Acorn application guide
Timeline Viewer
A chronology is useful when it explains why each row belongs in the account. Timeline Viewer supports focused review of recorded activity, while the examiner keeps timestamp kind, time basis and source context separate from the final interpretation.
Demonstrated on public training data
Are these multiple events, or different timestamp representations of one underlying event?
Start with
- A public training timeline containing Windows security-log events.
What you can take away
- Filtered timeline rows with source event details, including account and SID where present.
View full screenOpen the screenshot and choose “View actual size” to read the records at their original resolution.
A practical starting point
How the workflow fits together.
Define the period and question before filtering the timeline. Record the time basis used for the comparison and any uncertainty in the source clock.
Inspect the selected rows and their underlying event details. Distinguish alternate timestamp representations from separate proven actions.
Correlate important points with other sources, and explain gaps or conflicting times. Keep the resulting narrative separate from the raw chronology.
Evaluate the workflow
Questions worth bringing to a demonstration.
- Can I see which timestamp kind and source record support each selected timeline row?
- How will different time bases or an unknown source time zone be handled in my examination?
- Can another examiner reproduce the filtered sequence without inheriting my interpretation of it?
Useful next steps
Start with your requirements
Bring a sample question.
Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.
Planned for Q1 2027
Be first to hear. Save 10% at launch.
Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.
Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.
About the screenshots and illustrations
Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.
Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.
Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.
