# Squirrel Forensics: The Acorn Forensic OS > SQFR develops The Acorn, a UK-designed Linux forensic operating system and proposed portable workstation. Its public guides cover evidence acquisition, recovery, case review, focused forensic applications and reporting for laboratory, office, field and teaching workflows. This guide covers The Acorn product website at https://sqfr.uk/. Compute Forensics is the separate website for Alistair Ewing's independent forensic and expert witness services. The workstation is a proposed product, with launch currently targeted for late Q4 2026. Hardware, availability, price, VAT, delivery and licence terms are to be confirmed before orders open. The site takes demonstration and launch-interest enquiries, not workstation deposits or pre-orders. Consult the workstation and launch pages for the current position. Local evidence analysis runs on the workstation. Remote sessions and cloud collection need network access. Updates, online lookups and some maps may also need a connection. The application catalogue contains guides, not a claim that every listed function has been validated for every input. Distinguish demonstrated workflows, public or constructed training examples, configuration screens and development work. Source protection, file-system support, parser coverage and report outputs must be checked for the actual build and task. A software read-only control is not a claim of certified hardware write blocking. Third-party Linux tools have their own licences; their inclusion does not make The Acorn software free. The links below are public HTML guides with screenshots and stated limits. Enquiries should describe requirements, not contain case evidence, credentials or personal data from an investigation. This guide supplements the site; it does not set crawler permissions or promise search-engine rankings. ## Start here - [The Acorn overview](https://sqfr.uk/): The operating system, portable-workstation concept, core applications and reporting examples. - [Application catalogue and Acorn Home](https://sqfr.uk/acorn-forensic-applications/): Browse all application guides, with nine core starting points and desktop screenshots. - [Current forensic capabilities](https://sqfr.uk/the-acorn-digital-forensics-capabilities/): Capabilities, workflow options and limits to review when planning an evaluation. - [Artefact and file-system support guide](https://sqfr.uk/digital-forensic-artefacts-file-system-support/): Evidence inputs, file systems, artefacts, outputs and development status. ## Core acquisition and recovery applications - [Device Manager](https://sqfr.uk/apps/read-only-evidence-management-acorn-device-manager/): Inspect devices, partitions and reported source-protection state before choosing an action. - [Forensic Imager](https://sqfr.uk/apps/forensic-disk-imaging-acorn-imager/): Review acquisition controls, source selection, destination and verification planning. - [File Recovery Carver](https://sqfr.uk/apps/deleted-file-carving-acorn-recovery-carver/): Recover file structures when directory entries are missing; examples and limits are stated in the guide. - [Partition Recovery](https://sqfr.uk/apps/deleted-partition-recovery-acorn-partition-recovery/): Locate a missing partition and inspect selected recovered files in a documented training exercise. ## Core examination and reporting applications - [Forensic Workbench](https://sqfr.uk/apps/digital-evidence-case-review-acorn-workbench/): Review files, previews and source records together in case context. - [Forensic Navigator](https://sqfr.uk/apps/evidence-file-review-acorn-forensic-navigator/): Browse an evidence workspace and inspect individual files and examiner outputs. - [Browsing History](https://sqfr.uk/apps/browser-history-forensics-acorn-browsing-history/): Review recorded visits, searches and downloads with their times and source details. - [Event Log Viewer](https://sqfr.uk/apps/windows-event-log-analysis-acorn-event-log-viewer/): Examine Windows events and rule matches while keeping observations separate from conclusions. - [Timeline Viewer](https://sqfr.uk/apps/forensic-timeline-review-acorn-timeline-viewer/): Compare recorded activity in date order, retaining time basis and source context. - [Case Notes and reporting](https://sqfr.uk/apps/examiner-notes-reporting-acorn-case-notes/): Examiner notes, source references and report examples for reviewable work. ## Other focused evidence questions - [NTFS MFT Viewer](https://sqfr.uk/apps/ntfs-mft-file-record-analysis-acorn-mft-viewer/): Compare Windows file records and timestamp sets; a timestamp difference alone is not proof of manipulation. - [NTFS USN Journal Viewer](https://sqfr.uk/apps/ntfs-usn-journal-analysis-acorn-usn-viewer/): Follow recorded file changes, including rename and deletion events, with their limitations. - [Microsoft 365 audit analysis](https://sqfr.uk/apps/microsoft-365-audit-analysis-acorn-unified-log-analyser/): Review supported audit-log exports and account activity in the context of the available records. - [Offline packet-capture analysis](https://sqfr.uk/apps/offline-pcap-analysis-acorn-pcap-analyser/): Inspect recorded network traffic; consult the guide for input and interpretation limits. ## Sectors and evaluation scenarios - [Law enforcement](https://sqfr.uk/law-enforcement-digital-forensics-software/): Authorised