COMING SOON · Q1 2027 Planned releaseGet notified + 10% launch offer ↗

THE ACORN / FORENSIC OPERATING SYSTEM

Digital forensics.
One portable OS.

Acorn is the forensic operating system. Workbench is where you organise and review the case. Acquisition, examination and reporting tools share one Linux workspace.

Explore the workflow

Targeting Q1 2027 · Explore the tools and read about the planned launch offer.

ACORN / YOUR WORKSPACE
Acorn Home: a task-based starting point for the forensic workflow.
Acorn Home: a task-based starting point for the forensic workflow.
The branded Acorn portable workstationTHE ACORN WORKSTATION
Evidence-aware workflows
Focused examination tools
Practical learning & review

SQFR · Acorn · Workbench

An operating system built around the examination.

SQFR is the company behind Acorn. Acorn is the Linux forensic operating system. Workbench is its case workspace, supported by focused applications for particular evidence and tasks.

Acorn: the environment

A dedicated place for acquisition, evidence access and examination tools. Check the source state and choose the workflow before processing.

Workbench: the case

Organise evidence, review records, search and tag relevant items. Keep the original source in reach while deciding what a result means.

Explore Workbench ↗

Focused apps: the detail

Use the tool suited to the question, from an event log or deleted file to an account audit. Inspect its input, output and limits before relying on it.

Browse by task ↗

One environment. A deliberate workflow.

Keep the source. Follow the evidence.

The useful result is not simply that a tool ran. It is knowing what was examined, what was found and what still needs checking.

01 / PRESERVE

Know what is connected.

Start with the device, its state and the authorised scope. Inspect protection settings and choose a suitable acquisition route before working on the evidence.

Device and imaging tools ↗
02 / EXAMINE

Ask a smaller question.

Move from a case view into the relevant record: a file, event, browser entry or account action. Keep the source context close as you test an explanation.

Inside the Workbench ↗
03 / EXPLAIN

Make the work reviewable.

Use the supported logs, tables and reports for the task. Distinguish a completed process from complete coverage, and carry the gaps into the handover.

See a real report example ↗

Inside the examination

Start with a question. Follow the records.

Acorn brings tools into one workspace. The examiner connects the findings to the question, checks the context and decides what needs a closer look.

  1. 01

    Define the question

    What can the available files and activity records establish? Set the source, date range and permitted scope before choosing a tool.

  2. 02

    Locate the record

    Follow the relevant path, file or event. Keep its source reference and recorded time alongside the item you are reviewing.

  3. 03

    Examine the context

    Open the content, compare related records and test other explanations. A picture, page visit or search hit is a lead, not the whole answer.

  4. 04

    Explain the finding

    Record what you checked, what it shows and what remains unresolved. Keep enough context for another examiner to review the work.

Look at the photograph and its file record together.

Acorn Workbench: a recovered photograph and its file records from the public Narcos teaching scenario. The pictured crystalline material cannot be identified from the image alone. View full screen
Acorn Workbench: a recovered photograph and its file records from the public Narcos teaching scenario. The pictured crystalline material cannot be identified from the image alone.

What is visible

The case tree, Recycle Bin file entries and the selected picture appear together. You can inspect the content without losing the record being examined.

What needs further work

The picture does not establish the substance, its ownership or the circumstances in which it was taken. Those questions require other evidence.

Earlier supplied Workbench interface, using the public Narcos teaching scenario. Select the screen, then choose “View actual size” to inspect the records.

Core forensic apps

Find the tool for the question.

Nine core apps cover source handling, imaging, case review, recovery and focused investigation. Open a card for an example, or follow its guide for the detail.

9 core apps

Device ManagerCheck devices and source protection

Identify the evidence device before choosing an examination action. Device Manager makes the reported device, partition, mount and protection state available for inspection. That gives the examiner useful context, while the chosen protection method still needs its own validation.

Native device-state inspection

The selected USB is shown as read-only, with its kernel protection, partitions and mount information. This capture is a state inspection, not a write-block validation test. View full screen
The selected USB is shown as read-only, with its kernel protection, partitions and mount information. This capture is a state inspection, not a write-block validation test.
Explore Device Manager ↗
Forensic ImagerCreate and verify a forensic image

A forensic disk imaging job needs a clear source, a separate destination and a verification plan. The populated Imager interface brings those choices together before capture. Agree what will be checked afterwards, rather than treating a completed progress indicator as sufficient evidence of success.

Acquisition setup shown

Supplied screenshot of the Acorn Forensic Imager with its disk inventory populated. No acquisition outcome is inferred from this setup screen. View full screen
Supplied screenshot of the Acorn Forensic Imager with its disk inventory populated. No acquisition outcome is inferred from this setup screen.
Explore Forensic Imager ↗
Forensic WorkbenchReview files and artefacts in case context

Workbench keeps the file, its preview and the case context together. Open a relevant item, inspect its contents and follow the source record before deciding what it tells you. The example below shows a recovered photograph from a public training scenario.

