TARGETING LATE Q4 2026Release date and final specification to be confirmedJoin the launch list for the planned 10% offer

THE ACORN / FORENSIC OPERATING SYSTEM

One portable operating system.
Thousands of forensic workflows.

The Acorn combines a forensic operating system, focused applications and a portable workstation. Protect and copy evidence, recover files, trace activity and prepare reports in the laboratory, office or field.

Local evidence analysis runs on the workstation. Remote sessions and cloud collection need network access.

THE ACORN / YOUR WORKSPACE
The Acorn workstation, front view.
The Acorn workstation, front view.

Images show earlier hardware. Final components, ports and compatibility remain subject to confirmation.

A forensic multi-tool

A multi-tool for forensic work

A portable Linux workspace for the laboratory, office and field.

Image a disk, recover a file or inspect its records in one prepared workspace.

Use focused applications for a specific question, then return to the case view. Keep specialist tools and your own scripts where the examination needs them.

  • Case workspace: keep tools, source records and reports within one forensic operating system.
  • Portable kit: plan a working setup before you arrive on site.
  • Extend the system: add Linux tools, your own scripts and organisation-approved workflows.
Explore the portable workstation

Hover, focus or tap to open the multi-tool.

The AcornOne forensic operating system

Why a forensic operating system

Advantages of a forensic operating system

Choose an advantage to see how it fits an examination.

01 / A prepared forensic workspace

One connected workspace

Keep source records, case review and focused tools together. Spend less time moving between unrelated utilities.

Browse the applications
The Acorn home screen with routes into its forensic applications.Enlarge this view

02 / A prepared forensic workspace

Protect the source

Inspect connected media and use integrated write-blocking controls within a planned acquisition workflow. External hardware blockers can be used where your policy requires them.

Explore device protection
Device Manager controls for inspecting connected media and protection settings.Enlarge this view

03 / A prepared forensic workspace

A portable setup

Use a portable workstation at the bench or on site. Plan suitable power, storage and a safe place to handle the evidence.

Explore the portable workstation
Illustrative portable forensic workspace in the field.Enlarge this view
Illustrative fieldwork scene.

04 / A prepared forensic workspace

Local analysis

Review local evidence without relying on a live cloud service. Online lookups, updates and remote collection need a separate, authorised connection.

Check capabilities and limits
The Acorn Linux desktop for local forensic work.Enlarge this view

06 / A prepared forensic workspace

Plan the setup

Scope the workstation, applications and support around the work you need to do. Reuse suitable equipment and keep specialist software where it adds value.

Discuss your requirements
Front view of the existing Acorn workstation enclosure.Enlarge this view
See current capabilities and limits
Recovery, from a missing file to difficult media

Choose standard imaging, resumable copying or a focused recovery route. Bad-sector mapping and tools such as OpenSuperClone can support a failing-disk workflow. Partition recovery and fragmented-file carving address different problems, so start with the condition of the source.

Shared intelligence, not separate lists for every task

Reuse keywords, file hashes, pattern rules and review leads across the investigation. Focused viewers help you work through large tables, event logs and timelines without losing the source behind an entry.

A route into specialist work

Guided workflows bring memory review, Windows file records, event logs and timeline processing closer to both new and experienced examiners. Graphical tools and the terminal let students learn the underlying method, not just follow an output.

Your scripts, formats and future workflows

Add open-source utilities or write a parser for an unusual case. Test custom scripts before casework and keep case data within your approved environment. Standard outputs help you retain your work without depending on one vendor.

We plan to provide regular fixes, tool updates, detection content and workflow improvements. We will confirm the release schedule before launch.

Protect. Image. Unlock. Recover.

Preserve the source with read-only acquisition

Kernel-level write blocking and forensic imaging are built into Device Manager and Forensic Imager. Work with encrypted volumes, recover lost partitions and image faulty disks.

