Skip to content

Belkasoft Live RAM Capturer Hands-on Labs

Choose the browser simulation for coached practice, or complete the Full Lab on an isolated, authorised Windows VM with controlled evidence storage.

Hands-on memory acquisition

Bound it. Capture it. Defend it.

Acquire a case-linked .mem image, verify a working copy and explain the result without overstating what live acquisition proves.

⏱ Setup: 20–30 min · Exercise: 35–50 min◆ Guided beginner✓ Evidence required

Interactive Lab

Full Lab

Isolated Windows VM · Setup: 20–30 min · Exercise: 35–50 min

Belkasoft Live RAM Capturer Full Lab

Administrator access and evidence storage required

Use an isolated, authorised environment

Acquire only a disposable system you own or are authorised to examine. Memory acquisition changes the endpoint and the image may contain sensitive credentials, communications and personal information.

Before you begin

You need: a Windows x64 training VM with 5,120 MB RAM, administrator access, a clean snapshot, verified Belkasoft files and a separate evidence volume with at least 8 GB free.

Case question

Can the acquired memory preserve short-lived process and network context for later analysis before the authorised host is contained?

Objective

You are supporting case SUSA-061 on authorised host WIN11-LAB01. A brief PowerShell window and outbound connection were reported. Acquire memory before containment, verify the image and prepare an evidence record another beginner analyst can reproduce. Do not claim the acquisition proves malicious intent.

01

Activity 1: Establish the boundary

  1. Restore the clean VM and record case authority, hostname, installed RAM, system time and time zone.
  2. Record the archive and RamCapturer64.exe provenance, version, architecture and SHA-256.
  3. Create E:\SUSA-061\memory and confirm free space exceeds installed RAM.
  4. Record why volatile memory is being collected before containment and which question it may help answer.
Milestone 1Boundary recordedSource, authority, tool and destination are attributable before elevation.

02

Activity 2: Acquire memory

  1. Run the verified x64 executable as administrator and approve the expected UAC prompt.
  2. Set the output folder to E:\SUSA-061\memory; do not enter a filename in the folder field.
  3. Compare the displayed 5,120 MB physical-memory size with the recorded source and preserve driver messages.
  4. Select Capture!, record start and finish times, and monitor the log and progress bar.
  5. Preserve the generated .mem filename, path, byte size, timestamps, messages, warnings and errors.
Milestone 2MEM image createdThe timestamped output is present on controlled storage and the acquisition record is retained.

03

Activity 3: Verify and explain

  1. Calculate SHA-256 for the acquisition copy and record the command, algorithm and value.
  2. Protect the acquisition copy, create a labelled working copy and confirm its independent SHA-256 matches.
  3. Test whether an approved analysis tool recognises the working copy; retain warnings and do not modify the original.
  4. Write observation, interpretation, confidence and limitations separately.
  5. State the next analysis step that could address the case question.
Milestone 3Evidence package reviewableAnother analyst can identify the source, verify copy integrity and understand the acquisition limits.

Full Lab evidence checklist

  • Core completion

    Required for an attributable acquisition.

0 of 6 recorded Mark each item after saving the evidence.

Troubleshooting

Symptom First check
Driver does not load Confirm administrator elevation, matching architecture and endpoint-control messages; preserve the error.
Capture button is unavailable Confirm the output folder exists, is writable and has sufficient capacity.
Output remains on the source volume Stop before capture and select the controlled evidence folder.
File size appears unexpected Compare installed RAM, displayed physical-memory size, messages, completion state and storage capacity.
Working-copy hash differs Stop analysis, protect both copies and recreate the working copy from the protected acquisition copy.

Clean up

Protect the acquisition image and notes, remove temporary working material when authorised, record final custody and restore the disposable VM snapshot.