Verify and preserve the memory image¶
Confirm that the output exists, record its acquisition context and protect an integrity-verified copy for analysis.
Confirm the output¶
Verify that memory.raw exists in C:\Labs\memory and record its exact path
and byte size.
Calculate a SHA-256 hash with an approved utility. Protect the acquisition copy, record access and transfers, and perform analysis on a clearly identified working copy whose SHA-256 matches the acquisition copy.
Evidence quality record¶
| Record | Why it matters |
|---|---|
| Authority, case reference and source hostname | Defines scope and attribution |
| Tool filename, version, source and SHA-256 | Establishes acquisition-tool provenance |
| Installed RAM, destination and free space | Supports capacity and completeness checks |
| Start/finish times and time zone | Anchors the changing live state |
| Completion status, warnings and output size | Exposes acquisition gaps or anomalies |
| Output SHA-256 and custody notes | Supports integrity checks and handover |
| Known limitations and endpoint impact | Prevents conclusions stronger than the method supports |
1 Confirm path›2 Record size›3 Hash›4 Protect original›5 Verify working copy
Troubleshooting¶
| Symptom | First check |
|---|---|
| Output is missing | Recheck the recorded destination and retained completion or error message. |
| Output size seems wrong | Compare installed RAM, displayed size, segmentation, filesystem limits and acquisition messages. |
| Acquisition and working hashes differ | Stop analysis and investigate copying, truncation or modification. |
| Analysis tool cannot open the image | Confirm format, byte size, hash, transfer completeness and tool compatibility. |
Integrity checkpointWhat best supports safe analysis of the acquired image?
Select the control that verifies image content.
