".
The screen is, from left to right: type tree, timeline, grid, detail panel.
The type tree
Extracted artifacts, grouped by the stage of an intrusion they belong to. The number in parentheses is how many match the current search.
| Category | What is in it |
|---|---|
| Basic information | OS install details, time zone, user accounts — the plain facts about the host |
| Initial access | Browser history, USB device connections, and other ways something got in |
| Execution | Traces of programs having run |
| Persistence | Autoruns, scheduled tasks — whatever survives a reboot |
| Indicators | IPs, MD5s, SHA1s, domains and URLs harvested from every piece of evidence while loading |
| Linux | Artifacts collected from Linux hosts |
Types with a count of zero are not shown. The tree is meant to say what is actually in this evidence.
found inside the evidence, so being there does not make a value malicious. To compare against
known-bad indicators, register them under
[Administration](/en/apps/forensic/user-guide/admin) and use the `match_forensic_*` functions or
the right-click menu.
The timeline
A bar chart of how many artifacts fall in each slice of the search range, colored by type.
Drag across the chart to keep only that span. It is the fastest way to ask what was happening around a particular moment. The bucket size adjusts itself to the range.
The grid
The matching artifacts, a page at a time.
- The star in the first column is the tag. Click it to add or edit one
- The Details column writes out the fields specific to that artifact type as
field=value. Types carry different fields, so they cannot have columns of their own — this cell is the only place those values appear - Click a row and the detail panel opens on the right
The detail panel
Every field of the selected record, in two tabs.
- Details — the schema's fields in order, then whatever else the record carries. Below them is where this record came from: project, host, evidence file
- Tags — the tags on this record with their notes, and who left them when
Condition filters
Right-click a cell to filter on its value. Conditions stack as chips above the grid, and each chip reads as the query it stands for.
| Field kind | Operators offered |
|---|---|
| Text | equals, not equals, contains, does not contain |
| Number, time | equals, not equals, ≥, ≤, >, < |
| Artifact type | equals, not equals |
Text columns also offer matches an indicator — MD5, SHA1, domain and IP. These do not use the value in the cell you clicked: they test the whole column against your registered indicators.
Remove a chip with its ✕, or drop them all with Ctrl+Q.
Tags
When a record looks wrong, click the star to mark it. The colors are red (blacklist), yellow (warning) and green (bookmark), and you can attach a note.
A record can carry several colors at once; the star in the list shows the most serious of them. Filter by Tag in the bar at the top to see only what you marked.
Once an investigation runs past a day or two, that difference matters.
Tagging from a query, and collecting what you tagged into a timeline, is covered in Query Commands.
Download
Search results can be downloaded as CSV, JSON and other formats — for a report, or to hand to another tool.
Next: reading the raw evidence, in Evidence Browsers.