Integrated Forensic & Incident Response Tools

The Acorn includes more than 30 integrated open-source technologies supporting evidence acquisition, disk analysis, data recovery, Windows investigations, memory forensics, network analysis and incident response activities. These tools operate within a portable Linux-based forensic environment designed for investigators, cybersecurity teams, consultants, educators and students.

The Acorn is not simply a Linux workstation with forensic software installed. Integrated tools are organised into structured investigation workflows and supported by evidence protection controls designed to help maintain evidential integrity throughout the examination process.

Whether supporting traditional digital forensic investigations, incident response activities, cybersecurity operations or academic training, The Acorn provides access to recognised open-source technologies within a consistent investigative platform.

Explore The Acorn's Integrated Tools

The tools listed below support evidence acquisition, forensic analysis, data recovery, memory investigations, network analysis and incident response activities. Explore examples of some of the forensic outputs and evidence protection controls available throughout The Acorn platform.

Autopsy

Full suite digital forensic investigation platform.

Chainsaw

Windows event log analysis and threat hunting.

DB Browser for SQLite

SQLite database examination and analysis.

dc3dd

Forensic disk imaging and acquisition.

dcfldd

Forensic disk imaging with hashing and verification.

dd

Classic Unix disk imaging and data copying utility

Disks

Disk, partition and storage management utility.

Disk Usage Analyser

Storage usage analysis and visualisation.

EWF Tools

Evidence container creation and management.

ExifTool

Metadata extraction and analysis.

GTKHash

Hash verification and integrity validation.

Guymager

Forensic disk imaging and acquisition.

Hayabusa

Windows event log analysis and timeline generation.

John the Ripper

Password auditing and credential recovery.

Log2Timeline

Forensic timeline generation and event correlation.

NetworkMiner

Network forensic analysis and session reconstruction.

Nmap

Network discovery and security auditing.

OpenSuperClone

Advanced disk imaging and damaged drive recovery.

PhotoRec

File recovery and data carving utility.

Pinta

Image editing and annotation utility.

RegRipper

Windows Registry artefact extraction and analysis.

Remmina

Remote desktop and remote access client.

Scalpel

File carving and data recovery utility.

Sleuthy's Write-Blocker

Integrated write-blocking and evidence protection utility.

TestDisk

Partition recovery and file system repair utility..

Velociraptor

Endpoint visibility and digital forensic investigation platform.

VeraCrypt

Disk encryption and secure container management.

VLC

Media playback and evidence review utility.

Volatility 2 & 3

Advanced memory forensics and memory analysis framework.

Wireshark

Network protocol analysis and packet inspection.

YARA

Malware identification and pattern matching.

YARP

Windows Registry parsing and analysis.

Zenmap

Graphical interface for Nmap network scanning.

Explore The Acorn Platform

The technologies featured on this page are delivered as part of The Acorn forensic workstation. Systems are supplied with 16GB RAM and 500GB storage as standard, with enhanced hardware configurations available upon request for organisations requiring additional performance or storage capacity.