  • Kernel-level write blocking

    Non-system drives start read-only at the Linux kernel level. Device Manager protects evidence disks and their partitions, blocking writes to the source.

    Explore Device Manager →
    From a protected device to acquisition

    Inspect device identity and protection state, open a source read-only, then send it straight to Forensic Imager. Output media is managed separately from protected evidence.

  • Forensic imaging

    Launch acquisition from Device Manager or Forensic Imager. Create E01 or RAW images, record acquisition hashes and save the image and logs to separate storage.

    Explore Forensic Imager →
    Choose how you acquire

    Choose physical or logical acquisition. The imaging interface brings source, destination, case details and hash settings together, with focused routes for healthy media and faulty-disk recovery.

  • Encrypted volumes

    Open BitLocker, LUKS and VeraCrypt/TrueCrypt volumes read-only using a password, recovery key or keyfile. The mounting tools are built into Forensic Imager.

    Explore read-only mounting →
    Work with encrypted evidence

    Select the encrypted partition or container and supply its credentials. Browse the unlocked files through a read-only view while keeping the source protected.

  • Partition recovery

    Scan for lost or deleted partitions from Forensic Imager's built-in recovery tool. Browse the recovered volume and extract selected files to a separate destination.

    Explore Partition Recovery →
    Recover without rewriting the source

    The scanner locates volume structures and opens them through a read-only view. Export a recovered partition or selected files while leaving the original partition table unchanged.

Faulty-disk detection and recovery

Imager checks SMART disk-health data and flags signs of failing media. Faulty-disk mode captures readable sectors first and records progress and problem areas in a recovery map. Resume from the saved map, control retry passes and follow progress in Live Disk Map.

Core forensic apps

Find the forensic app for your task

These nine core apps cover device checks, imaging, recovery and review. Filter by task, open a card to see an example, or browse all 49 application guides.

9 core apps

Device ManagerIdentify a device and inspect its protection state

Check the connected device, its partitions and any mounts before choosing an action. The selected USB device is reported as read-only. That state is useful context, not independent proof that every write attempt would be blocked.

Native device-state inspection

The selected USB is shown as read-only, with its kernel protection, partitions and mount information. View full screen
The selected USB is shown as read-only, with its kernel protection, partitions and mount information.
Read the Device Manager application guide
Forensic ImagerChoose the source and destination before imaging

Check the disk inventory, select the source and choose a separate destination. The Imager screen brings those settings together before acquisition. The screenshot shows setup, not a completed imaging job.

Acquisition setup shown

Supplied screenshot of the Acorn Forensic Imager with its disk inventory populated. View full screen
Supplied screenshot of the Acorn Forensic Imager with its disk inventory populated.
Read the Forensic Imager application guide
Forensic WorkbenchExamine a recovered photograph with its file records

A recovered photograph is worth more when you can check where it came from. In this public Narcos teaching example, Workbench puts the photograph beside its file records. The image alone cannot identify the pictured substance.

Public training example · earlier interface

Forensic Workbench: examine a recovered photograph with its file records in the training example. View full screen
Workbench shows a recovered photograph beside its file records in the public Narcos teaching scenario. The picture alone cannot identify the crystalline material.
Read the Forensic Workbench application guide
File Recovery CarverRecover PDF content after a quick format

A quick format left four PDF structures in an owned FAT16 training image. Recovery Carver found them in free space. The recovered files were then checked against the originals, including where each PDF ended.

Constructed test example

After an actual quick format of an owned FAT16 image copy, the native carver located four intact PDF structures in its free space. The selected invoice can be reviewed alongside the recovery audit fields. View full screen
After an actual quick format of an owned FAT16 image copy, the native carver located four intact PDF structures in its free space. The selected invoice can be reviewed alongside the recovery audit fields.
Read the Recovery Carver application guide
Partition RecoveryFind a volume after its partition entry is lost

The training image has no partition table, but its FAT16 volume survives. The scanner finds that volume at byte offset 1048576. Selected files recovered from it match their reference hashes.

