Skip to content

Magnet RAM Capture Hands-on Labs

Choose the Interactive Lab to practise the acquisition decisions in a safe simulation, or use the Full Lab to acquire and preserve memory from an isolated Windows training VM.

Hands-on volatile-evidence proof of concept

Scope it. Capture it. Defend it.

Respond to a suspected credential-theft event, preserve the system's changing memory, validate the image and write an acquisition note another analyst can trust.

⏱ Setup: 30–45 min · Core exercise: 45–75 min◆ Guided beginner✓ Evidence required

Interactive Lab

Full Lab

Isolated Windows VM · Setup: 30–45 min · Exercise: 45–75 min

Magnet RAM Capture Full Lab

Administrator access and evidence storage required

Outcome-led, not screenshot-led

Interface labels may differ by release. Use the screenshots in the overview to orient yourself, but preserve the actual version, settings, messages and results from your acquisition.

Use an isolated, authorised environment

Acquire memory only from a system you own or are authorised to examine. The image can contain credentials, personal data and sensitive content. Restrict access, use a disposable VM and follow your evidence-handling rules.

Before you begin

You need: one isolated Windows training VM, administrator access, a clean snapshot, the authorised Magnet RAM Capture executable, and a controlled destination with free space greater than the VM's assigned RAM.

How to use this lab

Make the acquisition decisions before opening the tool. At each milestone, stop if the expected result is missing. Preserve errors rather than repeatedly running the tool without understanding the cause.

Optional extension

Compare one controlled change

Repeat from a restored snapshot with one harmless process running, then compare acquisition records and a focused process-list result.

  1. Session 1Scope and prepare
  2. Session 2Acquire and verify
  3. Session 3Assess and report

Objective

You are supporting case SUSA-047. Monitoring detected a suspicious sign-in followed by a short-lived PowerShell process on the authorised workstation WIN11-LAB01. The process has ended, but volatile evidence may still provide context. The incident lead authorises a memory acquisition before containment.

Your task is to preserve a defensible raw memory image, not to prove compromise. You must decide whether the destination is safe, document acquisition impact, verify integrity and explain whether the output is ready for analysis.

01

Activity 1: Establish the acquisition boundary

  1. Restore the clean snapshot of WIN11-LAB01. Record the VM name, Windows version, assigned RAM, system time, time zone, snapshot and case authority.
  2. State the question: Can volatile evidence be preserved now for later review of process and credential-access activity? Record what a memory image cannot establish by itself, including user intent and complete event chronology.
  3. Stage Magnet RAM Capture in C:\Tools\Magnet RAM Capture. Record the supplied filename, working filename, version, source, download date and SHA-256 hash.
  4. Attach a separate controlled evidence volume as E: and create E:\SUSA-047\memory. Record its filesystem and free space. Free space must exceed assigned RAM with sufficient operational headroom.
  5. Take a pre-memory-acquisition snapshot. Do not take another snapshot while acquisition is running.

Acquisition decision gate

Observation Decision
Destination is on E:, writable and has more free space than assigned RAM Proceed
Only the busy system volume is available Pause and document the risk; obtain an approved destination
Tool hash or source cannot be established Do not execute until provenance is resolved
Authority or source-host identity is unclear Stop and escalate the scope question
Milestone 1Boundary readyThe authority, question, host, time context, tool provenance, destination, capacity and snapshot are recorded.

Expected result Another analyst can identify exactly what will be acquired, why, with which executable, and where the output will be written.

02

Activity 2: Acquire and verify memory

  1. Open Magnet RAM Capture as administrator. Record the start time immediately before configuring the output.
  2. Keep Segment size at Don't Split because the NTFS evidence volume supports the expected file size. Browse to E:\SUSA-047\memory\WIN11-LAB01_SUSA-047.raw.
  3. Compare the application's reported memory-to-capture value with the VM's assigned RAM. If materially different, pause and record the discrepancy.
  4. Select Start. Avoid unnecessary interaction while acquisition runs. Observe progress and preserve every warning, error or cancellation message.
  5. On success, record the exact completion message, finish time and output path. Close the application only after those details are retained.
  6. Confirm the output exists and record its byte size. Calculate SHA-256 using an approved utility and save the value with the acquisition note.
  7. Create a clearly labelled working copy. Recalculate SHA-256 and confirm it matches before allowing analysis of that copy.

