Review Magnet Response output¶
Locate the requested output, preserve the original collection and review an identified working copy. Keep the command string tied to its endpoint, profile path, case reference and collection time.
Locate the collected history¶
Navigate to the captured PowerShell history. The timestamped directory name will vary:
C:\Tools\Magnet Response\<case>-MagnetRESPONSE-<timestamp>\Saved_Files\PowerShell_History\C\Users\<user>\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine
Open ConsoleHost_history.txt as a working copy and retain the original
collection unchanged.
Interpret the result¶
Record the source endpoint, user-profile path, collection time and profile alongside any relevant command. PowerShell history can be incomplete, disabled, cleared or produced by a different host process.
Treat the command string as a direct observation. Corroborate successful execution with suitable evidence such as PowerShell Operational logs, process creation telemetry, prefetch, Amcache, filesystem changes or other case data. Authorship requires separate identity and access evidence.
Evidence quality checklist¶
| Record | Why it matters |
|---|---|
| Authority and case reference | Links the live collection to an approved purpose |
| Endpoint identity and system time | Attributes the output and supports time interpretation |
| Magnet Response version and profile | Makes the collection scope reviewable |
| Output path, completion status and errors | Shows what finished and which gaps remain |
| Integrity information and working-copy record | Supports later verification |
| Observation, interpretation and limitations | Prevents a recovered string being overstated |

