Skip to content

Verify and preserve the memory image

Confirm that the output exists, record its acquisition context and protect an integrity-verified copy for analysis.

Confirm the output

Verify that memory.raw exists in C:\Labs\memory and record its exact path and byte size.

Screenshot: memory.raw visible in the acquisition directory

Calculate a SHA-256 hash with an approved utility. Protect the acquisition copy, record access and transfers, and perform analysis on a clearly identified working copy whose SHA-256 matches the acquisition copy.

Evidence quality record

Record Why it matters
Authority, case reference and source hostname Defines scope and attribution
Tool filename, version, source and SHA-256 Establishes acquisition-tool provenance
Installed RAM, destination and free space Supports capacity and completeness checks
Start/finish times and time zone Anchors the changing live state
Completion status, warnings and output size Exposes acquisition gaps or anomalies
Output SHA-256 and custody notes Supports integrity checks and handover
Known limitations and endpoint impact Prevents conclusions stronger than the method supports
1 Confirm path2 Record size3 Hash4 Protect original5 Verify working copy

Troubleshooting

Symptom First check
Output is missing Recheck the recorded destination and retained completion or error message.
Output size seems wrong Compare installed RAM, displayed size, segmentation, filesystem limits and acquisition messages.
Acquisition and working hashes differ Stop analysis and investigate copying, truncation or modification.
Analysis tool cannot open the image Confirm format, byte size, hash, transfer completeness and tool compatibility.
Integrity checkpointWhat best supports safe analysis of the acquired image?