One connected environment
Keep source records, case review and focused tools together. Spend less time moving between unrelated utilities.
THE ACORN / FORENSIC OPERATING SYSTEM
The Acorn brings a forensic operating system, focused apps and a portable workstation together. Protect and copy evidence, recover files, follow activity and prepare reports. Take the same workspace from the laboratory to the office or field, with local analysis that does not depend on the cloud.
Core forensic apps
These nine core apps cover device checks, imaging, recovery and review. Filter by task, open a card to see an example, or browse all 49 application guides.
9 core apps
Check that you have the right device before you act. Device Manager shows the reported device, partitions, how they are attached and their protection state.
Native device-state inspection
View full screen
Choose the source, a separate place to save the copy and a plan to check it. The Imager screen shows these choices before capture. Decide how you will check the result.
Acquisition setup shown
View full screen
Workbench keeps the file, its preview and the case context together. Open an item, check its contents and follow the source record before drawing a conclusion. This example shows a recovered photograph from a public training scenario.
Public training example · earlier interface
View full screen
Deleting a file or quick-formatting a disk can leave its content behind. This example finds PDF structures and checks where the recovered content ends.
Demonstrated on constructed training data
View full screen
A disk section, called a partition, can lose its entry without losing all its files. This example finds a FAT16 partition and checks selected recovered files.
Demonstrated on constructed training data
View full screen
Review recorded page visits, searches and downloads in one view. Filter by a term or category, then check the page title, web address, time and source. The public Lone Wolf example shows this process with firearm-marketplace browsing records.
Demonstrated on public training data
View full screen
An event match is a place to start, not a conclusion. Event Log Viewer shows the source record and decoded command. Check what the record says. Keep it separate from a proposed action, a repeat rule match or an outcome you have inferred.
Demonstrated on public training data
View full screen
Review activity in date order and check why each event matters. With Timeline Viewer, keep track of what each time records, the time basis used and where the record came from. These details help you explain your findings.
Demonstrated on public training data
View full screen
Check each guide’s example and the technical support guide for the relevant build, inputs and limits.
Browse the Application Catalogue ↗A forensic multi-tool
For the lab, office, field and defence investigation. The Acorn brings digital forensics and incident response (DFIR) into one portable Linux operating system, with 49 focused application guides to explore.
Think of it as a forensic Swiss Army knife: disk imaging, recovery, memory analysis and artefact review in one working environment.
Take the same workspace from your desk to the evidence. The planned bundle brings the computer, portable screen, keyboard, mouse, storage adaptors and carry case together. Keep specialist tools where the case needs them.
Why a forensic operating system
An entire working environment, prepared for the evidence rather than assembled again for each task.
Keep source records, case review and focused tools together. Spend less time moving between unrelated utilities.
Inspect connected media and use integrated write-blocking controls within a planned acquisition workflow. External hardware blockers can be used where your policy requires them.
Use a portable workstation at the bench or on site. Plan suitable power, storage and a safe place to handle the evidence.
Review local evidence without relying on a live cloud service. Online lookups, updates and remote collection need a separate, authorised connection.
Start with the case question. Collect what is needed, review the relevant records and widen the work when the evidence calls for it.
Reuse one portable system for several tasks. Reduce duplicated hardware and configuration work, while keeping specialist software where it earns its place.
Choose standard imaging, resumable copying or a focused recovery route. Bad-sector mapping and tools such as OpenSuperClone can support a failing-disk workflow. Partition recovery and fragmented-file carving address different problems, so start with the condition of the source.
Reuse keywords, file hashes, pattern rules and review leads across the investigation. Focused viewers help you work through large tables, event logs and timelines without losing the source behind an entry.
Guided workflows bring memory review, Windows file records, event logs and timeline processing closer to both new and experienced examiners. Graphical tools and the terminal let students learn the underlying method, not just follow an output.
Add open-source utilities or write a parser for an unusual case. An organisation-approved AI assistant can help develop a script, but test the result and keep case data within your approved environment. Standard outputs help you retain your work without depending on one vendor.
Regular updates are planned for fixes, tools, detection content and workflow improvements. The release schedule will be confirmed with the product.
