Start with the source
Check what is available, how it can be accessed and where the output will go. The right method depends on the device and the examination.
SQUIRRELFORENSICSDesigned in the UKAcorn workspace and app directory
See how Acorn Home organises the workspace, then choose an application by the source you have or the task you need to complete.
The forensic operating system
Acorn is the Linux workspace. Home helps you find a tool; Workbench gives case review its working context. Move into a specialist application when the record or question calls for it.
View full screenCheck what is available, how it can be accessed and where the output will go. The right method depends on the device and the examination.
Browse, image, recover or inspect a particular record type. Follow the app guide for the expected inputs, useful output and limits.
Retain source references, settings and notes so that another examiner can check the result and understand unresolved points.
Inside Acorn Home
The native Home screen groups 53 launcher entries across seven stages. Those entries include apps, setup helpers and shortcuts. The directory below focuses on 49 forensic apps and workflow tools.

Scroll through the complete screen, or open it at full size. The screenshot includes the original launcher utilities; the website’s forensic directory omits Hardware Readiness, State Lens, Capability Matrix and OS Guard.
Enlarge the complete Home screen ↗This is an unaltered native interface capture, not evidence that every launcher completed a test. App guides distinguish reviewed results, setup views and work still in development.
The forensic app catalogue
Browse all 49 forensic apps and workflow tools. Filter by task or choose Core for the nine starting points featured on the homepage.
49 forensic apps and workflow tools
Identify the evidence device before choosing an examination action. Device Manager makes the reported device, partition, mount and protection state available for inspection. That gives the examiner useful context, while the chosen protection method still needs its own validation.
Native device-state inspection
View full screenA forensic disk imaging job needs a clear source, a separate destination and a verification plan. The populated Imager interface brings those choices together before capture. Agree what will be checked afterwards, rather than treating a completed progress indicator as sufficient evidence of success.
Acquisition setup shown
View full screenCollection planning should make the account, scope and destination explicit. This interface shows those choices before a provider-export workflow is attempted.
Provider-export setup shown
View full screenA missing partition entry does not necessarily mean all of its contents have gone. The demonstrated workflow locates a FAT16 partition and checks selected recovered files.
Demonstrated on constructed training data
View full screenThe disk map gives a visual way to review acquisition coverage. Its demonstrated example comes from regular image files, not a failing physical drive.
Demonstrated on constructed training data
View full screenRead-only access begins before the mount action. Inspect image and partition information, then select a method appropriate to the evidence and examination.
Read-only access options shown
View full screenVirtual Boot exposes the choices needed to plan an image-based boot. The displayed configuration is useful preparation, not evidence that the selected image successfully boots.
Boot configuration shown
View full screenGood timeline work starts with an explicit source and time basis. The Plaso setup route exposes those decisions before processing.
Processing options shown
View full screenWorkbench keeps the file, its preview and the case context together. Open a relevant item, inspect its contents and follow the source record before deciding what it tells you. The example below shows a recovered photograph from a public training scenario.
Public training example · earlier interface
View full screenUse the NTFS file record to investigate a specific file, rather than reading a timestamp difference as a conclusion. The MFT view helps compare stored information; copying, application behaviour and other artefacts may explain a pattern that initially looks unusual.
Demonstrated on public training data
View full screenFollow changes through the file reference when a name alone is no longer enough. USN records can help connect temporary names, renames and deletions, but a useful sequence still needs the associated file context and a clear account of what the journal covers.
Demonstrated on public training data
View full screenAn event match is a place to start reading. Event Log Viewer keeps the underlying record and decoded command context close to the review, so an examiner can separate what was recorded from a proposed action, duplicated rule match or inferred outcome.
Demonstrated on public training data
View full screenRegistered software and application paths can help explain the state of a Windows system. Use that state to choose follow-up questions. A registration entry is not an execution history, and the significance of a value depends on its source and context.
Demonstrated on public training data
View full screenApplication-level network counters can help decide where to investigate next. SRUM Viewer makes those recorded usage rows available for review, but identifying transferred files or explaining a transfer needs evidence beyond a byte count.
Demonstrated on public training data
View full screenA shortcut can retain a target path, arguments and details of a volume or authoring system. Use those fields to guide a focused examination, while keeping the shortcut's own history separate from the target information stored inside it.
Demonstrated on public training data
View full screenConfiguration is evidence of a setting, not proof that its action completed. Read a LaunchAgent's arguments and conditions together before making that distinction.
Demonstrated on constructed training data
View full screenA chronology is useful when it explains why each row belongs in the account. Timeline Viewer supports focused review of recorded activity, while the examiner keeps timestamp kind, time basis and source context separate from the final interpretation.
Demonstrated on public training data
View full screenChoose the artefact that can address the question, then inspect what its parser actually returned. Artifact Lab's demonstrated task and Prefetch workflows support focused examination. A successful stage label is not a substitute for checking the output and its diagnostics.
Demonstrated on constructed training data
View full screenThe guide helps turn a broad question into a source checklist. It supports examination planning; it does not itself process the evidence.
Reference guide
View full screenIdentity work needs a precise scope and appropriate source material. The illustrated interface distinguishes account records from workflows that depend on valid key material.
