Acorn application guide
Unified Log Analyser
Account investigations benefit from connecting related audit events. The demonstrated workflow compares sign-ins, forwarding and downloads without treating a rule match as proof of compromise.
Demonstrated on constructed training data
Do sign-in, inbox-rule or download records support the incident account being proposed?
Start with
- Constructed Microsoft 365-style audit events using reserved accounts and documentation-range IP addresses.
What you can take away
- Native audit-review rows and rule findings.
View full screenOpen the screenshot and choose “View actual size” to read the records at their original resolution.
A practical starting point
How the workflow fits together.
Load the audit material and define the account or activity under review.
Compare sign-in, forwarding-rule and download records with their source context.
Test automated leads against authorised activity and any further records available.
Useful next steps
Start with your requirements
Bring a sample question.
Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.
Planned for Q1 2027
Be first to hear. Save 10% at launch.
Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.
Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.
About the screenshots and illustrations
Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.
Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.
Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.
