Logpresso Forensic

Download 0
Last updated Oct 11, 2026

Evidence Browsers

Reading the raw evidence

If artifacts are facts that have been extracted, these three screens are the evidence as it was collected. Use them when you need something the extraction rules did not pull out, or when you need the context around something an artifact showed you.

All three share the filter bar at the top, so once you have settled on a host and a time range you can move between them within that scope.

File System

Walks the NTFS master file table ($MFT) as a folder tree. You are not looking at the disk — you are reading the file metadata as it stood when the evidence was collected.

The tree on the left expands project → host → partition → folder; clicking a folder lists its files in the grid. Each level is fetched when you open it, so a large disk does not have to be loaded up front.

Created, modified and accessed times are there alongside size and path, which makes this the place to ask what was written at a given moment. Traces of deleted files show up too, as long as $MFT still holds their records.

Registry

Walks registry hives as a key tree.

The tree expands project → host → hive → key. The number beside a key is how many values sit beneath it. Click a key and its values appear in the grid.

Where the Artifacts screen hands you a tidied result — "the autorun entries" — this is where you can see which key that result came from. It is also where you go for keys no extraction rule covers.

Search scope in the filter bar decides whether the keyword is matched against key names, value names or value contents.

Logs

Reads the raw logs that were loaded. The tree on the left is the log type.

TypeWhat it is
Text logsLogs in various text formats
NTFS eventsUSN journal ($J) records
Windows eventsThe Windows event log, with per-channel entries beneath it
Web logsIIS, Apache, Nginx and other web server logs
Firewall · Detection logsSecurity appliance logs
PCAPPacket captures

The entries under Windows events are not separate tables — they are channel conditions: System, Application, Security, PowerShell, Windows Defender, Remote Desktop (connection manager and session manager), and Task Scheduler. Select the parent to see all of them.

The registry and the MFT have screens of their own, so they do not appear in this tree.

What they share

All three are investigated the same way the Artifacts screen is.

  • Right-click a cell to filter on its value. Text columns also offer the indicator matches
  • Chip bar — the conditions you have applied, written as the query they stand for. Ctrl+Q clears them
  • Star — tag a record and leave a note
  • Detail panel — click a row for every field, and the tags on it
  • Sorting — click a column header
Note
If a search comes back empty, check the **time range** in the filter bar first. Forensic records
routinely carry timestamps from years back, and a narrow range can exclude all of them.

Next: detection rules and evidence definitions, in Administration.