Structured Investigator Outputs
Investigators need structured outputs that can be reviewed, validated, exported, correlated, and incorporated into reporting workflows.
The Acorn is designed to support this process through integrated workflows that generate investigator-focused outputs across multiple stages of an investigation.
Output Screenshots
This section shows a selection of example investigative artefacts, structured exports, timeline data, forensic reports, memory analysis findings, and workflow-generated evidence outputs on The Acorn.
Timeline Reconstruction
Investigation Output Examples
The examples below show how The Acorn’s integrated forensic tools on the Acorn generate structured outputs for a range of forensic workflows, including timeline reconstruction, memory analysis, data recovery, event log analysis and network investigations.
Timeline Reconstruction
Structured timelines from forensic artefacts, event logs and endpoint data.
• Unified timelines correlating activity across multiple sources with precise timestamps
• Chronological sequencing of user and system actions for clear event reconstruction
• Key event summaries with direct context for reporting and further analysis
Memory Analysis
Runtime artefact extraction and analysis from memory acquisitions.
• Detection of running processes, injected code and persistence mechanisms
• Extraction of credentials, encryption keys and active connections at time of capture
• Structured findings on suspicious artefacts to support targeted follow-up
Evidence & Log Analysis
Parsing and review of Windows event logs, registry and endpoint artefacts.
• Detailed examination of authentication events, process execution and system changes
• Registry analysis identifying configuration modifications and historical system state
• Consolidated outputs ready for timeline integration and report preparation
Hidden Data & Recovery
Recovery and examination of deleted files, hidden partitions and embedded metadata.
• Recovery of deleted content from unallocated space and damaged media
• Metadata analysis to establish file provenance, creation and modification history
• Review of encrypted containers and partition structures for accessible data
Network & Traffic Analysis
Processing of network captures, session reconstruction and host discovery.
• Reconstruction of network sessions and identification of communication patterns
• Extraction of files and indicators from packet data for further examination
• Network mapping documenting connected hosts and observed data flows
Threat Detection
Detection of suspicious behaviours and known patterns across logs and artefacts.
• Application of detection rules to surface anomalies in event and endpoint data
• Cross-referencing of findings with timelines and memory artefacts
• Prioritised outputs to focus examiner review and support clear reporting
Explore The Acorn Investigation Platform
The Acorn combines integrated forensic workflows, evidence protection controls, investigator-focused reporting, and structured forensic outputs within a portable Linux forensic environment.
Designed for digital forensics, incident response, cybersecurity investigations, education, and field-based investigative work, The Acorn helps investigators move from acquisition through analysis and reporting using a unified workflow-driven platform.