Logpresso Forensic

Download 0
Last updated Oct 11, 2026

File System

Walks the NTFS master file table ($MFT) as a folder tree. You are not looking at the disk - you are reading the file metadata as it stood when the evidence was collected.

If artifacts are facts that have been extracted, this is the evidence as it was collected. Use it when you need something the extraction rules did not pull out, or when you need the context around something an artifact showed you.

Walking the tree

The tree on the left expands project → host → partition → folder; clicking a folder lists its files in the grid. Each level is fetched when you open it, so a large disk does not have to be loaded up front.

Created, modified and accessed times are there alongside size and path, which makes this the place to ask what was written at a given moment. Traces of deleted files show up too, as long as $MFT still holds their records.

Where a file came from

The Zone.Identifier stream NTFS keeps in an alternate data stream (ADS) is read as well. Windows attaches it to anything downloaded from the internet to record where it came from, so these columns tell you how a file arrived:

ColumnWhat it is
Download URLThe address the file was fetched from
Referrer URLThe page that led to that address
Security zoneInternet, local intranet and the rest of Windows' own classification

This is how you trace the way a malicious file got in. To see only the files that carry a URL, the Artifacts screen's Initial access → Internet-downloaded files gets you there faster.

Note
Zone.Identifier is written by browsers and mail clients, so a file extracted from an archive or
carried in on a USB stick will not have one. Its absence does not mean the file did not come from
the internet.

How you investigate here

Results are handled the same way the Artifacts screen handles them. Right-click a cell to filter on its value, watch the conditions stack up in the chip bar as the query they stand for (Ctrl+Q clears them), star a record to tag it and leave a note, and click a row for the detail panel with every field and tag on it. There is more in Artifacts.

The filter bar is shared with the other browsing screens, so settling on a host and a time range once lets you carry that scope from screen to screen.

Note
If a search comes back empty, check the time range in the filter bar first. Forensic records
routinely carry timestamps from years back, and a narrow range can exclude all of them.

Next: Registry.