Skip to content

Configure and capture a focused set

Use the smallest profile that answers the case question. This preserved procedure collects PowerShell history from Critical System Files without enabling unrelated collection categories.

Question

Identify the PowerShell-history evidence required and what it cannot prove.

Profile

Select Critical System Files and configure only PowerShell history.

Record

Retain the case reference, settings, destination, times, status, warnings and errors.

Select the collection profile

Enter a meaningful training case reference. The preserved screenshot uses 1; for independent practice, use a reference that ties the output to your lab notes.

Under Collection Options, select only Collect Critical System Files.

Screenshot: Select Collect Critical System Files

Select Configure next to Collect Critical System Files. For this focused demonstration, select only PowerShell history, then save and close the configuration.

Screenshot: Configure PowerShell history collection

Collection changes the endpoint

Magnet Response runs processes, reads live data and files, and writes collection output. Record the expected footprint and use a controlled destination with enough capacity.

Start and monitor the capture

Review the case reference, selected profile and output destination, then select Start Capture.

Screenshot: Start the Magnet Response capture

When the capture completes, record the completion status and any warnings before selecting Exit.

Screenshot: Completed Magnet Response capture

Completion is a checkpoint, not a conclusion

Confirm that the timestamped destination exists and contains the requested material. Preserve warnings and inaccessible-item messages. A success dialog alone does not establish coverage or evidential meaning.

Scope checkpointYou need PowerShell history from one authorised endpoint. What is the proportionate profile?