Acorn: the environment
A dedicated place for acquisition, evidence access and examination tools. Check the source state and choose the workflow before processing.
SQUIRRELFORENSICSDesigned in the UKTHE ACORN / FORENSIC OPERATING SYSTEM
Acorn is the forensic operating system. Workbench is where you organise and review the case. Acquisition, examination and reporting tools share one Linux workspace.
Targeting Q1 2027 · Explore the tools and read about the planned launch offer.
SQFR · Acorn · Workbench
SQFR is the company behind Acorn. Acorn is the Linux forensic operating system. Workbench is its case workspace, supported by focused applications for particular evidence and tasks.
A dedicated place for acquisition, evidence access and examination tools. Check the source state and choose the workflow before processing.
Organise evidence, review records, search and tag relevant items. Keep the original source in reach while deciding what a result means.
Explore Workbench ↗Use the tool suited to the question, from an event log or deleted file to an account audit. Inspect its input, output and limits before relying on it.
Browse by task ↗One environment. A deliberate workflow.
The useful result is not simply that a tool ran. It is knowing what was examined, what was found and what still needs checking.
Start with the device, its state and the authorised scope. Inspect protection settings and choose a suitable acquisition route before working on the evidence.
Device and imaging tools ↗Move from a case view into the relevant record: a file, event, browser entry or account action. Keep the source context close as you test an explanation.
Inside the Workbench ↗Use the supported logs, tables and reports for the task. Distinguish a completed process from complete coverage, and carry the gaps into the handover.
See a real report example ↗Inside the examination
Acorn brings tools into one workspace. The examiner connects the findings to the question, checks the context and decides what needs a closer look.
What can the available files and activity records establish? Set the source, date range and permitted scope before choosing a tool.
Follow the relevant path, file or event. Keep its source reference and recorded time alongside the item you are reviewing.
Open the content, compare related records and test other explanations. A picture, page visit or search hit is a lead, not the whole answer.
Record what you checked, what it shows and what remains unresolved. Keep enough context for another examiner to review the work.
View full screenThe case tree, Recycle Bin file entries and the selected picture appear together. You can inspect the content without losing the record being examined.
The picture does not establish the substance, its ownership or the circumstances in which it was taken. Those questions require other evidence.
Earlier supplied Workbench interface, using the public Narcos teaching scenario. Select the screen, then choose “View actual size” to inspect the records.
Core forensic apps
Nine core apps cover source handling, imaging, case review, recovery and focused investigation. Open a card for an example, or follow its guide for the detail.
9 core apps
Identify the evidence device before choosing an examination action. Device Manager makes the reported device, partition, mount and protection state available for inspection. That gives the examiner useful context, while the chosen protection method still needs its own validation.
Native device-state inspection
View full screenA forensic disk imaging job needs a clear source, a separate destination and a verification plan. The populated Imager interface brings those choices together before capture. Agree what will be checked afterwards, rather than treating a completed progress indicator as sufficient evidence of success.
Acquisition setup shown
View full screenWorkbench keeps the file, its preview and the case context together. Open a relevant item, inspect its contents and follow the source record before deciding what it tells you. The example below shows a recovered photograph from a public training scenario.
Public training example · earlier interface
View full screenDeletion or quick formatting can leave file content behind. The demonstrated carver finds PDF structures, with explicit checks of where the recovered content ends.
Demonstrated on constructed training data
View full screenA missing partition entry does not necessarily mean all of its contents have gone. The demonstrated workflow locates a FAT16 partition and checks selected recovered files.
Demonstrated on constructed training data
View full screenBrowsing History brings recorded visits, searches and downloads into a reviewable view. Narrow the records by a relevant term or category, then inspect the page title, URL, time and source. The public Lone Wolf example makes that process visible with firearm-marketplace browsing records.
Demonstrated on public training data
View full screenAn event match is a place to start reading. Event Log Viewer keeps the underlying record and decoded command context close to the review, so an examiner can separate what was recorded from a proposed action, duplicated rule match or inferred outcome.
Demonstrated on public training data
View full screenA chronology is useful when it explains why each row belongs in the account. Timeline Viewer supports focused review of recorded activity, while the examiner keeps timestamp kind, time basis and source context separate from the final interpretation.
