Logpresso Graph

Download 110
Last updated Sep 29, 2026

Attack Graph

Attack Graph

An analysis screen that unfolds detection events into a relationship graph between IPs to trace attack flows. The layout splits into the IP list on the left, the graph with a timeline below in the center, and the filter/event panel on the right. The right edge and the timeline edge are resizable by dragging.

Query Flow

  1. Set the period at the top left. The default is today; presets (today / 7 / 30 / 60 / 90 days) and hour/minute/second selection are available.
  2. Click Search to list IPs that had detection events in the period. A progress bar with a running count appears and the query can be cancelled.
  3. Use the IP filter box above the list for partial matching on IP or hostname.
  4. Each item shows priority badges (H: red, M: orange, L: blue), the hostname, and technique/tactic/event counts.
  5. Checking an item draws that IP on the graph, adds a row to the bottom timeline, and opens the filter panel on the right.

Reading the Graph

  • Round nodes = IPs, shown on two lines when the hostname is known. Node color encodes the relative accumulated threat score — green → yellow → orange → red.
  • Blue square nodes = domains, connected to their IP with a blue dashed edge.
  • Edges (arrows) bundle detection events from source to destination. The label is the MITRE technique ID (such as T1595), or the rule name when no technique is known. Hover for the rule name, TTPs, tactics, and event count.

Working with the Graph

  • Single-click a node to open its menu:
    • Expand events: widen the graph from that IP.
    • Event list: open that IP's event panel on the right.
    • Analyze in new tab: open a new workspace tab dedicated to that IP.
  • Double-click a node to expand from it (existing nodes stay and accumulate).
  • Expand all — expand every not-yet-expanded IP node at once.
  • Cluster / Uncluster — group private IPs by /24 subnet and public IPs by ASN. Cluster nodes show the group name and member count; double-click one to open it.
  • Reset — clear all nodes and edges.

Filter Panel (Right)

Rule and ASN statistics for the selected IPs and period, as checkbox lists.

  • Each list has a search box; the All/None links apply only to the visible (filtered) items.
  • Changing any checkbox immediately requeries the graph and the timeline with that filter.
  • All items checked means "no filter".

Bottom Timeline

One row per selected IP, with stacked bars in three priority colors (HIGH red / MEDIUM orange / LOW yellow). The bucket interval adjusts to the period automatically.

  • Drag the orange handles at either end to narrow the range; on release, the whole graph requeries for that range (filters preserved). The Reset button in the header restores the full period.

Event Panel

Opened from a node's "Event list" menu. Rows show time, priority, rule, and source → destination. Click a row to unfold every field of the raw event — field labels are replaced with display names from the log schema, and IP fields show a country flag with the ASN.

Note
When analyzing several IPs and you want separate contexts, use "Analyze in new tab" from
the node menu. Each workspace tab at the top keeps its own graph, filters, and timeline.