Configure and capture a focused set¶
Use the smallest profile that answers the case question. This preserved procedure collects PowerShell history from Critical System Files without enabling unrelated collection categories.
Identify the PowerShell-history evidence required and what it cannot prove.
Select Critical System Files and configure only PowerShell history.
Retain the case reference, settings, destination, times, status, warnings and errors.
Select the collection profile¶
Enter a meaningful training case reference. The preserved screenshot uses
1; for independent practice, use a reference that ties the output to your
lab notes.
Under Collection Options, select only Collect Critical System Files.
Select Configure next to Collect Critical System Files. For this focused demonstration, select only PowerShell history, then save and close the configuration.
Collection changes the endpoint
Magnet Response runs processes, reads live data and files, and writes collection output. Record the expected footprint and use a controlled destination with enough capacity.
Start and monitor the capture¶
Review the case reference, selected profile and output destination, then select Start Capture.
When the capture completes, record the completion status and any warnings before selecting Exit.
Completion is a checkpoint, not a conclusion
Confirm that the timestamped destination exists and contains the requested material. Preserve warnings and inaccessible-item messages. A success dialog alone does not establish coverage or evidential meaning.