Public training example · earlier interface

Inspect a recovered photograph alongside its file records in Acorn Workbench. This public Narcos teaching scenario shows bagged crystalline material; the image alone cannot identify the substance. View full screen
Inspect a recovered photograph alongside its file records in Acorn Workbench. This public Narcos teaching scenario shows bagged crystalline material; the image alone cannot identify the substance.
Explore Forensic Workbench ↗
File Recovery CarverRecover files without directory entries

Deletion or quick formatting can leave file content behind. The demonstrated carver finds PDF structures, with explicit checks of where the recovered content ends.

Demonstrated on constructed training data

After an actual quick format of an owned FAT16 image copy, the native carver located four intact PDF structures in its free space. The selected invoice can be reviewed alongside the recovery audit fields. View full screen
After an actual quick format of an owned FAT16 image copy, the native carver located four intact PDF structures in its free space. The selected invoice can be reviewed alongside the recovery audit fields.
Explore File Recovery Carver ↗
Partition RecoveryFind lost partitions and inspect their contents

A missing partition entry does not necessarily mean all of its contents have gone. The demonstrated workflow locates a FAT16 partition and checks selected recovered files.

Demonstrated on constructed training data

The native scanner locates a FAT16 volume at byte offset 1048576 despite the missing partition table. This is a constructed image, not an actual client disk. View full screen
The native scanner locates a FAT16 volume at byte offset 1048576 despite the missing partition table. This is a constructed image, not an actual client disk.
Explore Partition Recovery ↗
Forensic NavigatorBrowse evidence and inspect individual files

Move between files and their context without treating every visible document as original endpoint evidence. The supplied example previews an examiner's report.

Demonstrated on public training data

The native Navigator renders the Case Notes PDF beside its source export and reference files. The selected report records a real filter operation on public event-log data. View full screen
The native Navigator renders the Case Notes PDF beside its source export and reference files. The selected report records a real filter operation on public event-log data.
Explore Forensic Navigator ↗
Browsing HistoryReview visits, searches and downloads

Browsing History brings recorded visits, searches and downloads into a reviewable view. Narrow the records by a relevant term or category, then inspect the page title, URL, time and source. The public Lone Wolf example makes that process visible with firearm-marketplace browsing records.

Demonstrated on public training data

A category filter shows 65 firearm-marketplace browsing records from 2,613 public Lone Wolf training records. Recorded times, page titles and source URLs stay together, with the selected entry expanded below. View full screen
A category filter shows 65 firearm-marketplace browsing records from 2,613 public Lone Wolf training records. Recorded times, page titles and source URLs stay together, with the selected entry expanded below.
Explore Browsing History ↗
Event Log ViewerInspect Windows events and rule matches

An event match is a place to start reading. Event Log Viewer keeps the underlying record and decoded command context close to the review, so an examiner can separate what was recorded from a proposed action, duplicated rule match or inferred outcome.

Demonstrated on public training data

Eighteen rule matches identify archive-decoding PowerShell command lines in public training logs. The selected record preserves the encoded command, source event and a decoded gzip script fragment. View full screen
Eighteen rule matches identify archive-decoding PowerShell command lines in public training logs. The selected record preserves the encoded command, source event and a decoded gzip script fragment.
Explore Event Log Viewer ↗
Timeline ViewerCompare events in date order

A chronology is useful when it explains why each row belongs in the account. Timeline Viewer supports focused review of recorded activity, while the examiner keeps timestamp kind, time basis and source context separate from the final interpretation.

Demonstrated on public training data

The native Timeline Viewer filters 226 public training timeline rows to two timestamp entries describing Windows Security Event 1102, an audit-log clearing event. The recorded account and SID remain visible in the event details. View full screen
The native Timeline Viewer filters 226 public training timeline rows to two timestamp entries describing Windows Security Event 1102, an audit-log clearing event. The recorded account and SID remain visible in the event details.
Explore Timeline Viewer ↗

Check each guide’s example and the technical support guide for the relevant build, inputs and limits.

A workspace beyond the office

From the bench to the field.

Think about where the examination will happen, not just what is installed. The proposed portable kit brings the workstation, screen and input devices together.

Illustrative Acorn workstation concept: at a client’s premises. View full screen
Illustrative Acorn workstation concept: at a client’s premises.

At a client’s premises

Set up a temporary examination space around the authorised scope, available power and the systems you need to work with.

Illustrative Acorn workstation concept: in a sheltered field workspace. View full screen
Illustrative Acorn workstation concept: in a sheltered field workspace.

In a sheltered field workspace

A portable setup still needs suitable power, protection from the elements and a safe place to handle the source.

