Structured Investigator Outputs

Investigators need structured outputs that can be reviewed, validated, exported, correlated, and incorporated into reporting workflows.

The Acorn is designed to support this process through integrated workflows that generate investigator-focused outputs across multiple stages of an investigation.

Autopsy Investigation HTML Report

Output Screenshots

This section shows a selection of example investigative artefacts, structured exports, timeline data, forensic reports, memory analysis findings, and workflow-generated evidence outputs on The Acorn.

Timeline Reconstruction

Evidence Source Selection

Timeline Generation In Progress

Timeline Generation Complete

Timeline Output Files

Memory Analysis

Memory Analysis Workflow Selection

Memory Analysis In Progress

Memory Analysis Complete

Extracted Memory Artefacts

Hidden Data & Recovery

Recovery Source Selection

File System Selection

Recovery Complete

Recovered Files

Evidence & Log Analysis

Event Log Selection

Log Analysis In Progress

Log Analysis Complete

Analysis Output Files

Investigation Output Examples

The examples below show how The Acorn’s integrated forensic tools on the Acorn generate structured outputs for a range of forensic workflows, including timeline reconstruction, memory analysis, data recovery, event log analysis and network investigations.

Timeline Reconstruction

Structured timelines from forensic artefacts, event logs and endpoint data.

• Unified timelines correlating activity across multiple sources with precise timestamps
• Chronological sequencing of user and system actions for clear event reconstruction
• Key event summaries with direct context for reporting and further analysis

Memory Analysis

Runtime artefact extraction and analysis from memory acquisitions.

• Detection of running processes, injected code and persistence mechanisms
• Extraction of credentials, encryption keys and active connections at time of capture
• Structured findings on suspicious artefacts to support targeted follow-up

Evidence & Log Analysis

Parsing and review of Windows event logs, registry and endpoint artefacts.

• Detailed examination of authentication events, process execution and system changes
• Registry analysis identifying configuration modifications and historical system state
• Consolidated outputs ready for timeline integration and report preparation

Hidden Data & Recovery

Recovery and examination of deleted files, hidden partitions and embedded metadata.

• Recovery of deleted content from unallocated space and damaged media
• Metadata analysis to establish file provenance, creation and modification history
• Review of encrypted containers and partition structures for accessible data

Network & Traffic Analysis

Processing of network captures, session reconstruction and host discovery.

• Reconstruction of network sessions and identification of communication patterns
• Extraction of files and indicators from packet data for further examination
• Network mapping documenting connected hosts and observed data flows

Threat Detection

Detection of suspicious behaviours and known patterns across logs and artefacts.

• Application of detection rules to surface anomalies in event and endpoint data
• Cross-referencing of findings with timelines and memory artefacts
• Prioritised outputs to focus examiner review and support clear reporting

Explore The Acorn Investigation Platform

The Acorn combines integrated forensic workflows, evidence protection controls, investigator-focused reporting, and structured forensic outputs within a portable Linux forensic environment.

Designed for digital forensics, incident response, cybersecurity investigations, education, and field-based investigative work, The Acorn helps investigators move from acquisition through analysis and reporting using a unified workflow-driven platform.