COMING SOON · LATE Q4 2026Join the launch list + 10% launch offerJoin the launch list + 10% launch offer ↗Planned offer. Terms to be confirmed.

THE ACORN / FORENSIC OPERATING SYSTEM

Thousands of forensic uses.
One portable OS.

The Acorn brings a forensic operating system, focused apps and a portable workstation together. Protect and copy evidence, recover files, follow activity and prepare reports. Take the same workspace from the laboratory to the office or field, with local analysis that does not depend on the cloud.

THE ACORN / YOUR WORKSPACE
The Acorn workstation, front view. Earlier hardware shown; final 2026/2027 components and ports will be confirmed.
The Acorn workstation, front view. Earlier hardware shown; final 2026/2027 components and ports will be confirmed.

Core forensic apps

Find the forensic app for your task.

These nine core apps cover device checks, imaging, recovery and review. Filter by task, open a card to see an example, or browse all 49 application guides.

9 core apps

Device ManagerCheck devices and source protection

Check that you have the right device before you act. Device Manager shows the reported device, partitions, how they are attached and their protection state.

Native device-state inspection

The selected USB is shown as read-only, with its kernel protection, partitions and mount information. View full screen
The selected USB is shown as read-only, with its kernel protection, partitions and mount information.
Explore Device Manager ↗
Forensic ImagerCreate and verify a forensic image

Choose the source, a separate place to save the copy and a plan to check it. The Imager screen shows these choices before capture. Decide how you will check the result.

Acquisition setup shown

Supplied screenshot of the Acorn Forensic Imager with its disk inventory populated. View full screen
Supplied screenshot of the Acorn Forensic Imager with its disk inventory populated.
Explore Forensic Imager ↗
Forensic WorkbenchReview files and artefacts in case context

Workbench keeps the file, its preview and the case context together. Open an item, check its contents and follow the source record before drawing a conclusion. This example shows a recovered photograph from a public training scenario.

Public training example · earlier interface

Inspect a recovered photograph alongside its file records in The Acorn Workbench. This public Narcos teaching scenario shows bagged crystalline material; the image alone cannot identify the substance. View full screen
Inspect a recovered photograph alongside its file records in The Acorn Workbench. This public Narcos teaching scenario shows bagged crystalline material; the image alone cannot identify the substance.
Explore Forensic Workbench ↗
File Recovery CarverRecover files without directory entries

Deleting a file or quick-formatting a disk can leave its content behind. This example finds PDF structures and checks where the recovered content ends.

Demonstrated on constructed training data

After an actual quick format of an owned FAT16 image copy, the native carver located four intact PDF structures in its free space. The selected invoice can be reviewed alongside the recovery audit fields. View full screen
After an actual quick format of an owned FAT16 image copy, the native carver located four intact PDF structures in its free space. The selected invoice can be reviewed alongside the recovery audit fields.
Explore File Recovery Carver ↗
Partition RecoveryFind lost partitions and inspect their contents

A disk section, called a partition, can lose its entry without losing all its files. This example finds a FAT16 partition and checks selected recovered files.

Demonstrated on constructed training data

The native scanner locates a FAT16 volume at byte offset 1048576 despite the missing partition table. This is a constructed image, not an actual client disk. View full screen
The native scanner locates a FAT16 volume at byte offset 1048576 despite the missing partition table. This is a constructed image, not an actual client disk.
Explore Partition Recovery ↗
Forensic NavigatorBrowse evidence and inspect individual files

Browse files and check where they came from. Not every document on screen is evidence from the source device. This example shows an examiner's report.

Demonstrated on public training data

The native Navigator renders the Case Notes PDF beside its source export and reference files. The selected report records a real filter operation on public event-log data. View full screen
The native Navigator renders the Case Notes PDF beside its source export and reference files. The selected report records a real filter operation on public event-log data.
Explore Forensic Navigator ↗
Browsing HistoryReview visits, searches and downloads

Review recorded page visits, searches and downloads in one view. Filter by a term or category, then check the page title, web address, time and source. The public Lone Wolf example shows this process with firearm-marketplace browsing records.

