Acorn application guide
Event Log Viewer
An event match is a place to start reading. Event Log Viewer keeps the underlying record and decoded command context close to the review, so an examiner can separate what was recorded from a proposed action, duplicated rule match or inferred outcome.
Demonstrated on public training data
Which Windows events support a concern, and what does a decoded command actually contain?
Start with
- Windows event records, including PowerShell-related records from public test logs.
What you can take away
- Native event-detail and decoded-command views with rule matches.
View full screenOpen the screenshot and choose “View actual size” to read the records at their original resolution.
A practical starting point
How the workflow fits together.
Choose the event source and the period or behaviour being investigated. Retain the source file and the identifiers needed to revisit the selected records.
Inspect the matched events and any decoded command text. Distinguish several matches on one event from several separate actions.
Check the interpretation against related logs or other evidence, and independently inspect a material record where appropriate. State what the available logging does and does not establish.
Evaluate the workflow
Questions worth bringing to a demonstration.
- Can I revisit the selected event in its source rather than relying only on the rule-match label?
- How are duplicate matches, recorded times and decoded command text distinguished during review?
- Which further record would support or contradict the proposed execution or incident sequence?
Useful next steps
Start with your requirements
Bring a sample question.
Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.
Planned for Q1 2027
Be first to hear. Save 10% at launch.
Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.
Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.
About the screenshots and illustrations
Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.
Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.
Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.