Constructed test example

The native scanner locates a FAT16 volume at byte offset 1048576 despite the missing partition table. This is a constructed image, not an actual client disk. View full screen
The native scanner locates a FAT16 volume at byte offset 1048576 despite the missing partition table. This is a constructed image, not an actual client disk.
Read the Partition Recovery application guide
Forensic NavigatorRead an examiner’s report beside its source files

Navigator previews a Case Notes PDF beside the event-log export and reference files used for the work. The PDF is an examiner-produced report, not a document recovered from the investigated computer.

Public training example

Forensic Navigator: read an examiner’s report beside its source files in the training example. View full screen
Navigator previews a Case Notes PDF beside its source export and reference files. The report records a filter operation on public event-log data.
Read the Forensic Navigator application guide
Browsing HistoryReview recorded visits to firearm marketplaces

A category filter picks out 65 firearm-marketplace records from the public Lone Wolf training data. Review the page titles, recorded times and source URLs together. A visit alone does not show a purchase or identify the user.

Public training example

A category filter shows 65 firearm-marketplace browsing records from 2,613 public Lone Wolf training records. Recorded times, page titles and source URLs stay together, with the selected entry expanded below. View full screen
A category filter shows 65 firearm-marketplace browsing records from 2,613 public Lone Wolf training records. Recorded times, page titles and source URLs stay together, with the selected entry expanded below.
Read the Browsing History application guide
Event Log ViewerRead encoded PowerShell beside the source event

Eighteen rule matches flag archive-decoding commands in public training logs. The selected view puts the encoded command beside a decoded gzip script fragment. Review the source event and repeated matches before counting distinct actions.

Public training example

Eighteen rule matches identify archive-decoding PowerShell command lines in public training logs. The selected record preserves the encoded command, source event and a decoded gzip script fragment. View full screen
Eighteen rule matches identify archive-decoding PowerShell command lines in public training logs. The selected record preserves the encoded command, source event and a decoded gzip script fragment.
Read the Event Log Viewer application guide
Timeline ViewerInvestigate an audit-log clearing event

An audit log has been cleared. Filtering 226 public training rows reveals two timestamp entries for Windows Security Event 1102. They describe one event, not two actions. Check the recorded account and surrounding activity before explaining the clearing.

Public training example

Timeline Viewer: investigate an audit-log clearing event in the training example. View full screen
Filtering 226 public training rows finds two timestamp entries for one Windows audit-log clearing event. The detail shows the account and security identifier (SID) for follow-up checks.
Read the Timeline Viewer application guide

Check each guide’s example and the technical support guide for the relevant build, inputs and limits.

Browse the Application Catalogue

Inside the examination

Examine a photograph in its file context

The Acorn brings the tools together. You link the findings to the case, check the context and decide what needs a closer look.

  1. 01

    Define the question

    What can the files and records tell you? Set the source, date range and limits of your permission before choosing a tool.

  2. 02

    Locate the record

    Follow the path, file or event. Keep its source reference and recorded time beside the item you review.

  3. 03

    Examine the context

    Open the item, compare related records and test other explanations. A picture, page visit or search hit is a lead, not the whole answer.

  4. 04

    Explain the finding

    Record what you checked, what it shows and what is still unclear. Keep enough detail for another examiner to review your work.

The photograph and its Recycle Bin entries

The Acorn Workbench: a recovered photograph and its file records from the public Narcos teaching scenario. The pictured crystalline material cannot be identified from the image alone. View full screen
The Acorn Workbench: a recovered photograph and its file records from the public Narcos teaching scenario. The pictured crystalline material cannot be identified from the image alone.

A recovered photograph with its file records

The photograph was recovered in the public Narcos teaching scenario. Workbench shows it beside Recycle Bin entries, so you can examine the file records as well as the picture.

