COMING SOON · Q1 2027 Planned releaseGet notified + 10% launch offer ↗
← Acorn overview

Acorn application guide

Device Manager

Identify the evidence device before choosing an examination action. Device Manager makes the reported device, partition, mount and protection state available for inspection. That gives the examiner useful context, while the chosen protection method still needs its own validation.

Native device-state inspection

Which connected device is the evidence source, and what protection state does the system report?

Start with

  • Connected-device and partition information displayed by the operating system.

What you can take away

  • Device, partition, mount and protection-state information for examiner review.
The selected USB is shown as read-only, with its kernel protection, partitions and mount information. This capture is a state inspection, not a write-block validation test. View full screen
The selected USB is shown as read-only, with its kernel protection, partitions and mount information. This capture is a state inspection, not a write-block validation test.

Open the screenshot and choose “View actual size” to read the records at their original resolution.

A practical starting point

How the workflow fits together.

  1. Match the intended source to the displayed device and partition details. Keep the evidence source separate from storage used for working outputs.

  2. Inspect the reported read-only and mount states before selecting an access route. Record the observation and the protection method being relied upon.

  3. Where protection is material to the task, check it using an appropriate controlled method and test media. Recheck the reported state after any deliberate change to the connection or workflow.

Evaluate the workflow

Questions worth bringing to a demonstration.

  • Can I identify the intended source unambiguously from the displayed device and partition information?
  • What is an observed operating-system state, and what has actually been tested about the protection method?
  • For my intended hardware and access route, which controlled checks should be completed before handling evidence?

Start with your requirements

Bring a sample question.

Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.

Planned for Q1 2027

Be first to hear. Save 10% at launch.

Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.

Notify me at launch ↗

Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.

About the screenshots and illustrations

Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.

Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.

Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.

Zoom in, then scroll to inspect the detail.

Open full-resolution image ↗

A useful first conversation

Let’s look at your workflow.

Tell us what you examine, where you work and what you need to deliver.

Use the enquiry form to outline your role, intended use and potential order quantity. Do not send case material through a general enquiry.

Your enquiry goes to the SQFR team. Please do not include passwords or case evidence.