A useful control

Record the tool executable hash separately from the memory-image hash. They answer different integrity questions and should never be substituted.

Milestone 2Image preservedThe raw image, timing, completion state, size and hash remain attributable to WIN11-LAB01, and the verified acquisition copy is protected.

Expected result The working-copy hash matches the acquisition-copy hash and no unexplained warning, error or capacity discrepancy remains.

03

Activity 3: Assess and report

Work only from the verified working copy. Use an approved memory-analysis tool to perform a small intake validation such as identifying the Windows kernel information and listing processes. This is a quality check, not a full malware investigation.

  1. Record the analysis tool and version, working-copy path and verified hash.
  2. Determine whether the image can be parsed and whether the reported system identity broadly agrees with WIN11-LAB01.
  3. Record one process-list observation. Do not infer compromise merely because PowerShell or another dual-use process appears.
  4. Decide whether the image is ready for analysis, ready with a noted limitation, or not ready. Support the decision with acquisition and validation evidence.
  5. Write the acquisition note using this structure:
Case and authority: SUSA-047
Source host, system time and time zone:
Reason for volatile acquisition:
Tool filename, version, source and SHA-256:
Destination, filesystem and free space:
Start time, finish time and completion state:
Output filename, byte size and SHA-256:
Warnings, errors and endpoint impact:
Intake validation and analyst tool:
Readiness decision and confidence:
Limitations and proposed corroboration:
Custody, working copy and cleanup:

Answer these review questions:

  • What directly shows that the image came from the authorised host and run?
  • What shows that the analyst's copy matches the preserved acquisition copy?
  • Did the capture alter memory? Why is the answer necessarily yes?
  • Does successful acquisition prove the suspicious sign-in was malicious?
  • Which disk, identity, endpoint and network records should be correlated next?
Milestone 3Acquisition ready for reviewAnother analyst can verify the image, reproduce intake validation and understand the readiness decision, impact and limitations.

Expected result The note distinguishes tool observations from interpretation and makes no claim stronger than the acquisition supports.

Optional: compare a controlled process

Restore pre-memory-acquisition, start a harmless application such as Notepad, record its PID and time, and repeat the acquisition to a new case-labelled path. Compare only the acquisition context and a focused process-list result. Explain why a returned process supports presence in the captured state but not malicious intent.

Full Lab evidence checklist

This checklist applies to the VM-based Full Lab. If you completed the Interactive Lab, retain its downloaded evidence summary instead.

  • Core completion

    Required for an attributable, integrity-checked memory acquisition.

  • Good analyst practice

    Supplementary records that strengthen review and recovery.

0 of 10 recorded Mark each item when you have saved the evidence.

Troubleshooting

Symptom First check
UAC or security control blocks execution Confirm authority, expected tool hash, publisher and local policy; do not bypass controls silently.
Reported RAM differs from the VM allocation Record both values and check dynamic-memory settings before acquisition.
Destination cannot accept the image Check mount state, filesystem limits, write access and free space; choose an approved destination.
Capture fails or is cancelled Preserve messages and partial output, assess contamination, then decide whether a documented retry is justified.
Acquisition and working hashes differ Stop analysis and determine whether copying, truncation or modification occurred.
Image will not parse Recheck hash, size, format and transfer; preserve the failure and use a compatible tool before reacquiring.

Clean up

Protect the acquisition copy, working copy, hashes and case note. Remove temporary access and harmless test material, safely detach evidence storage and restore the disposable VM when authorised. Do not delete failed or partial output until its evidential value and retention requirement are assessed.