Acorn application guide
Shortcut Viewer
A shortcut can retain a target path, arguments and details of a volume or authoring system. Use those fields to guide a focused examination, while keeping the shortcut's own history separate from the target information stored inside it.
Demonstrated on public training data
What target, arguments and device information are stored inside this shortcut?
Start with
- Windows shortcut files from a public test collection.
What you can take away
- Parsed shortcut targets, arguments and available embedded device and timestamp information.
View full screenOpen the screenshot and choose “View actual size” to read the records at their original resolution.
A practical starting point
How the workflow fits together.
Select the relevant shortcut and inspect its stored target, arguments and available device details.
Separate the shortcut file's current timestamps from the embedded target timestamps. Consider the effect of the collection or test-data copy on the former.
Compare a significant path or volume lead with other available file and activity records. Check material fields independently before relying on them in a finding.
Evaluate the workflow
Questions worth bringing to a demonstration.
- Does the review clearly separate the shortcut's own timestamps from embedded target timestamps?
- Which stored fields link the shortcut to the target or volume being discussed?
- What additional evidence would be needed to move from a recorded target to a claim of execution or user activity?
Useful next steps
Start with your requirements
Bring a sample question.
Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.
Planned for Q1 2027
Be first to hear. Save 10% at launch.
Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.
Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.
About the screenshots and illustrations
Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.
Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.
Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.