Demonstrated on public training data

A category filter shows 65 firearm-marketplace browsing records from 2,613 public Lone Wolf training records. Recorded times, page titles and source URLs stay together, with the selected entry expanded below. View full screen
A category filter shows 65 firearm-marketplace browsing records from 2,613 public Lone Wolf training records. Recorded times, page titles and source URLs stay together, with the selected entry expanded below.
Explore Browsing History ↗
Event Log ViewerInspect Windows events and rule matches

An event match is a place to start, not a conclusion. Event Log Viewer shows the source record and decoded command. Check what the record says. Keep it separate from a proposed action, a repeat rule match or an outcome you have inferred.

Demonstrated on public training data

Eighteen rule matches identify archive-decoding PowerShell command lines in public training logs. The selected record preserves the encoded command, source event and a decoded gzip script fragment. View full screen
Eighteen rule matches identify archive-decoding PowerShell command lines in public training logs. The selected record preserves the encoded command, source event and a decoded gzip script fragment.
Explore Event Log Viewer ↗
Timeline ViewerCompare events in date order

Review activity in date order and check why each event matters. With Timeline Viewer, keep track of what each time records, the time basis used and where the record came from. These details help you explain your findings.

Demonstrated on public training data

The native Timeline Viewer filters 226 public training timeline rows to two timestamp entries describing Windows Security Event 1102, an audit-log clearing event. The recorded account and SID remain visible in the event details. View full screen
The native Timeline Viewer filters 226 public training timeline rows to two timestamp entries describing Windows Security Event 1102, an audit-log clearing event. The recorded account and SID remain visible in the event details.
Explore Timeline Viewer ↗

Check each guide’s example and the technical support guide for the relevant build, inputs and limits.

Browse the Application Catalogue ↗

A forensic multi-tool

One kit. Many ways into the evidence.

For the lab, office, field and defence investigation. The Acorn brings digital forensics and incident response (DFIR) into one portable Linux operating system, with 49 focused application guides to explore.

Think of it as a forensic Swiss Army knife: disk imaging, recovery, memory analysis and artefact review in one working environment.

Take the same workspace from your desk to the evidence. The planned bundle brings the computer, portable screen, keyboard, mouse, storage adaptors and carry case together. Keep specialist tools where the case needs them.

  • More than an app: an evidence-focused OS, tools, case workspace and reports.
  • More than a computer: a prepared workflow, not a blank machine to configure on site.
  • Room to adapt: add Linux tools, your own scripts and organisation-approved workflows.
Explore the portable workstation

Why a forensic operating system

Advantages of a forensic operating system

An entire working environment, prepared for the evidence rather than assembled again for each task.

One connected environment

Keep source records, case review and focused tools together. Spend less time moving between unrelated utilities.

Protect the source

Inspect connected media and use integrated write-blocking controls within a planned acquisition workflow. External hardware blockers can be used where your policy requires them.

Take the workspace with you

Use a portable workstation at the bench or on site. Plan suitable power, storage and a safe place to handle the evidence.

Work offline

Review local evidence without relying on a live cloud service. Online lookups, updates and remote collection need a separate, authorised connection.

Examine in stages

Start with the case question. Collect what is needed, review the relevant records and widen the work when the evidence calls for it.

Keep costs in view

Reuse one portable system for several tasks. Reduce duplicated hardware and configuration work, while keeping specialist software where it earns its place.

See current capabilities and limits ↗
Recovery, from a missing file to difficult media

Choose standard imaging, resumable copying or a focused recovery route. Bad-sector mapping and tools such as OpenSuperClone can support a failing-disk workflow. Partition recovery and fragmented-file carving address different problems, so start with the condition of the source.

