Skip to content

Magnet Response Hands-on Labs

Choose the Interactive Lab to practise the complete focused capture in a safe Magnet Response simulation, or use the Full Lab on an isolated Windows training VM to collect and review your own evidence.

Interactive Lab

Browser-based · 20–30 min

Magnet Response Interactive Lab

No installation

Investigate case SUSA-031 in a Magnet Response-style interface: record the case, configure a focused PowerShell-history capture, choose a controlled destination and interpret the returned evidence.

Magnet RESPONSE guided captureCase SUSA-031 · training simulation
Current taskEnter the case reference

Use the reference from the authorised training brief.

  1. 1Case
  2. 2Profile
  3. 3Configure
  4. 4Capture
  5. 5Review
Magnet Forensics
Case briefCollect PowerShell history from the authorised WIN11-LAB endpoint.

Use case reference SUSA-031, select Critical System Files, choose PowerShell history only, and save to D:\SUSA-031\MagnetResponse.

Enter a case reference, select your collection preferences, and output location:

Case Reference
Collection Options

Focused profile: PowerShell history only. Select Critical System Files to open its configuration.

Output
Enter the training case reference to begin.

Full Lab

Self-hosted · Setup: 20–30 min · Core exercise: 45–75 min

Magnet Response Full Lab

Windows training VM and separate destination required

Hands-on focused live-response proof of concept

Scope it. Capture it. Explain it.

Collect PowerShell history from an authorised Windows training endpoint, preserve the capture context and write a conclusion that distinguishes a recorded command string from proof of execution or authorship.

⏱ Setup: 20–30 min · Core exercise: 45–75 min◆ Guided beginner✓ Evidence required

Outcome-led practice

The Full Lab provides a bounded case question, safety boundary and evidence checklist. Record your own version, settings, paths, times, warnings and result instead of attempting to reproduce every screenshot exactly.

Use an isolated, authorised environment

Run Magnet Response only on a disposable Windows training VM that you own or are explicitly authorised to examine. Use a separate controlled output destination, preserve warnings and restore the recorded snapshot after the exercise.

Before you begin

You need: one isolated Windows training VM, local administrator access, Magnet Response, a separate evidence destination, enough free space for the focused capture, a clean snapshot and a harmless PowerShell history entry.

How to use this lab

Complete the three activities in order. Stop when the expected output is missing, preserve the warning or error and correct that boundary before collecting more data.

Optional extension

Add corroborating context

After the core succeeds, repeat the capture with one additional focused source, such as relevant event logs, and explain whether it supports or challenges the initial interpretation.

Expected time: one additional 30–45 minute session.

  1. Session 1Prepare and snapshot
  2. Session 2Configure and capture
  3. Session 3Review and report

Safety boundary

Use only an owned or explicitly authorised endpoint. Record the live-system changes caused by collection.

Evidence

an authorised Windows lab endpoint and a written collection question

Success evidence

targeted output whose source, time, tool version, and integrity are recorded

Full Lab scenario

Case SUSA-031: an authorised Windows training endpoint may contain PowerShell activity related to an unexpected administrative change. Use Magnet Response to preserve a focused live-response set, identify relevant PowerShell-history context and write a bounded triage note. Do not interpret a history entry as proof that the command completed or that a particular person typed it.

01

Activity 1: Prepare the environment

  1. Restore an isolated Windows training VM and record its hostname, time zone, clock state and clean snapshot.
  2. Attach or prepare a separate controlled destination with enough free space.
  3. Obtain Magnet Response from Magnet Forensics. Record the version, archive provenance and supplied integrity information.
  4. Create a harmless PowerShell training entry, record the exact command and time, then close the PowerShell session normally.
Milestone 1Collection boundary readyAuthority, endpoint identity, destination, version, time context and known training entry are recorded.

02

Activity 2: Collect the focused set

  1. Start Magnet Response and enter case reference SUSA-031.
  2. Select Collect Critical System Files, open its configuration and select only PowerShell history.
  3. Review the profile and destination before starting capture. Record start and finish times, completion status and any warning.
  4. Preserve the consolidated output and collection metadata. Do not discard errors simply because the interface reports completion.
Milestone 2Focused output preservedThe output remains attributable to the endpoint, case reference, version, profile, destination and collection time.

03

Activity 3: Review and report

  1. Locate the collected ConsoleHost_history.txt beneath the recorded user profile path.
  2. Confirm whether the harmless training entry appears. Record missing or truncated history as a limitation rather than evidence of absence.
  3. Hash the retained output or evidence package and create a clearly labelled working copy for review.
  4. Write a finding with observation, interpretation, confidence and limitations. Identify independent evidence that could confirm execution, such as event logs, process evidence or filesystem artefacts.
  5. Remove the harmless training material and restore the disposable VM.
Milestone 3Triage note ready for reviewAnother learner can trace the selected profile to the retained output and understand what the history entry does and does not establish.

Full Lab evidence checklist

This checklist applies to the self-hosted Full Lab. If you completed the Interactive Lab, retain its downloaded evidence summary instead.

Complete the lab by showing that the focused capture is attributable and that the conclusion is traceable to retained output.

  • Core completion

    Required to demonstrate a safe, attributable focused response collection.

  • Good analyst practice

    Supplementary records that strengthen reproducibility and review.

0 of 10 recorded Mark each item when you have saved the evidence.

Clean up

Protect retained output and case notes, remove harmless training material, clear temporary credentials or access and restore disposable systems to their recorded baseline. Confirm that no test collection remains active.