Capture memory with Magnet RAM Capture¶
Choose a controlled destination, confirm capacity and acquire the changing physical memory of an authorised Windows endpoint.
Live acquisition changes the source
A memory image is not an atomic snapshot. The acquisition utility, driver, storage activity and system workload change memory while it is read. Record timing and errors, and avoid unnecessary endpoint interaction.
Prepare the destination¶
Create the approved evidence directory before opening the tool. The preserved
SUSA workflow uses C:\Labs\memory; in casework, prefer a separate controlled
evidence volume when available. Confirm free space exceeds installed RAM plus
operational headroom.
Open Magnet RAM Capture as administrator. Keep Segment size set to
Don't Split unless the destination filesystem or transfer process imposes
a file-size limit. Select Browse, navigate to the destination, enter
memory, keep Raw/Bin File (*.raw), and select Save.
Start and monitor acquisition¶
Confirm the displayed output path and reported memory size before selecting Start. Record the acquisition start time and preserve warnings or errors.
The preserved screenshot reports 5,120 MB of system memory to be captured. Compare the displayed value with the host's installed RAM. Investigate material differences instead of treating file size alone as proof of completeness.
Record completion¶
When the success dialogue appears, record the finish time, completion message and exact output path before selecting OK and closing the utility.
Record observations as they occur
A success message reports the utility's completion state. It does not replace file verification, hashing or documentation of acquisition impact.


