Acorn application guide
USN Journal Viewer
Follow changes through the file reference when a name alone is no longer enough. USN records can help connect temporary names, renames and deletions, but a useful sequence still needs the associated file context and a clear account of what the journal covers.
Demonstrated on public training data
Do journal records connect a temporary filename, a rename or a deletion to the same file reference?
Start with
- NTFS USN journal records from a public training source.
What you can take away
- Parsed change records retaining names, file references and recorded timestamps.
View full screenOpen the screenshot and choose “View actual size” to read the records at their original resolution.
A practical starting point
How the workflow fits together.
Locate the relevant names or file references and retain the source journal context.
Compare adjacent changes, recorded times and references to test whether they describe the same file. Avoid joining unrelated records simply because their names resemble one another.
Compare the proposed sequence with the available file records and document evidence. Treat missing journal entries as a coverage question, not automatic proof that an action did not occur.
Evaluate the workflow
Questions worth bringing to a demonstration.
- Can the demonstration connect the relevant changes by file reference as well as by name?
- What part of the proposed sequence is supported by these journal records, and what needs another source?
- Can a second examination of the same journal reproduce the selected records and their order?
Useful next steps
Start with your requirements
Bring a sample question.
Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.
Planned for Q1 2027
Be first to hear. Save 10% at launch.
Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.
Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.
About the screenshots and illustrations
Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.
Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.
Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.