SQFR · The Acorn · Workbench
The Acorn grew from frustration with finding a different tool for each task. Hashes, keywords and intelligence were held in separate places. What began as scripts and a personal incident-response toolkit developed into a connected forensic operating environment.
Access tools to collect and examine evidence in one place. Check the source and choose how to work with it before you start.
Organise evidence, search records and tag useful items. Keep the source close while you decide what a result means.
Explore Workbench ↗Choose a tool to suit the question: an event log, a deleted file or an account check. Look at what goes in, what comes out and the limits of the tool.
Browse by task ↗One environment. A deliberate workflow.
Begin with a protected source and a clear question. Use the right tool to read its artefacts, the files and records left by activity. Check what they mean, keep their source references and explain the limits of the result.
Check the device, its state and what you have permission to examine. Then check how it is protected and choose a suitable way to collect the evidence.
Device and imaging tools ↗Move from the case view to a file, event, browser record or account action. Check where it came from as you test what it could mean.
Inside the Workbench ↗Use the logs, tables and reports supported for your task. A finished process may not have covered everything. Explain any gaps when you hand over the work.
See a real report example ↗Inside the examination
The Acorn brings the tools together. You link the findings to the case, check the context and decide what needs a closer look.
What can the files and records tell you? Set the source, date range and limits of your permission before choosing a tool.
Follow the path, file or event. Keep its source reference and recorded time beside the item you review.
Open the item, compare related records and test other explanations. A picture, page visit or search hit is a lead, not the whole answer.
Record what you checked, what it shows and what is still unclear. Keep enough detail for another examiner to review your work.
View full screen
The public Narcos capture shows Recycle Bin entries beside the selected photograph. Open the full-size image to inspect the names and recorded times.
A file’s modification time is not its deletion time. Read the matching Recycle Bin record and compare the activity around it.
Earlier supplied Workbench interface, using the public Narcos teaching scenario. Select the screen, then choose “View actual size” to inspect the records.
Illustrative training record, separate from the Narcos capture
Read the deletion time from the matching Recycle Bin metadata. File created, modified and accessed times answer different questions. Record the time zone and compare related activity.
A workspace beyond the office
Where will you work, and what will you need there? The proposed portable kit brings the workstation, screen, keyboard and mouse together.
View full screen
Plan a temporary workspace around your permitted tasks, the power supply and the systems you need to examine.
View full screen
You still need suitable power, shelter from the weather and a safe place to handle the source.
Generated illustrations of the proposed hardware and working settings, not photographs of deployments. Connections, source adapters, power and environmental suitability must be checked for the actual task.
Explore the workstation and portable kit ↗Right click. Follow the evidence.
Right-click a file or folder to open its relevant actions. Artefact Lens helps identify the item; the reporting route turns supported records into something you can read and follow.
View full screen
Artefact Lens recognises the selected item and helps route it to the right workflow. Report actions sit alongside it in the context menu.
INTERACTIVE EXPLANATION
Right-click the example record or use the Actions button. This browser illustration does not run The Acorn.
Choose an action to see how the source, finding and report relate.
Illustrative interaction. No file is uploaded, analysed or downloaded.
A guided sequence of genuine training screenshots, not a continuous recording or a processing-time benchmark. The report keeps the source close to the finding.
Download the animated walkthrough (GIF)From a result to a finding
An IP address, keyword, file hash or rule match can turn a long list of records into a focused line of enquiry. Follow the hit back to its source, then decide what to examine next.
Use YARA pattern rules, shared keywords and other checks to surface useful leads. A heuristic is a clue based on a pattern, not a final verdict. The point is to narrow the next question, not to replace the examiner.
Keep input records and outputs together.
Separate observations from conclusions.
Payment-advice.pdf
The planned 2026/2027 bundle
The proposed portable bundle pairs The Acorn with a workstation, USB-C-powered screen, mini keyboard, mouse and carry bag.
Working specification: 24 GB RAM, AMD Ryzen 9 or Intel Core i9, and a 1 TB PCIe SSD. Final components and compatibility are still being selected.
Explore the planned bundle ↗COMING SOON · Q4 2026
Final components, pricing, VAT, delivery and licence terms will be confirmed before orders open.
Notify me + 10% launch offer ↗No deposit or pre-order is taken here.