Acorn application guide
MFT Viewer
Use the NTFS file record to investigate a specific file, rather than reading a timestamp difference as a conclusion. The MFT view helps compare stored information; copying, application behaviour and other artefacts may explain a pattern that initially looks unusual.
Demonstrated on public training data
What do the NTFS file record and its timestamp sets actually say about this file?
Start with
- NTFS Master File Table records from a public training corpus.
What you can take away
- Parsed NTFS file-record and timestamp views.
View full screenOpen the screenshot and choose “View actual size” to read the records at their original resolution.
A practical starting point
How the workflow fits together.
Locate the relevant file record and retain enough source context to find it again. Check that similar names are not being treated as the same file.
Compare the displayed timestamp sets and stream information. Keep stored values, any display conversion and the source collection's history distinct.
Test the proposed sequence against journal, shortcut or other available records. If the interpretation matters to the finding, check the relevant record using a suitable independent method.
Evaluate the workflow
Questions worth bringing to a demonstration.
- Can I identify the same file record in the supplied source and explain the timestamp fields being compared?
- Does the demonstration distinguish the source's stored values from any conversion used to display them?
- Would an ordinary copy or application action explain the pattern, and which additional record would help decide?
Useful next steps
Start with your requirements
Bring a sample question.
Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.
Planned for Q1 2027
Be first to hear. Save 10% at launch.
Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.
Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.
About the screenshots and illustrations
Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.
Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.
Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.
