COMING SOON · Q1 2027 Planned releaseGet notified + 10% launch offer ↗
← Acorn overview

Acorn application guide

Forensic Workbench

Workbench keeps the file, its preview and the case context together. Open a relevant item, inspect its contents and follow the source record before deciding what it tells you. The example below shows a recovered photograph from a public training scenario.

Public training example · earlier interface

What does this file show, and where does it sit in the case?

Start with

  • Supported files and artefacts assembled into a case. The lead example uses the public Narcos teaching scenario.

What you can take away

  • Case-based file review, tagging and source-linked timeline views demonstrated on training material.
Inspect a recovered photograph alongside its file records in Acorn Workbench. This public Narcos teaching scenario shows bagged crystalline material; the image alone cannot identify the substance. View full screen
Inspect a recovered photograph alongside its file records in Acorn Workbench. This public Narcos teaching scenario shows bagged crystalline material; the image alone cannot identify the substance.

Open the screenshot and choose “View actual size” to read the records at their original resolution.

Earlier Workbench interface from the public Narcos teaching scenario, not a client case.

A practical starting point

How the workflow fits together.

  1. Define the question and identify the source collection. Review the recorded processing coverage before deciding which files or activity deserve attention.

  2. Inspect relevant files and timeline records, then tag items with the reason they matter. Distinguish the underlying record from your interpretation of it.

  3. Follow important leads back to the source and use a suitable independent check where needed. Keep processing gaps and unresolved questions in the examination notes.

Evaluate the workflow

Questions worth bringing to a demonstration.

  • Can you follow a selected result back to its source and distinguish source material from an examiner-created output?
  • What does the supplied build show when a processing stage is skipped, unavailable or limited?
  • Using a known training case, what would justify moving from a focused review to a broader examination?

Inside the examination

Start with a question. Follow the records.

Acorn brings tools into one workspace. The examiner connects the findings to the question, checks the context and decides what needs a closer look.

  1. 01

    Define the question

    What can the available files and activity records establish? Set the source, date range and permitted scope before choosing a tool.

  2. 02

    Locate the record

    Follow the relevant path, file or event. Keep its source reference and recorded time alongside the item you are reviewing.

  3. 03

    Examine the context

    Open the content, compare related records and test other explanations. A picture, page visit or search hit is a lead, not the whole answer.

  4. 04

    Explain the finding

    Record what you checked, what it shows and what remains unresolved. Keep enough context for another examiner to review the work.

Start with your requirements

Bring a sample question.

Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.

Planned for Q1 2027

Be first to hear. Save 10% at launch.

Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.

Notify me at launch ↗

Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.

About the screenshots and illustrations

Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.

Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.

Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.

Zoom in, then scroll to inspect the detail.

Open full-resolution image ↗

A useful first conversation

Let’s look at your workflow.

Tell us what you examine, where you work and what you need to deliver.

Use the enquiry form to outline your role, intended use and potential order quantity. Do not send case material through a general enquiry.

Your enquiry goes to the SQFR team. Please do not include passwords or case evidence.