Start with a focused review
Choose the account, host and period relevant to the incident. Set out which records are available and what they could answer, while keeping the wider preservation requirement in view.
SQUIRRELFORENSICSDesigned in the UK
For incident responders and cyber investigators
Bring event logs, host artefacts and exported account records into a focused investigation. Inspect the activity behind an alert and establish which evidence can explain the incident.
Planned release Q1 2027 · Explore the workflow and check build support.
View full screen
DFIR teams
An unexpected forwarding rule or a changed invoice may be the first sign of an account incident. The evidence can be spread across mailbox exports, sign-in records, a user's computer and messages held by another party.
Preserve the required sources, then start the review with a defined question. Acorn's focused applications provide routes into supported audit and host records; Workbench can hold a wider case review as the question develops. Follow the record behind an alert and collect or examine more material when a specific gap calls for it.
Choose the account, host and period relevant to the incident. Set out which records are available and what they could answer, while keeping the wider preservation requirement in view.
Use a suspicious rule change, command or timestamp as a reason to inspect its source and surrounding activity. Expand the review when that comparison raises another question, not merely because another tool is available.
Separate account access, message changes, downloads and network activity. Each can help establish the incident's extent, but they answer different questions.
EXAMPLE WORKFLOW
Example incident: a supplier reports that an invoice contains different bank details. The response team has an exported audit log and an authorised collection from the account holder's laptop.
Retain the relevant messages and available source exports. Record the collection period and timezone. Define the first question, then select the account and endpoint records needed to investigate that window.
Review sign-ins, inbox-rule changes and related events. Compare the sequence with the laptop evidence and messages, keeping the selected source records behind each finding.
Explain the access and changes supported by the records, then identify the next collection or deeper examination. Missing message traces, provider records or recipient evidence may matter when assessing forwarding, exposure or altered payment details.
Illustrative incident, not a customer breach. The audit screenshot uses constructed events, while the PowerShell example uses public training logs. Neither represents this fictional account.
View full screenA useful evaluation
Begin with a defined incident question and review the relevant records. Record what was not covered, then widen the sources or processing when a finding, gap or competing explanation makes it necessary. A triage result is not a statement that the whole incident has been examined.
It may support part of the sequence. Check the event's meaning and corroborate the result with available provider, recipient or network evidence before concluding what left the environment.
Yes, the shown exercise analyses constructed exports locally. Live collection and optional enrichment are separate tasks with their own access and connectivity requirements.
Choose an incident question, representative test exports and an expected result. Walk through collection assumptions, focused review and the point at which you would go deeper. Record actual handling effort; no general speed benchmark is implied.
The planned 2027 bundle
The proposed portable bundle pairs Acorn with a workstation, USB-C-powered screen, mini keyboard, mouse and carry bag.
Working specification: 24 GB RAM, AMD Ryzen 9 or Intel Core i9, and a 1 TB PCIe SSD. Final components and compatibility are still being selected.
Explore the planned bundle ↗COMING SOON · Q1 2027
Provisional specification and price target. Final VAT treatment, delivery, licence terms and availability will be confirmed before orders open.
Notify me + 10% launch offer ↗No deposit or pre-order is taken here.
Start with your requirements
Bring an incident question and your usual evidence sources. We can show a focused starting point and the decisions that would lead to deeper work.
Application screens are selected from the September 2026 Acorn screenshot pack. Captions distinguish native setup views, constructed training records and public-corpus results. They are not private client cases, and a displayed control does not establish that every operation was completed.
Relevant public sources include DeepBlueCLI training event logs and Plaso test data. Check the relevant source terms before redistributing an underlying dataset.
Workspace scenes and sector mascot variants are generated illustrations. They do not show actual police, judicial, military or university deployments or endorsements. The original Squirrel Forensics identity is retained.