Logpresso Forensic

Download 0
Last updated Oct 11, 2026

Getting Started

One investigation, end to end

This page follows a single investigation from collecting the evidence to closing the case. Each screen is covered in detail in its own page.

1. Obtain the collection tool

Gathering evidence from the machine under investigation needs a collection tool. The Korea Internet & Security Agency (KISA) provides one free of charge to businesses — the Hacking Detection Tool — and you request it through 보호나라, KISA's security portal.

  1. Go to 정보보호 서비스 (Security Services) → 서비스 신청하기 (Apply for a Service)
  2. Pick 해킹진단도구 (Hacking Detection Tool) from the list and click 신청하기 (Apply)
  3. Accept the privacy and terms-of-service agreements and continue
  4. Look up your company by business registration number; the company details fill themselves in. Give a contact, choose the operating systems you want (Windows, Linux), and attach the business registration certificate
  5. Submit. After review, the tool arrives by email
Note
This is a service for registered businesses, so a business registration number and certificate
are required. Windows and Linux can be requested together.

2. Collect the evidence

Run the tool on the machine under investigation.

  1. Pick the executable matching the target's architecture — HackingDiagnosisKit_x64.exe for 64-bit Windows, _x86.exe for 32-bit. The wrong one refuses to start
  2. CollectSetting.ini must sit next to the executable. If it is missing, one with default values is written on startup
  3. Choose 증거데이터 수집 (Collect Evidence Data) on the home screen
  4. Set a password for the result file: at least ten characters mixing digits, letters and symbols
  5. Adjust what to gather under the collection target settings if you need to. The defaults already cover system information, filesystem metadata ($MFT, $LogFile, $J), registry hives, Windows event logs and web logs — everything this app reads
  6. Start it; a result file is produced when collection finishes
Note
Check the **free disk space on the target** before collecting. Running short of it can disrupt a
system that is still in service.

3. Repackage without a password

The tool's result file is password protected. This app can only open a plain ZIP, so one step stands between collection and upload.

  1. Extract the result file with the password you set during collection
  2. Repackage the contents as a ZIP with no password

Leave the directory layout alone. Evidence types are recognized by file name and by the signature in the file header, so whatever the collection tool produced can be zipped as is.

4. Create a project

Click Projects → Add, give it a name, and save.

A project holds one case. It starts in the Waiting state; move it to In Progress when you begin and Done when you are finished.

5. Register the evidence

Click the project name to open it, then Register Evidence File and supply:

  • Host name — the Windows computer name or Linux hostname. This is what you narrow by when browsing
  • Evidence file — the ZIP you repackaged in step 3

You can register evidence from several hosts in one project, and you should when a case spans more than one machine: the browsing screens search across hosts.

6. Load it

Check the evidence row and start Import.

Loading runs in two stages, with progress shown for each:

  1. The archive is fetched from the file store into a work directory
  2. Every file inside it is matched against the evidence types; the recognized ones are loaded into tables, and the artifact extraction rules attached to them run

You can open Artifacts while this is still running and see what has landed. Large images take a while, so looking at the evidence that arrived first is usually quicker than waiting.

7. Detection runs by itself

When loading finishes, the TTP detection rules run automatically. There is no button to press.

Each rule queries the loaded evidence for records matching its condition and groups consecutive records about the same subject into a single event. The results collect in Events.

If you have added a rule since, or want to rerun only some of them, you can start a scan by hand from Administration → TTP Detection Rules → Scan.

8. Start from the events

Open Events, pick the project and host in the filter bar, and search.

The list shows what was detected and when, with a priority indicator. Click a row and the Evidence panel opens below it — the records the event was cut from, exactly as they were loaded.

A detection is a starting point, not a conclusion. Read the evidence, decide whether it is real, then move to Artifacts and look at what was happening around it.

9. Investigate the artifacts

In Artifacts, narrow by intrusion stage in the tree on the left, narrow by time on the timeline, and read individual records in the grid.

Sooner or later you will ask what else happened around a given moment. Right-click a cell to add a condition filter, or drag across the timeline to keep only that span.

10. Tag what you find

When a record looks wrong, click the star on the left and tag it.

ColorWhat it means
RedCompromise confirmed, or as good as
YellowSuspicious, needs another look
GreenChecked and benign, or worth revisiting later

Write a note with it. Without one, you will not remember why you flagged it either. A record can carry several colors at once, and the star in the list shows the most serious of them.

You can then filter by Tag in the bar at the top. In a long investigation, re-reading only what you marked is something you end up doing often.

11. Register the indicators

Malicious hashes, addresses and domains you confirmed belong in Administration → Indicators.

Once registered, the match_forensic_md5 family of query functions — and the right-click menu in the grids — will tell you whether the same indicator appears in other evidence. That is how you find out whether the same attacker also touched another host.

You can paste many at once, one per line, straight from a report or a feed.

12. Close the case

Set the project state to Done in the project editor and save.

The tags and notes stay with the project, so reopening the case later shows you exactly what you marked and why.

Next: how to read a detection, in Events.