Shared intelligence, not separate lists for every task

Reuse keywords, file hashes, pattern rules and review leads across the investigation. Focused viewers help you work through large tables, event logs and timelines without losing the source behind an entry.

A route into specialist work

Guided workflows bring memory review, Windows file records, event logs and timeline processing closer to both new and experienced examiners. Graphical tools and the terminal let students learn the underlying method, not just follow an output.

Your scripts, formats and future workflows

Add open-source utilities or write a parser for an unusual case. An organisation-approved AI assistant can help develop a script, but test the result and keep case data within your approved environment. Standard outputs help you retain your work without depending on one vendor.

Regular updates are planned for fixes, tools, detection content and workflow improvements. The release schedule will be confirmed with the product.

Evidence-aware workflows
Focused examination tools
Practical learning & review

SQFR · The Acorn · Workbench

An operating system built around the examination.

The Acorn grew from frustration with finding a different tool for each task. Hashes, keywords and intelligence were held in separate places. What began as scripts and a personal incident-response toolkit developed into a connected forensic operating environment.

The Acorn: the environment

Access tools to collect and examine evidence in one place. Check the source and choose how to work with it before you start.

Workbench: the case

Organise evidence, search records and tag useful items. Keep the source close while you decide what a result means.

Explore Workbench ↗

Focused apps: the detail

Choose a tool to suit the question: an event log, a deleted file or an account check. Look at what goes in, what comes out and the limits of the tool.

Browse by task ↗

One environment. A deliberate workflow.

Acquire the source. Parse the artefacts. Explain the content.

Begin with a protected source and a clear question. Use the right tool to read its artefacts, the files and records left by activity. Check what they mean, keep their source references and explain the limits of the result.

01 / PRESERVE

Know what is connected.

Check the device, its state and what you have permission to examine. Then check how it is protected and choose a suitable way to collect the evidence.

Device and imaging tools ↗
02 / EXAMINE

Ask a smaller question.

Move from the case view to a file, event, browser record or account action. Check where it came from as you test what it could mean.

Inside the Workbench ↗
03 / EXPLAIN

Make the work reviewable.

Use the logs, tables and reports supported for your task. A finished process may not have covered everything. Explain any gaps when you hand over the work.

See a real report example ↗

Inside the examination

Start with a question. Follow the records.

The Acorn brings the tools together. You link the findings to the case, check the context and decide what needs a closer look.

  1. 01

    Define the question

    What can the files and records tell you? Set the source, date range and limits of your permission before choosing a tool.

  2. 02

    Locate the record

    Follow the path, file or event. Keep its source reference and recorded time beside the item you review.

  3. 03

    Examine the context

    Open the item, compare related records and test other explanations. A picture, page visit or search hit is a lead, not the whole answer.

  4. 04

    Explain the finding

    Record what you checked, what it shows and what is still unclear. Keep enough detail for another examiner to review your work.

Put the picture beside the record.

The Acorn Workbench: a recovered photograph and its file records from the public Narcos teaching scenario. The pictured crystalline material cannot be identified from the image alone. View full screen
The Acorn Workbench: a recovered photograph and its file records from the public Narcos teaching scenario. The pictured crystalline material cannot be identified from the image alone.

From image to record

The public Narcos capture shows Recycle Bin entries beside the selected photograph. Open the full-size image to inspect the names and recorded times.

Which time answers the question?

A file’s modification time is not its deletion time. Read the matching Recycle Bin record and compare the activity around it.

Earlier supplied Workbench interface, using the public Narcos teaching scenario. Select the screen, then choose “View actual size” to inspect the records.

Where would I find the deletion time?

Illustrative training record, separate from the Narcos capture

Recycle Bin record$I metadata + $R content
Original file
Training-photo.jpg
Moved to Recycle Bin
Record source
Companion $I record
Content to examine
Matching $R file

Read the deletion time from the matching Recycle Bin metadata. File created, modified and accessed times answer different questions. Record the time zone and compare related activity.