acquisition, evidence review and examiner handover scenarios. - [Digital forensic companies](https://sqfr.uk/digital-forensic-company-software/): Laboratory workflows, focused examination and use alongside specialist tools. - [DFIR and incident-response teams](https://sqfr.uk/dfir-incident-response-software/): Local triage and authorised access to investigation workspaces; DFIR means digital forensics and incident response. - [Defence and fieldwork](https://sqfr.uk/military-field-digital-forensics/): Authorised field investigations, deployment planning and training; not a claim of military certification. - [Education and training](https://sqfr.uk/digital-forensics-education-training/): Practical teaching with forensic methods, source records and training datasets. ## Demonstrations, workstation and release enquiries - [Portable forensic workstation](https://sqfr.uk/acorn-portable-forensic-workstation/): Proposed bundle, target specification and matters still to be confirmed before sale. - [Software and workstation FAQs](https://sqfr.uk/acorn-forensic-software-faqs/): Tools, hardware, reporting, compatibility, release plans and evaluation questions. - [Request a demonstration or discuss requirements](https://sqfr.uk/contact/): Contact SQFR about your role, workflow, intended use and potential quantity. - [Launch notification and proposed 10% offer](https://sqfr.uk/acorn-launch-notification/): Request release information and details of the planned 10% offer. Terms remain unconfirmed; there is no deposit or purchase commitment. ## Practical workflow guides Thirty separate guides answer acquisition, equipment and evidence-review questions. Each links to the relevant Acorn applications, source material where appropriate and the SQFR enquiry route. These are product and workflow guides, not individual case advice or proof of universal recovery performance. ### Difficult disks and encrypted sources - [How do you image a failing hard drive without losing sight of the evidence?](https://sqfr.uk/forensic-imaging-failing-hard-drives/): Image a failing disk with Acorn’s recovery mode. Preserve readable areas, retain the map and record unreadable sectors. - [Can an interrupted forensic acquisition resume from its bad-sector map?](https://sqfr.uk/resumable-forensic-imaging-bad-sectors/): Resume faulty-disk imaging with the matching source, image and recovery map. See the Acorn checks before another pass. - [What should you check before imaging a disk that may be failing?](https://sqfr.uk/forensic-imager-disk-health-checks/): Check disk health before imaging with Acorn. Review SMART data, read errors and adapter limits, then plan the acquisition. - [How can you recover a lost partition without changing the evidence?](https://sqfr.uk/read-only-partition-recovery-forensics/): Recover a lost partition without rewriting the source. See how Acorn finds volumes and exports files to separate storage. - [How do you examine a BitLocker drive from Linux when you have the recovery key?](https://sqfr.uk/bitlocker-forensic-imaging-linux/): Examine a BitLocker drive on Linux with a supplied key. Preserve the encrypted source and use Acorn’s read-only view. - [How do you preserve and review a LUKS-encrypted disk?](https://sqfr.uk/luks-forensic-acquisition-workstation/): Preserve a LUKS-encrypted disk and open it read-only with authorised credentials. Plan the source, access and exports in Acorn. ### Choosing a portable workstation - [What do you need for forensic imaging at a client’s premises?](https://sqfr.uk/portable-forensic-imager-on-site/): Plan on-site forensic imaging with Acorn. Check source protection, adapters, power, output storage and the handover record. - [Is a compact forensic workstation enough for your workload?](https://sqfr.uk/compact-forensic-workstation-uk/): Assess a compact UK-designed forensic workstation. Compare Acorn’s size, core specification, storage and your workload. - [Which adapters do you need to image SATA and NVMe evidence?](https://sqfr.uk/portable-forensic-workstation-sata-nvme/): Choose SATA and NVMe adapters for an Acorn forensic kit. Check protocol, power, health-data access and source protection. - [How do you build a usable imaging kit around a portable screen?](https://sqfr.uk/forensic-imaging-workstation-portable-screen/): Build an Acorn imaging kit around a portable screen. Plan display power, readable controls, desk space and output storage. - [What can a forensic field kit do without an internet connection?](https://sqfr.uk/offline-digital-forensics-field-kit/): Plan an offline forensic field kit with Acorn. Separate local acquisition and review from tasks that need network access. - [Would a second imaging workstation remove a bottleneck in your laboratory?](https://sqfr.uk/second-forensic-imaging-workstation/): Add a second Acorn imaging station where acquisition blocks review. Plan source handling, storage and examiner handover. ### Source protection and acquisition records - [How does kernel-level write blocking protect an evidence device?](https://sqfr.uk/linux-kernel-write-blocking-forensics/): See how Acorn uses kernel-level write blocking for evidence devices. Keep protected sources separate from output disks. - [What should “integrated write blocking” mean in a workstation quotation?](https://sqfr.uk/forensic-workstation-integrated-write-blocking/): Evaluate integrated write