Magnet Response Hands-on Labs¶
Choose the Interactive Lab to practise the complete focused capture in a safe Magnet Response simulation, or use the Full Lab on an isolated Windows training VM to collect and review your own evidence.
- Recommended first
- No installation
- Short guided scenario
- Isolated lab required
- Independent decisions
- Evidence or analyst outcome
Interactive Lab¶
Magnet Response Interactive Lab
Investigate case SUSA-031 in a Magnet Response-style interface: record the case, configure a focused PowerShell-history capture, choose a controlled destination and interpret the returned evidence.

Use the reference from the authorised training brief.
- 1Case
- 2Profile
- 3Configure
- 4Capture
- 5Review

Use case reference SUSA-031, select Critical System Files, choose PowerShell history only, and save to D:\SUSA-031\MagnetResponse.
Enter a case reference, select your collection preferences, and output location:

All operations have completed, with no errors.
- Case
- Profile
- Critical System Files › PowerShell history
- Saved to
- Collected item
- ConsoleHost_history.txt
Get-DateGet-LocalGroupMember -Group AdministratorsAdd-LocalGroupMember -Group Administrators -Member svc-backupGet-Service WinRM
Observation: the attributed profile contains the highlighted command string. PowerShell history does not record whether it completed successfully or who was at the keyboard.
Open ConsoleHost_history.txt before assessing the evidence.
Full Lab¶
Magnet Response Full Lab
Hands-on focused live-response proof of concept
Scope it. Capture it. Explain it.
Collect PowerShell history from an authorised Windows training endpoint, preserve the capture context and write a conclusion that distinguishes a recorded command string from proof of execution or authorship.
Outcome-led practice
The Full Lab provides a bounded case question, safety boundary and evidence checklist. Record your own version, settings, paths, times, warnings and result instead of attempting to reproduce every screenshot exactly.
Use an isolated, authorised environment
Run Magnet Response only on a disposable Windows training VM that you own or are explicitly authorised to examine. Use a separate controlled output destination, preserve warnings and restore the recorded snapshot after the exercise.
Before you begin
You need: one isolated Windows training VM, local administrator access, Magnet Response, a separate evidence destination, enough free space for the focused capture, a clean snapshot and a harmless PowerShell history entry.
How to use this lab
Complete the three activities in order. Stop when the expected output is missing, preserve the warning or error and correct that boundary before collecting more data.
Recommended first
Beginner Core Lab¶
Capture PowerShell history from one authorised endpoint and write a bounded finding that distinguishes recorded command text from execution evidence.
Expected time: 65–105 minutes after Magnet Response is available.
Optional extension
Add corroborating context¶
After the core succeeds, repeat the capture with one additional focused source, such as relevant event logs, and explain whether it supports or challenges the initial interpretation.
Expected time: one additional 30–45 minute session.
- Session 1Prepare and snapshot
- Session 2Configure and capture
- Session 3Review and report
Safety boundary
Use only an owned or explicitly authorised endpoint. Record the live-system changes caused by collection.
an authorised Windows lab endpoint and a written collection question
targeted output whose source, time, tool version, and integrity are recorded
Full Lab scenario¶
Case SUSA-031: an authorised Windows training endpoint may contain PowerShell activity related to an unexpected administrative change. Use Magnet Response to preserve a focused live-response set, identify relevant PowerShell-history context and write a bounded triage note. Do not interpret a history entry as proof that the command completed or that a particular person typed it.
01
Activity 1: Prepare the environment¶
- Restore an isolated Windows training VM and record its hostname, time zone, clock state and clean snapshot.
- Attach or prepare a separate controlled destination with enough free space.
- Obtain Magnet Response from Magnet Forensics. Record the version, archive provenance and supplied integrity information.
- Create a harmless PowerShell training entry, record the exact command and time, then close the PowerShell session normally.
02
Activity 2: Collect the focused set¶
- Start Magnet Response and enter case reference
SUSA-031. - Select Collect Critical System Files, open its configuration and select only PowerShell history.
- Review the profile and destination before starting capture. Record start and finish times, completion status and any warning.
- Preserve the consolidated output and collection metadata. Do not discard errors simply because the interface reports completion.
03
Activity 3: Review and report¶
- Locate the collected
ConsoleHost_history.txtbeneath the recorded user profile path. - Confirm whether the harmless training entry appears. Record missing or truncated history as a limitation rather than evidence of absence.
- Hash the retained output or evidence package and create a clearly labelled working copy for review.
- Write a finding with observation, interpretation, confidence and limitations. Identify independent evidence that could confirm execution, such as event logs, process evidence or filesystem artefacts.
- Remove the harmless training material and restore the disposable VM.
Full Lab evidence checklist¶
This checklist applies to the self-hosted Full Lab. If you completed the Interactive Lab, retain its downloaded evidence summary instead.
Complete the lab by showing that the focused capture is attributable and that the conclusion is traceable to retained output.
-
Core completion¶
Required to demonstrate a safe, attributable focused response collection.
-
Good analyst practice¶
Supplementary records that strengthen reproducibility and review.
Clean up¶
Protect retained output and case notes, remove harmless training material, clear temporary credentials or access and restore disposable systems to their recorded baseline. Confirm that no test collection remains active.