A workspace beyond the office

From the bench to the field.

Where will you work, and what will you need there? The proposed portable kit brings the workstation, screen, keyboard and mouse together.

Illustrative The Acorn workstation concept: at a client’s premises. View full screen
Illustrative The Acorn workstation concept: at a client’s premises.

At a client’s premises

Plan a temporary workspace around your permitted tasks, the power supply and the systems you need to examine.

Illustrative The Acorn workstation concept: in a sheltered field workspace. View full screen
Illustrative The Acorn workstation concept: in a sheltered field workspace.

In a sheltered field workspace

You still need suitable power, shelter from the weather and a safe place to handle the source.

Generated illustrations of the proposed hardware and working settings, not photographs of deployments. Connections, source adapters, power and environmental suitability must be checked for the actual task.

Explore the workstation and portable kit ↗

Right click. Follow the evidence.

From an artefact to a useful report.

Right-click a file or folder to open its relevant actions. Artefact Lens helps identify the item; the reporting route turns supported records into something you can read and follow.

Native folder actions: open Artefact Lens, run triage or choose a report. View full screen
Native folder actions: open Artefact Lens, run triage or choose a report.

Artefact Lens recognises the selected item and helps route it to the right workflow. Report actions sit alongside it in the context menu.

INTERACTIVE EXPLANATION

Try the right-click workflow

Right-click the example record or use the Actions button. This browser illustration does not run The Acorn.

Training evidence folderConstructed collection · example only

Choose an action to see how the source, finding and report relate.

Illustrative interaction. No file is uploaded, analysed or downloaded.

Follow the right-click reporting route

Training screenshot: folder right-click actions with reporting choices.
1. Select the training folder and open its right-click actions.

A guided sequence of genuine training screenshots, not a continuous recording or a processing-time benchmark. The report keeps the source close to the finding.

Download the animated walkthrough (GIF)

From a result to a finding

Triage reports you can pivot from.

An IP address, keyword, file hash or rule match can turn a long list of records into a focused line of enquiry. Follow the hit back to its source, then decide what to examine next.

Use YARA pattern rules, shared keywords and other checks to surface useful leads. A heuristic is a clue based on a pattern, not a final verdict. The point is to narrow the next question, not to replace the examiner.

Show the source

Keep input records and outputs together.

Explain the limits

Separate observations from conclusions.

STATIC DOCUMENT REVIEWIllustrative report

A payment request with a different destination.

Payment-advice.pdf

Phishing indicators flagged for review
Visible message
“Review your payment advice”
Link destination
accounts-check.example
Review leads
Sign-in request, off-domain link, urgency wording
Next checks
Compare the sender, actual URL, email headers and account logs
Extract URLsCompare keywordsReview source
Phishing-PDF report mock-up using an inert example domain. It illustrates the review, not a live malware detection or a completed The Acorn test.

The planned 2026/2027 bundle

Take the workspace with you.

The proposed portable bundle pairs The Acorn with a workstation, USB-C-powered screen, mini keyboard, mouse and carry bag.

Working specification: 24 GB RAM, AMD Ryzen 9 or Intel Core i9, and a 1 TB PCIe SSD. Final components and compatibility are still being selected.

Explore the planned bundle ↗

COMING SOON · Q4 2026

Launch specification to be confirmed

Final components, pricing, VAT, delivery and licence terms will be confirmed before orders open.

Notify me + 10% launch offer ↗

No deposit or pre-order is taken here.

Zoom in, then scroll to inspect the detail.

Open full-resolution image ↗

A useful first conversation

Let’s look at your workflow.

Tell us what you examine, where you work and what you need to deliver.

Use the enquiry form to outline your role, intended use and potential order quantity. Do not send case material through a general enquiry.

Your enquiry goes to the SQFR team. Please do not include passwords or case evidence.