Magnet RAM Capture¶
What Magnet RAM Capture does¶
Volatile-memory acquisition
Magnet RAM Capture is a Windows memory-acquisition utility. It copies physical memory into a raw image so an authorised investigator can preserve volatile evidence for later examination.
Volatile value
Memory may contain running processes, active network connections, injected code, decrypted content, command history and credentials that never reach disk.
Acquisition effect
Memory changes continuously, which makes acquisition both time-sensitive and intrusive: running any tool changes some of the memory being collected.
Screenshot and version context
The preserved SUSA screenshots show Magnet RAM Capture v1.2.0. Current download, licence and interface details may differ. Record the exact version and executable hash used in your case.
Choose your journey¶
01Install and openRequest, stage and verify the acquisition utility before elevation.Complete when provenance, version and authority are recorded.Beginner · Windows · 15–25 min 02Capture physical memoryChoose a controlled destination, configure the raw image and monitor acquisition.Complete when the output path and completion state are recorded.Beginner · Administrator · 10–30 min 03Verify and preserveRecord size and SHA-256, protect the acquisition copy and verify a working copy.Complete when integrity and custody are reviewable.Beginner · Evidence storage · 15–25 min 04Go hands-onPractise capture in the simulated interface or complete an isolated VM acquisition.Complete when another analyst can review your acquisition note.Guided beginner · Two alternative routes
Evidence workflow¶
Live acquisition has limits
A memory capture is not an atomic snapshot. Memory changes while it is read, and the acquisition tool, driver and storage activity alter the source. Preserve errors and timing information, and corroborate important findings with disk, event-log, network or endpoint evidence.
Before you begin¶
Why memory?
State the question volatile evidence may answer. For example, determine whether a suspicious process, decrypted payload or active connection exists now.
Where will it go?
Use a controlled destination with free space greater than installed RAM. Prefer a separate evidence volume to reduce source-disk writes.
What will you preserve?
Record the host, tool, timing, settings, completion state, size, hash, acquisition impact and custody.