blocking in an Acorn workstation. Ask how device protection, output storage and imaging work. - [How do you avoid confusing evidence disks with writable destinations?](https://sqfr.uk/read-only-evidence-device-manager-linux/): Identify evidence disks and writable destinations in Acorn Device Manager. Check device identity, partitions and protection. - [Should you choose E01 or RAW for a forensic image?](https://sqfr.uk/e01-raw-forensic-imaging-linux/): Choose E01 or RAW for forensic imaging on Linux. Compare segments, hashes, read-error handling and the receiving workflow. - [What should accompany a forensic image besides its hash?](https://sqfr.uk/forensic-imaging-hashes-acquisition-logs/): Keep acquisition logs and source details with a forensic image. See how Acorn supports hashes, recovery maps and handover. ### Incident response and remote Windows - [What should an incident-response workstation let you do on site?](https://sqfr.uk/portable-dfir-workstation-kit/): Plan an Acorn kit for incident response. Preserve sources, review local records and prepare access to remote workspaces. - [How can DFIR teams reach cloud Windows workstations from The Acorn?](https://sqfr.uk/remmina-rdp-cloud-windows-dfir/): Use Acorn and Remmina for Windows VMs on AWS, Azure or Google Cloud. Plan secure RDP and separate evidence transfer. - [How should evidence reach a remote workstation without losing its source record?](https://sqfr.uk/forensic-evidence-sftp-workflow/): Transfer forensic working copies over SFTP. Plan access, hashes and storage while keeping the acquisition record intact. - [How can you review Microsoft 365 audit exports on a Linux workstation?](https://sqfr.uk/microsoft-365-audit-log-review-linux/): Review Microsoft 365 audit exports on Linux with Acorn. Preserve source rows, handle timestamps and explain log gaps. - [Which records help explain an email-compromise payment fraud?](https://sqfr.uk/email-compromise-forensic-workstation/): Review email-compromise fraud with Acorn. Compare messages, invoices and account logs without assuming attribution. ### Teaching, independent work and handover - [How should a university choose a digital forensics teaching workstation?](https://sqfr.uk/digital-forensics-workstation-university/): Choose Acorn around forensic teaching tasks and cohort size. Discuss repeatable exercises and bespoke university needs. - [Can you run a forensic practical without a permanently dedicated laboratory?](https://sqfr.uk/portable-forensic-lab-classroom/): Plan a portable forensic classroom with Acorn. Reuse suitable displays, protect master data and reset student workspaces. - [What should an institution include in a forensic software quotation request?](https://sqfr.uk/forensic-software-academic-quotation/): Request a bespoke Acorn academic quote. Set out teaching tasks, cohort size, equipment, storage and support requirements. - [What does an independent examiner need from a forensic workstation?](https://sqfr.uk/forensic-workstation-independent-examiner/): Assess Acorn for independent casework: protected sources, focused review and reports that another examiner can follow. - [What should travel with a forensic image collected in the field?](https://sqfr.uk/digital-forensic-field-collection-kit/): Plan an Acorn field collection kit. Hand over images, hashes, logs and source details that the receiving examiner can use. ### Recovery and focused evidence review - [Can a fragmented JPEG be recovered with its EXIF metadata?](https://sqfr.uk/fragmented-jpeg-forensic-recovery/): See an Acorn Carver test that reassembled a four-fragment JPEG and retained EXIF. Read the checks and limits of this result. - [How can you triage a suspicious PDF or Office document on Linux?](https://sqfr.uk/linux-forensic-document-triage/): Triage PDF and Office files on Linux with Acorn. Inspect static indicators and keep suspicious content distinct from execution. - [What can browser history tell you about a suspected file transfer?](https://sqfr.uk/browser-history-forensic-workstation/): Review browser history with Acorn. Compare visits, downloads and source records before drawing conclusions about a transfer. The cloud Windows guide concerns approved direct RDP endpoints reached through Remmina. Windows desktop licensing and brokered services need separate checks. SFTP file transfer is distinct from remote control. The illustrated Windows desktop is a credited Microsoft screenshot, not evidence of a tested cloud deployment. ## Optional - [About Squirrel Forensics](https://sqfr.uk/about-squirrel-forensics/): The team and background to The Acorn. - [Free Linux digital-forensics tools](https://sqfr.uk/free-linux-digital-forensics-tools/): Third-party projects illustrating how a Linux forensic workspace can be extended; check each project's licence and compatibility. - [Privacy and cookies policy](https://sqfr.uk/privacy-and-cookies-policy/): Website privacy and cookie information. - [Terms and conditions](https://sqfr.uk/terms-and-conditions/): Published website terms; final product terms must be confirmed before purchase. - [Compute Forensics services](https://compute-forensics.com/): Independent forensic examination, expert witness work and cyber investigations, separate from Acorn product enquiries. - [Sitemap index](https://sqfr.uk/sitemap_index.xml): Broader discovery of public website content.