Demonstrated on public training data
View full screenCheck each guide’s example and the technical support guide for the relevant build, inputs and limits.
A workspace beyond the office
Think about where the examination will happen, not just what is installed. The proposed portable kit brings the workstation, screen and input devices together.
View full screenSet up a temporary examination space around the authorised scope, available power and the systems you need to work with.
View full screenA portable setup still needs suitable power, protection from the elements and a safe place to handle the source.
Generated illustrations of the proposed hardware and working settings, not photographs of deployments. Connections, source adapters, power and environmental suitability must be checked for the actual task.
Explore the workstation and portable kit ↗Right click. Follow the evidence.
Keep the action beside the item you are examining. Acorn’s context menus offer actions matched to the file or source; the available details and report options depend on the selected item and build.
View full screenArtefact Lens recognises the selected item and helps route it to the right workflow. Report actions sit alongside it in the context menu. A view-only Lens is not the same as a completed analysis or report.
INTERACTIVE EXPLANATION
Right-click the example record or use the Actions button. This browser illustration does not run Acorn.
Choose an action to see how the source, finding and report relate.
Illustrative interaction. No file is uploaded, analysed or downloaded.
Fit it into your examination process
You do not need to replace an established method to evaluate Acorn. Start with one useful task: a second look at an artefact, a source-protection workflow or a focused examination of an available image.
Then test the handover. Which exact file or table leaves one tool, what reads it next, and which source references remain available?
This is an approach to evaluation, not a claim of native AXIOM, FTK or X-Ways project import, a vendor partnership, or that Windows applications run on Acorn.
Look beyond the feature list
Inspect a native report example and ask which records, settings and limits accompany it.
View the example report ↗Separate a tested input from a documented route, a setup view or a feature still in development.
Open the technical guide ↗Agree the question, the expected result and a repeatable check before making a buying decision.
Get the evaluation checklist ↗Your environment. Your requirements.
A police examination, incident review and university practical ask different things of the same platform. Start with the workflow that looks like yours.

From seized storage to a focused examination.
Explore the workflow ↗
Fit the tools around the question you are asked.
Explore the workflow ↗
Test an incident hypothesis against the records.
Explore the workflow ↗
Plan evidence work beyond the laboratory.
Explore the workflow ↗
Give students evidence they can question.
Explore the workflow ↗Sector illustrations describe intended use cases, not endorsements or claims of current deployment.
From a result to a finding
An alert is a starting point. A useful handover also shows the input, the observation and the limits of the interpretation.
This native Malware Triage PDF comes from an inert constructed training example. It illustrates the reporting interface; a rule match is not, by itself, proof that a system was compromised.
Keep input records and outputs together.
Separate observations from conclusions.
View full screenThe planned 2027 bundle
The proposed portable bundle pairs Acorn with a workstation, USB-C-powered screen, mini keyboard, mouse and carry bag.
Working specification: 24 GB RAM, AMD Ryzen 9 or Intel Core i9, and a 1 TB PCIe SSD. Final components and compatibility are still being selected.
Explore the planned bundle ↗COMING SOON · Q1 2027
Provisional specification and price target. Final VAT treatment, delivery, licence terms and availability will be confirmed before orders open.
Notify me + 10% launch offer ↗No deposit or pre-order is taken here.
Before you decide
A demonstration should answer these against your actual work, not a generic feature checklist.
The Acorn name is used for the forensic software environment and the portable workstation offering. Confirm the edition, supplied hardware and included capabilities in the quotation and workstation specification.
That is not the proposition. Assess the relevant workflow and supported evidence against your existing tools. Keep your validation, specialist capabilities and independent checks where the work requires them.
The selected screens use documented public teaching material, constructed training records or native setup views. Captions identify the example. They are not presented as private client cases.
Not yet. The planned Q1 2027 bundle is not available to purchase. Contact and launch-update forms send your request to SQFR for review. They do not take payment or automatically enrol you in a mailing list.
Start with your requirements
Bring a task, an input format and the output you need. That makes for a better demonstration than a tour of every button.
Planned for Q1 2027
Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.
Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.
Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.
Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.
Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.