Check when the file was deleted

To investigate deletion, check the matching Recycle Bin metadata. The photograph’s modification time describes a different event. Compare both with other activity on the device.

Earlier supplied Workbench interface, using the public Narcos teaching scenario. Select the screen, then choose “View actual size” to inspect the records.

Where would I find the deletion time?

Illustrative training record, separate from the Narcos capture

Recycle Bin record$I metadata + $R content
Original file
Training-photo.jpg
Moved to Recycle Bin
Record source
Companion $I record
Content to examine
Matching $R file

Read the deletion time from the matching Recycle Bin metadata. File created, modified and accessed times answer different questions. Record the time zone and compare related activity.

From file to finding

Right-click. Inspect. Report.

A suspect PDF arrives by email. Check what the file contains, then choose the next step. The visible page is only part of the story.

Suspect-attachment.pdfConstructed email scenario

Try Actions, or right-click the example file.

Illustration only. No file is analysed in your browser. Available actions depend on the file and Acorn build.

Acorn folder actions including Artefact Lens, Rapid Triage, an intelligence PDF report and a directory inventoryView original screenshot
Genuine folder actions. Artefact Lens identifies the item; separate menu actions offer reports and other workflows.
See the three reporting screenshots Folder actions, directory report and event records

Three real reporting views

Training screenshot: folder right-click actions with reporting choices.
1. Select the training folder and open its right-click actions.

Three training screenshots show the reporting steps. Playback timing is illustrative, not a processing benchmark.

Download the animated walkthrough (GIF)

Triage an item with a right click

A normal-looking PDF. A hidden backdoor.

Right-click an item and open Artefact Lens. It checks the file's contents, not just its name, and points you towards a suitable tool.

Recognised file and record types include:

  • Windows event logs.evtx
  • NTFS file records$MFT
  • Browser recordsChrome and Firefox SQLite databases
  • Office documents.doc, .xls, .ppt, .docx, .xlsx, .pptx
  • Windows shortcuts.lnk
  • Apple property listsBinary and XML .plist
  • PDF documents.pdf
  • Registry hivesNTUSER.DAT, SYSTEM, SOFTWARE

Recognition is a first check, not a completed examination. Parsing and reports depend on the file and installed tools. Check the supported workflows.

In the 2013 MiniDuke attacks, a convincing PDF concealed malicious code. Explore the historical example to see why the visible page is only part of the story.

A finding is a lead, not a verdict. Finding a suspect file does not prove it ran. Compare the file with device and email records.

Explore Acorn Malware Triage →
Inside a malicious PDFMiniDuke · 2013

A backdoor hidden behind a briefing

Researchers found a malicious program concealed in the PDF. An exploit, code that abuses a software flaw, could install it through a vulnerable version of Adobe Reader.

Forensic question: Was the file merely present, or did it run?

Look beyond the visible page

The published analysis describes compressed JavaScript and an encoded payload inside the PDF. A dropped program contained both the backdoor and a harmless document to show the reader.

Forensic question: Which part of the file supports the finding?

Return to the original file

ASEM_seminar.pdf is one of the samples named in the research. In a case, record the source path and file hash, a fingerprint used to check the file has not changed.

Next check: Compare the attachment, email and device records. Finding the PDF alone does not prove infection.

Illustration based on published MiniDuke research, not an Acorn test result. No malware is hosted or run. Read the technical research (PDF) (opens in a new tab).

A workspace beyond the office

A portable workspace on site

The planned kit combines a workstation, screen, keyboard and mouse. Choose a safe working area with suitable power and storage for the task.

Workstation concept illustration: at a client’s premises. View full screen
Workstation concept illustration: at a client’s premises.

At a client’s premises

Plan a temporary workspace around your permitted tasks, the power supply and the systems you need to examine.

Workstation concept illustration: in a sheltered field workspace. View full screen
Workstation concept illustration: in a sheltered field workspace.

