COMING SOON · Q1 2027 Planned releaseGet notified + 10% launch offer ↗
← Acorn overview

Acorn application guide

Forensic Imager

A forensic disk imaging job needs a clear source, a separate destination and a verification plan. The populated Imager interface brings those choices together before capture. Agree what will be checked afterwards, rather than treating a completed progress indicator as sufficient evidence of success.

Acquisition setup shown

How should this source be acquired without confusing it with the destination?

Start with

  • A source device or image and an appropriate destination selected in the acquisition interface.

What you can take away

  • The illustrated inventory and acquisition setup; no completed acquisition is claimed from this screen.
Supplied screenshot of the Acorn Forensic Imager with its disk inventory populated. No acquisition outcome is inferred from this setup screen. View full screen
Supplied screenshot of the Acorn Forensic Imager with its disk inventory populated. No acquisition outcome is inferred from this setup screen.

Open the screenshot and choose “View actual size” to read the records at their original resolution.

A practical starting point

How the workflow fits together.

  1. Identify the correct source and destination, and record the protection method. Check the available space and the intended acquisition scope.

  2. Review the options for the chosen route against the source and expected output. Use representative test media before adopting that route for case work.

  3. For a completed test, retain the acquisition record and independently check the intended output. Record errors and unreadable areas instead of assuming completion means complete coverage.

Evaluate the workflow

Questions worth bringing to a demonstration.

  • Which acquisition route has been tested for my source and intended output, in the build and edition being evaluated?
  • What records and verification values are available after that route completes, and how are read errors or incomplete coverage shown?
  • Can the result be checked independently without changing the preserved source?

Start with your requirements

Bring a sample question.

Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.

Planned for Q1 2027

Be first to hear. Save 10% at launch.

Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.

Notify me at launch ↗

Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.

About the screenshots and illustrations

Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.

Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.

Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.

Zoom in, then scroll to inspect the detail.

Open full-resolution image ↗

A useful first conversation

Let’s look at your workflow.

Tell us what you examine, where you work and what you need to deliver.

Use the enquiry form to outline your role, intended use and potential order quantity. Do not send case material through a general enquiry.

Your enquiry goes to the SQFR team. Please do not include passwords or case evidence.