COMING SOON · Q1 2027 Planned releaseGet notified + 10% launch offer ↗
← Acorn overview

Acorn application guide

USN Journal Viewer

Follow changes through the file reference when a name alone is no longer enough. USN records can help connect temporary names, renames and deletions, but a useful sequence still needs the associated file context and a clear account of what the journal covers.

Demonstrated on public training data

Do journal records connect a temporary filename, a rename or a deletion to the same file reference?

Start with

  • NTFS USN journal records from a public training source.

What you can take away

  • Parsed change records retaining names, file references and recorded timestamps.
Three adjacent Lone Wolf journal records link ~WRD1133.tmp and The Cloudy Manifesto.docx through file reference 135991 at the same recorded time. The original and new names can help reconstruct a save sequence. The journal alone does not establish document contents, authorship or the identity of the person using the computer. View full screen
Three adjacent Lone Wolf journal records link ~WRD1133.tmp and The Cloudy Manifesto.docx through file reference 135991 at the same recorded time. The original and new names can help reconstruct a save sequence. The journal alone does not establish document contents, authorship or the identity of the person using the computer.

Open the screenshot and choose “View actual size” to read the records at their original resolution.

A practical starting point

How the workflow fits together.

  1. Locate the relevant names or file references and retain the source journal context.

  2. Compare adjacent changes, recorded times and references to test whether they describe the same file. Avoid joining unrelated records simply because their names resemble one another.

  3. Compare the proposed sequence with the available file records and document evidence. Treat missing journal entries as a coverage question, not automatic proof that an action did not occur.

Evaluate the workflow

Questions worth bringing to a demonstration.

  • Can the demonstration connect the relevant changes by file reference as well as by name?
  • What part of the proposed sequence is supported by these journal records, and what needs another source?
  • Can a second examination of the same journal reproduce the selected records and their order?

Start with your requirements

Bring a sample question.

Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.

Planned for Q1 2027

Be first to hear. Save 10% at launch.

Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.

Notify me at launch ↗

Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.

About the screenshots and illustrations

Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.

Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.

Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.

Zoom in, then scroll to inspect the detail.

Open full-resolution image ↗

A useful first conversation

Let’s look at your workflow.

Tell us what you examine, where you work and what you need to deliver.

Use the enquiry form to outline your role, intended use and potential order quantity. Do not send case material through a general enquiry.

Your enquiry goes to the SQFR team. Please do not include passwords or case evidence.