Skip to content

Capture memory with Magnet RAM Capture

Choose a controlled destination, confirm capacity and acquire the changing physical memory of an authorised Windows endpoint.

Live acquisition changes the source

A memory image is not an atomic snapshot. The acquisition utility, driver, storage activity and system workload change memory while it is read. Record timing and errors, and avoid unnecessary endpoint interaction.

Prepare the destination

Create the approved evidence directory before opening the tool. The preserved SUSA workflow uses C:\Labs\memory; in casework, prefer a separate controlled evidence volume when available. Confirm free space exceeds installed RAM plus operational headroom.

Open Magnet RAM Capture as administrator. Keep Segment size set to Don't Split unless the destination filesystem or transfer process imposes a file-size limit. Select Browse, navigate to the destination, enter memory, keep Raw/Bin File (*.raw), and select Save.

Screenshot: Save As configured for C Labs memory and memory.raw

Start and monitor acquisition

Confirm the displayed output path and reported memory size before selecting Start. Record the acquisition start time and preserve warnings or errors.

Screenshot: Magnet RAM Capture ready to save memory.raw

The preserved screenshot reports 5,120 MB of system memory to be captured. Compare the displayed value with the host's installed RAM. Investigate material differences instead of treating file size alone as proof of completeness.

Record completion

When the success dialogue appears, record the finish time, completion message and exact output path before selecting OK and closing the utility.

Screenshot: Successful Magnet RAM Capture completion dialogue

Record observations as they occur

A success message reports the utility's completion state. It does not replace file verification, hashing or documentation of acquisition impact.