Magnet Response¶
What Magnet Response does¶
Portable Windows incident-response collection
Magnet Response is a portable Windows incident response collection tool. It collects selected volatile information, critical system files and, when chosen, physical memory from a local endpoint before that information changes or is lost.
Learning route
This section arranges the original Magnet Response procedure into a guided collection journey. Start with the Overview, follow the focused capture, then use the Hands-on Labs to practise the complete evidence path in an authorised environment.
Evidence context
The guided interface is approachable for a first responder, but it does not remove the need to record authority, source identity, tool version, collection settings, start and finish times, output location and errors.
Version and trust checkpoint
Obtain Magnet Response from Magnet Forensics, retain the release notes and supplied integrity information, and record the version used. Interface labels and available collection choices can change between releases.
Operational model¶
Magnet Response runs locally on an authorised Windows endpoint and writes a consolidated response package to a selected destination. Investigators choose a bounded profile, capture the requested material, retain the collection context, and review working copies of the returned files.
Choose the collection scope¶
- Volatile data
Preserve current processes, connections, logged-on users and other live context before less volatile material. - Critical system files
Collect selected Registry, event-log, filesystem and user-activity artefacts for focused triage. - Physical memory
Include RAM only when the question, destination capacity, authority and live-system impact justify it.
Scope selection principle
Start with the smallest profile that answers the case question. A broad collection increases runtime, endpoint activity, output size and review work. Magnet Response is a logical and live-response collector, not a replacement for a forensic disk image or independent corroboration.
Choose your journey¶
You do not need to complete every section. Choose the route that matches your current task:
01Install and openObtain the utility, retain its provenance and prepare a controlled destination.Complete when the version, source and output boundary are recorded.Beginner · Windows workstation · 10–20 min 02Configure and captureSelect Critical System Files, configure PowerShell history and preserve the completion context.Complete when attributable output exists at the recorded destination.Guided beginner · Local endpoint · 15–30 min 03Review the outputLocate the collected history and separate observation from interpretation.Complete when the conclusion states what the evidence can and cannot establish.Beginner · Working copy · 15–25 min 04Go hands-onPractise in the Magnet-style browser simulation or complete the workflow in an isolated VM.Complete when another analyst can review your evidence.Guided beginner · Two alternative routes
Evidence workflow¶
When troubleshooting, follow the path from left to right. Confirm the source and collection profile before assuming an artefact did not exist. Preserve errors and collection metadata with the output.
Before you begin¶
Collection boundary
Use an owned or explicitly authorised Windows endpoint and a separate, controlled destination with sufficient capacity. Record the endpoint identity, system time and time zone before collection. Treat the response output as case material and create an identified working copy for review.
Evidence quality and limitations¶
- Completion is not completeness
A completed capture does not prove that every requested artefact was available or readable. - History can be incomplete
PowerShell history can be disabled, cleared or associated with a different host process. - Commands require corroboration
A recovered command string does not prove successful execution, authorship or malicious intent. - Live collection changes the endpoint
Record the expected footprint, warnings, errors and any unavailable material.