In a sheltered field workspace

You still need suitable power, shelter from the weather and a safe place to handle the source.

Generated illustrations of the proposed hardware and working settings, not photographs of deployments. Connections, source adapters, power and environmental suitability must be checked for the actual task.

Explore the workstation and portable kit

One workspace. Field to desk.

Take the workspace with you

Acquire on site. Review at your desk. Keep your case files and forensic tools in the same workspace.

The planned kit pairs a small workstation with a USB-C-powered screen, mini keyboard, mouse and carry bag. Plug into mains power on site, or plan an acquisition around a suitable rechargeable power station.

Target: 24 GB RAM · Ryzen Embedded, 6 cores / 12 threads · 1 TB PCIe SSD

Back at the desk, use a compatible USB-C dock for multiple screens, a full-size keyboard, mouse and external disks. Continue the review in Workbench, with focused tools close at hand.

How does it compare with a Pelican case?

The aim is a carry-bag kit rather than a workstation built into a full-size hard case. For scale, a Peli 1510 case measures 55.9 × 35.1 × 22.9 cm outside. The Acorn unit measures about 12.8 × 12.8 × 4.4 cm and weighs around 500 g. Its power supply, screen and other kit add to the packed size and weight.

The diagram is not to scale. A carry bag does not offer the same protection as a rated hard case.

Targeting late Q4 2026. Final hardware, price and compatibility will be confirmed before orders open. No deposit is taken here.

A bench wherever the case takes you

Connect the source, check write protection and choose separate storage for the image. With a suitable mains socket and adaptor, there is no battery countdown.

Keep power stable for the whole acquisition. Local evidence analysis runs on the workstation; cloud collection and remote sessions need a network.

How long between sockets?

As a planning example, a 512 Wh battery could supply a 100 W setup for about 4.1 hours, assuming 80% usable energy. This is not a measured Acorn runtime.

Estimate a different battery or load

Capacity in watt-hours × 0.8 ÷ total load in watts. The 80% figure is a planning assumption, not a battery test. Include the computer, screen, disks and adaptors. Measure your full setup and allow extra reserve.

At an assumed 100 W: 256 Wh gives about 2.0 hours; 1,024 Wh gives about 8.2 hours. Temperature, battery condition and power losses change the result. See the runtime calculation method.

Use a suitably rated AC power station and the correct workstation adaptor. A USB phone power bank is not a confirmed power source. Battery packs are not part of the stated bundle.

Using it in a vehicle or carrying bag

Work in a parked vehicle with the equipment secured. Check the power station's vehicle-charging requirements; do not rely on a starter battery for a long acquisition.

Carry the kit in a bag, then take it out to work. Keep vents clear and use a stable, ventilated surface. Do not run the workstation or power station inside a closed bag.

Small on the move. At home on a full desk.

A compatible USB-C dock can bring your screens and desk peripherals together. Spread the review across multiple displays, with external disks within reach.

*Video output, display count and Linux dock support depend on the final hardware. USB-C alone does not guarantee video or charging; separate workstation power may be needed.

What needs checking before docking?

Check the workstation's video-capable port, the dock, cables and display limits. Validate evidence connections and write protection separately: a dock is not a write blocker. Use suitable direct connections where your acquisition workflow needs them.

How dock and host compatibility work

Connection concepts, not a port map or tested hardware configuration. Illustrations are not to scale.

Discuss your workflow

See The Acorn in action

Tell us about the evidence you handle and the work you need to do. We can demonstrate the relevant tools and discuss a setup for your team.

Zoom in, then scroll to inspect the detail.

Open full-resolution image ↗

A useful first conversation

Let’s look at your workflow

Tell us what you examine, where you work and what you need to deliver.

Use the enquiry form to outline your role, intended use and potential order quantity. Do not send case material through a general enquiry.

Your enquiry goes to the SQFR team. Please do not include passwords or case evidence.