Generated illustrations of the proposed hardware and working settings, not photographs of deployments. Connections, source adapters, power and environmental suitability must be checked for the actual task.

Explore the workstation and portable kit ↗

Right click. Follow the evidence.

From an artefact to a useful report.

Keep the action beside the item you are examining. Acorn’s context menus offer actions matched to the file or source; the available details and report options depend on the selected item and build.

Native folder actions: open Artefact Lens, run triage or choose a report. This menu capture does not demonstrate every action completing. View full screen
Native folder actions: open Artefact Lens, run triage or choose a report. This menu capture does not demonstrate every action completing.

Artefact Lens recognises the selected item and helps route it to the right workflow. Report actions sit alongside it in the context menu. A view-only Lens is not the same as a completed analysis or report.

INTERACTIVE EXPLANATION

Try the right-click workflow

Right-click the example record or use the Actions button. This browser illustration does not run Acorn.

Training evidence folderConstructed collection · example only

Choose an action to see how the source, finding and report relate.

Illustrative interaction. No file is uploaded, analysed or downloaded.

Fit it into your examination process

Keep the specialist tools you rely on.

You do not need to replace an established method to evaluate Acorn. Start with one useful task: a second look at an artefact, a source-protection workflow or a focused examination of an available image.

Then test the handover. Which exact file or table leaves one tool, what reads it next, and which source references remain available?

This is an approach to evaluation, not a claim of native AXIOM, FTK or X-Ways project import, a vendor partnership, or that Windows applications run on Acorn.

Check the route, not just the extension.

  • Confirm the container variant, encryption and expected records.
  • Inspect the fields, time zones and warnings in any export.
  • Compare a known result with an independent method where appropriate.
  • Confirm that the receiving tool can read the actual output.
Use the evaluation checklist ↗

Look beyond the feature list

Three useful checks before you decide.

Check the support boundary

Separate a tested input from a documented route, a setup view or a feature still in development.

Open the technical guide ↗

Your environment. Your requirements.

Where will you use Acorn?

A police examination, incident review and university practical ask different things of the same platform. Start with the workflow that looks like yours.

Sector illustrations describe intended use cases, not endorsements or claims of current deployment.

From a result to a finding

Outputs you can question.

An alert is a starting point. A useful handover also shows the input, the observation and the limits of the interpretation.

This native Malware Triage PDF comes from an inert constructed training example. It illustrates the reporting interface; a rule match is not, by itself, proof that a system was compromised.

Show the source

Keep input records and outputs together.

Explain the limits

Separate observations from conclusions.

Native Acorn Malware Triage report page from an inert constructed training example. View full screen
Native Acorn Malware Triage report page from an inert constructed training example.

The planned 2027 bundle

Take the workspace with you.

The proposed portable bundle pairs Acorn with a workstation, USB-C-powered screen, mini keyboard, mouse and carry bag.

Working specification: 24 GB RAM, AMD Ryzen 9 or Intel Core i9, and a 1 TB PCIe SSD. Final components and compatibility are still being selected.

Explore the planned bundle ↗

COMING SOON · Q1 2027

Target RRP under £3,000 GBP

Provisional specification and price target. Final VAT treatment, delivery, licence terms and availability will be confirmed before orders open.

Notify me + 10% launch offer ↗

No deposit or pre-order is taken here.

Before you decide

A few practical questions.

A demonstration should answer these against your actual work, not a generic feature checklist.

Read all questions and answers ↗
Is Acorn the operating system or the hardware?

The Acorn name is used for the forensic software environment and the portable workstation offering. Confirm the edition, supplied hardware and included capabilities in the quotation and workstation specification.

Can it replace every tool in my laboratory?

That is not the proposition. Assess the relevant workflow and supported evidence against your existing tools. Keep your validation, specialist capabilities and independent checks where the work requires them.

Are these screenshots from real investigations?

The selected screens use documented public teaching material, constructed training records or native setup views. Captions identify the example. They are not presented as private client cases.

Can I order the planned workstation?

Not yet. The planned Q1 2027 bundle is not available to purchase. Contact and launch-update forms send your request to SQFR for review. They do not take payment or automatically enrol you in a mailing list.

Start with your requirements

See how it fits your evidence.

Bring a task, an input format and the output you need. That makes for a better demonstration than a tour of every button.

Planned for Q1 2027

Be first to hear. Save 10% at launch.

Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.

Notify me at launch ↗

Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.

About the screenshots and illustrations

Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.

Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.

Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.

Zoom in, then scroll to inspect the detail.

Open full-resolution image ↗

A useful first conversation

Let’s look at your workflow.

Tell us what you examine, where you work and what you need to deliver.

Use the enquiry form to outline your role, intended use and potential order quantity. Do not send case material through a general enquiry.

Your enquiry goes to the SQFR team. Please do not include passwords or case evidence.