COMING SOON · Q1 2027 Planned releaseGet notified + 10% launch offer ↗
Illustrative Acorn workspace for dfir teams

For incident responders and cyber investigators

An altered bank detail.
What happened in the account?

Bring event logs, host artefacts and exported account records into a focused investigation. Inspect the activity behind an alert and establish which evidence can explain the incident.

Explore the workflow

Planned release Q1 2027 · Explore the workflow and check build support.

Event Log Viewer examining encoded PowerShell in public DeepBlueCLI training logs. Rule matches and decoded text are review leads, not proof that the commands completed. View full screen
Event Log Viewer examining encoded PowerShell in public DeepBlueCLI training logs. Rule matches and decoded text are review leads, not proof that the commands completed.
DFIR teams Sleuthy sector illustration

DFIR teams

An alert starts the question

An unexpected forwarding rule or a changed invoice may be the first sign of an account incident. The evidence can be spread across mailbox exports, sign-in records, a user's computer and messages held by another party.

Preserve the required sources, then start the review with a defined question. Acorn's focused applications provide routes into supported audit and host records; Workbench can hold a wider case review as the question develops. Follow the record behind an alert and collect or examine more material when a specific gap calls for it.

Start with a focused review

Choose the account, host and period relevant to the incident. Set out which records are available and what they could answer, while keeping the wider preservation requirement in view.

Deepen the examination where it matters

Use a suspicious rule change, command or timestamp as a reason to inspect its source and surrounding activity. Expand the review when that comparison raises another question, not merely because another tool is available.

Scope access and possible exposure

Separate account access, message changes, downloads and network activity. Each can help establish the incident's extent, but they answer different questions.

EXAMPLE WORKFLOW

Email fraud: tracing a suspicious forwarding rule

Example incident: a supplier reports that an invoice contains different bank details. The response team has an exported audit log and an authorised collection from the account holder's laptop.

  1. Preserve the messages and available logs

    Retain the relevant messages and available source exports. Record the collection period and timezone. Define the first question, then select the account and endpoint records needed to investigate that window.

  2. Follow the account activity

    Review sign-ins, inbox-rule changes and related events. Compare the sequence with the laptop evidence and messages, keeping the selected source records behind each finding.

  3. Explain the scope and outstanding questions

    Explain the access and changes supported by the records, then identify the next collection or deeper examination. Missing message traces, provider records or recipient evidence may matter when assessing forwarding, exposure or altered payment details.

Illustrative incident, not a customer breach. The audit screenshot uses constructed events, while the PowerShell example uses public training logs. Neither represents this fictional account.

Unified Log Analyser reviewing 31 constructed AuditData records, including sign-in failures, downloads and a rule change. These genuine rule outputs are not independent proof of compromise or exfiltration. View full screen
Unified Log Analyser reviewing 31 constructed AuditData records, including sign-in failures, downloads and a rule change. These genuine rule outputs are not independent proof of compromise or exfiltration.

A useful evaluation

Bring the requirements that matter.

  • Incident question and preservation scope
  • Available records, time period and timezone
  • Criteria for further collection or deeper review
  • Source-linked technical and incident-management outputs
Explore the focused applications ↗
How do we move from triage into a deeper examination?

Begin with a defined incident question and review the relevant records. Record what was not covered, then widen the sources or processing when a finding, gap or competing explanation makes it necessary. A triage result is not a statement that the whole incident has been examined.

Can a download or forwarding entry establish data loss?

It may support part of the sequence. Check the event's meaning and corroborate the result with available provider, recipient or network evidence before concluding what left the environment.

Can the account examples be reviewed offline?

Yes, the shown exercise analyses constructed exports locally. Live collection and optional enrichment are separate tasks with their own access and connectivity requirements.

What is the best starting point for a demonstration?

Choose an incident question, representative test exports and an expected result. Walk through collection assumptions, focused review and the point at which you would go deeper. Record actual handling effort; no general speed benchmark is implied.

The planned 2027 bundle

Take the workspace with you.

The proposed portable bundle pairs Acorn with a workstation, USB-C-powered screen, mini keyboard, mouse and carry bag.

Working specification: 24 GB RAM, AMD Ryzen 9 or Intel Core i9, and a 1 TB PCIe SSD. Final components and compatibility are still being selected.

Explore the planned bundle ↗

COMING SOON · Q1 2027

Target RRP under £3,000 GBP

Provisional specification and price target. Final VAT treatment, delivery, licence terms and availability will be confirmed before orders open.

Notify me + 10% launch offer ↗

No deposit or pre-order is taken here.

Start with your requirements

Walk through an account incident with us

Bring an incident question and your usual evidence sources. We can show a focused starting point and the decisions that would lead to deeper work.

About the screenshots and illustrations

Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.

Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.

Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.

Zoom in, then scroll to inspect the detail.

Open full-resolution image ↗

A useful first conversation

Let’s look at your workflow.

Tell us what you examine, where you work and what you need to deliver.

Use the enquiry form to outline your role, intended use and potential order quantity. Do not send case material through a general enquiry.

Your enquiry goes to the SQFR team. Please do not include passwords or case evidence.