Acorn application guide
SRUM Viewer
Application-level network counters can help decide where to investigate next. SRUM Viewer makes those recorded usage rows available for review, but identifying transferred files or explaining a transfer needs evidence beyond a byte count.
Demonstrated on public training data
What network usage does Windows attribute to an application during the recorded period?
Start with
- SRUM network-usage records; the demonstrated import uses public Plaso data with normalised date fields.
What you can take away
- Application-level network-usage rows and byte counters.
View full screenOpen the screenshot and choose “View actual size” to read the records at their original resolution.
A practical starting point
How the workflow fits together.
Identify the source records and review any date-field normalisation used for import. Preserve uncertainty about the original clock or time zone.
Compare the relevant application rows and sent or received byte counters within the available period.
Use a significant pattern to select further file, account or network checks. Record the distinction between the observed counter and any proposed explanation.
Evaluate the workflow
Questions worth bringing to a demonstration.
- Can the original date values and any import normalisation be explained for the records being reviewed?
- What application, interval and counter does the selected row actually describe?
- Which other source would be needed to test whether particular files left the system?
Useful next steps
Start with your requirements
Bring a sample question.
Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.
Planned for Q1 2027
Be first to hear. Save 10% at launch.
Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.
Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.
About the screenshots and illustrations
Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.
Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.
Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.