Reference interface
View full screenA note may describe a plan, a reminder or a handover. The decoder makes the recorded text available for review without turning it into proof that the plan happened.
Demonstrated on constructed training data
View full screenThe Android collection interface presents an authorised logical-acquisition route. Device state, authorisation and operating-system version determine what can actually be collected.
Collection controls shown
View full screenKeep acquisition separate from interpretation. Apple Mobile Lab's illustrated workflow starts with supplied material and a defined parsing route.
Input and parser controls shown
View full screenAccount investigations benefit from connecting related audit events. The demonstrated workflow compares sign-ins, forwarding and downloads without treating a rule match as proof of compromise.
Demonstrated on constructed training data
View full screenBrowsing History brings recorded visits, searches and downloads into a reviewable view. Narrow the records by a relevant term or category, then inspect the page title, URL, time and source. The public Lone Wolf example makes that process visible with firearm-marketplace browsing records.
Demonstrated on public training data
View full screenDeletion or quick formatting can leave file content behind. The demonstrated carver finds PDF structures, with explicit checks of where the recovered content ends.
Demonstrated on constructed training data
View full screenA small, explicit query can answer a question that is easy to lose in a large database. Data Explorer's demonstrated read-only SQLite view lets the examiner inspect tables and stored values while keeping query choices and timestamp interpretation open to review.
Demonstrated on public training data
View full screenA focused table view can be the quickest route through a large output. Text Lab keeps the fields needed to check a lead beside the filtered records.
Demonstrated on public training data
View full screenReview the detail behind a network lead. The supplied example separates readable HTTP material and TLS names from encrypted content the capture does not disclose.
Demonstrated on constructed training data
View full screenA reference match is most useful when the algorithm, list and classification remain clear. The demonstrated hash workflow identifies a match to supplied reference material. The examiner must still decide what that identity means for the question being investigated.
Demonstrated on public training data
View full screenRun a focused artefact action and inspect its output within the evidence workspace. This example uses three public Prefetch fixtures.
Demonstrated on public training data
View full screenReview a decoding result before making assumptions about the file it contains. The verified example is a generic container test, not a claim of universal antivirus-format support.
Demonstrated on constructed training data
View full screenA useful triage report keeps the source file, hashes and review leads together. This native report comes from an inert training file examined without executing its contents, so each observation can be checked against a known input.
Demonstrated on constructed training data
View full screenA document can contain ordinary links and metadata as well as material worth investigating. This workflow starts with structure, not an assumption that every extracted string is a threat.
Demonstrated on constructed training data
View full screenUse text matches to prioritise a lawful examination, not to classify unseen image content. The demonstrated workflow makes no visual-content verdict.
Demonstrated on constructed training data
View full screenMemory examination depends on suitable source material and a compatible method. The supplied screen shows preparation, not recovered processes or completed analysis.
Memory analysis setup shown
View full screenStart with the shape of the traffic, then follow the detail. Network Workbench's supplied example summarises a public historical capture rather than live network activity.
Demonstrated on public training data
View full screenThe offline example brings network observations into native review tables. It does not establish live interception or every automatic processing path.
Demonstrated on constructed training data
View full screenPut available photo coordinates and recorded times side by side before interpreting them. The map and source table make that comparison visible, but the metadata does not independently establish who took the images or travelled between the points.
Demonstrated on constructed training data
View full screenRead the records before interpreting the map. The supplied example demonstrates a chronology using fictional data, not a coverage survey or reconstructed personal journey.
Demonstrated on constructed training data
View full screenA spectrogram lets an examiner compare sound frequency and timing with the source recording. This known-input example shows two tones separated by silence, making the measured output easy to check without turning a visual pattern into an authenticity verdict.
Demonstrated on constructed training data
View full screenThe supplied example is deliberately local. It shows query handling, not search-engine coverage, dark-web discovery or evidence that an individual appears in leaked data.
Demonstrated on constructed training data
View full screenExtraction is a useful first step, but it does not establish current maliciousness. Keep an indicator's source and date beside the address.
Demonstrated in the recorded development build
View full screenHome labels this route Velociraptor Setup; the current interface is Endpoint Collector Setup. It exposes deployment preparation without implying that a collector is already running.
Deployment setup shown
View full screenA response workflow needs authority and a clear collection plan. The current examples show the setup decisions before execution.
Collection setup shown
View full screenA useful case note connects the question, the source, the work carried out and the reasoning. Case Notes supports that account alongside the examination, with a demonstrated native PDF export. A hash can identify an export; it cannot certify its conclusions.
Demonstrated on public training data
View full screenAn audio note may support the working record when its purpose and handling are clear. The supplied screen shows the available controls rather than a completed recording.
Recording controls shown
View full screenA checklist can prompt useful questions at the right stage. Workflow Coach supports a reasoned examination rather than replacing the examiner's method.
Teaching checklist
View full screenCheck each guide’s example and the technical support guide for the relevant build, inputs and limits.
A working context
A useful question narrows the next step: recover a deleted file, inspect a browser record, review an event or compare a time sequence. Keep observations separate from conclusions.
Compute Forensics explains how Acorn’s collection and review tools fit into evidence-led examination. SQFR handles Acorn product demonstrations, software and workstation enquiries.
Acorn at Compute Forensics ↗Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.
Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.
Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.