Integrated Forensic & Incident Response Tools
The Acorn includes more than 30 integrated open-source technologies supporting evidence acquisition, disk analysis, data recovery, Windows investigations, memory forensics, network analysis and incident response activities. These tools operate within a portable Linux-based forensic environment designed for investigators, cybersecurity teams, consultants, educators and students.
The Acorn is not simply a Linux workstation with forensic software installed. Integrated tools are organised into structured investigation workflows and supported by evidence protection controls designed to help maintain evidential integrity throughout the examination process.
Whether supporting traditional digital forensic investigations, incident response activities, cybersecurity operations or academic training, The Acorn provides access to recognised open-source technologies within a consistent investigative platform.
Explore The Acorn's Integrated Tools
The tools listed below support evidence acquisition, forensic analysis, data recovery, memory investigations, network analysis and incident response activities. Explore examples of some of the forensic outputs and evidence protection controls available throughout The Acorn platform.
Autopsy
Full suite digital forensic investigation platform.
Chainsaw
Windows event log analysis and threat hunting.
DB Browser for SQLite
SQLite database examination and analysis.
dc3dd
Forensic disk imaging and acquisition.
dcfldd
Forensic disk imaging with hashing and verification.
dd
Classic Unix disk imaging and data copying utility
Disks
Disk, partition and storage management utility.
Disk Usage Analyser
Storage usage analysis and visualisation.
EWF Tools
Evidence container creation and management.
ExifTool
Metadata extraction and analysis.
GTKHash
Hash verification and integrity validation.
Guymager
Forensic disk imaging and acquisition.
Hayabusa
Windows event log analysis and timeline generation.
John the Ripper
Password auditing and credential recovery.
Log2Timeline
Forensic timeline generation and event correlation.
NetworkMiner
Network forensic analysis and session reconstruction.
Nmap
Network discovery and security auditing.
OpenSuperClone
Advanced disk imaging and damaged drive recovery.
PhotoRec
File recovery and data carving utility.
Pinta
Image editing and annotation utility.
RegRipper
Windows Registry artefact extraction and analysis.
Remmina
Remote desktop and remote access client.
Scalpel
File carving and data recovery utility.
Sleuthy's Write-Blocker
Integrated write-blocking and evidence protection utility.
TestDisk
Partition recovery and file system repair utility..
Velociraptor
Endpoint visibility and digital forensic investigation platform.
VeraCrypt
Disk encryption and secure container management.
VLC
Media playback and evidence review utility.
Volatility 2 & 3
Advanced memory forensics and memory analysis framework.
Wireshark
Network protocol analysis and packet inspection.
YARA
Malware identification and pattern matching.
YARP
Windows Registry parsing and analysis.
Zenmap
Graphical interface for Nmap network scanning.
Explore The Acorn Platform
The technologies featured on this page are delivered as part of The Acorn forensic workstation. Systems are supplied with 16GB RAM and 500GB storage as standard, with enhanced hardware configurations available upon request for organisations requiring additional performance or storage capacity.