Acorn application guide
Registry Analyser
Registered software and application paths can help explain the state of a Windows system. Use that state to choose follow-up questions. A registration entry is not an execution history, and the significance of a value depends on its source and context.
Demonstrated on public training data
What software or application-path registration is recorded in this Windows profile?
Start with
- Registry data from the public Lone Wolf training scenario.
What you can take away
- Registered-program and application-path review tables.
View full screenOpen the screenshot and choose “View actual size” to read the records at their original resolution.
A practical starting point
How the workflow fits together.
Identify the Registry source being examined and the profile or system context it represents.
Review relevant software registrations, available dates, versions and application paths. Retain the source context needed to locate material entries again.
Check an important entry in the underlying source with a suitable independent method. Use other artefacts when the question concerns execution, user activity or a sequence of events.
Evaluate the workflow
Questions worth bringing to a demonstration.
- Which hive and record support the displayed software or application-path entry?
- Is a displayed date explained in context, rather than being treated as the time an application ran?
- What separate artefact would help test an execution claim suggested by this registration information?
Useful next steps
Start with your requirements
Bring a sample question.
Ask us to demonstrate this workflow with suitable public or constructed material. Do not send confidential evidence in an initial enquiry.
Planned for Q1 2027
Be first to hear. Save 10% at launch.
Request Acorn launch news and details of the planned 10% offer. No deposit or purchase commitment.
Launch-update requests go to the SQFR team for review. Final offer terms and product availability are still to be confirmed.
About the screenshots and illustrations
Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.
Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.
Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.
