COMING SOON · LATE Q4 2026Join the launch list + 10% launch offerJoin the launch list + 10% launch offer ↗Planned offer. Terms to be confirmed.

The Acorn capability guide

Digital forensics capabilities you can check.

Start with your evidence, the question you need to answer and the output you need to review. This page connects the current examples to the detailed Technical Guide. It also sets out the gaps.

Available to evaluate

Current capabilities

The reviewed examples cover source inspection, selected recovery tasks, case review and focused artefact analysis. They are evidence of those examples, not a certificate for every input.

Protection and acquisition

Device Manager shows device and protection state. The Imager brings source, destination and verification choices together. Check a completed test for the route you intend to use.

Device Manager guide ↗

Recovery and review

Recorded examples include recovering PDFs after a quick format, locating a missing FAT16 partition and reviewing files in their case context.

Review recovery results ↗

Focused examination

Browse file records, browser activity, event logs and timelines. Keep the original record close while you test what it means.

Browse the applications ↗

Match the input to the route

Supported evidence and artefact types

Access to a file system, successful acquisition and interpretation of its records are separate checks.

File systems and image containers

The recorded tests include selected NTFS, FAT16, FAT32, exFAT, ext4, XFS, Btrfs, APFS and HFS+ inputs. Their scope varies. RAW, E01 and several virtual-disk containers have example-tested reading routes. Encryption and damaged sources need their own assessment.

Activity and file records

Examples cover browser histories, Windows events, MFT and USN records, Registry data, shortcuts and other supported artefacts. The Technical Guide records the status and limits for each family.

Check the full support matrix

Follow the work

Applications and workflows

Approximately 49 application guides describe focused tasks. The nine core apps are a useful starting point.

  1. Protect and collect

    Confirm the source, permission and protection method. Choose where the copy and its logs will be stored.

  2. Recover and process

    Use a supported route to recover files or read the records relevant to your question.

  3. Review and validate

    Inspect the content, check source references and compare a known result where possible.

  4. Report

    Record the method, findings and limits. Right-click actions place applicable reports beside the selected item.

Explore all application guides ↗

Before you rely on a result

Known limitations

The exact build, source and settings matter. A successful example should not be extended to a different input without checking it.

  • Software read-only controls are not a substitute for every hardware write-blocking requirement.
  • A setup screen or visible menu shows an available control, not that the operation completed.
  • Reading an image does not establish decryption, complete recovery or support for every file it contains.
  • Recognising an artefact in Artefact Lens does not mean it has been parsed or included in a report.
  • Exports and reports vary by app. Confirm the fields, time basis and output format you need.

Planned, not current

Capabilities in development

The following work is recorded as under development in the reviewed material. Scope and delivery dates may change.

Comprehensive native iOS parsing · Planned

The reference interface is not a demonstrated handset extraction or comprehensive parsing result. Confirm the supported device and data route before instructing work.

Additional direct cloud connectors · Planned

Provider-export import and direct provider collection are different routes. Additional connectors need provider-specific testing and authorisation.

Other unverified formats and reconstruction tasks are listed as gaps in the Technical Guide. They are not automatically promised roadmap items.

Read the detail

Technical results and supporting papers

Use the published test summaries and application examples to check a claim. Ask us for any supporting white paper relevant to your proposed use; a request is not a claim that a release-wide validation paper is already published.

Zoom in, then scroll to inspect the detail.

Open full-resolution image ↗

A useful first conversation

Let’s look at your workflow.

Tell us what you examine, where you work and what you need to deliver.

Use the enquiry form to outline your role, intended use and potential order quantity. Do not send case material through a general enquiry.

Your enquiry goes to the SQFR team. Please do not include passwords or case evidence.