Skip to content

Review Magnet Response output

Locate the requested output, preserve the original collection and review an identified working copy. Keep the command string tied to its endpoint, profile path, case reference and collection time.

Locate the collected history

Navigate to the captured PowerShell history. The timestamped directory name will vary:

C:\Tools\Magnet Response\<case>-MagnetRESPONSE-<timestamp>\Saved_Files\PowerShell_History\C\Users\<user>\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine

Open ConsoleHost_history.txt as a working copy and retain the original collection unchanged.

Screenshot: Locate ConsoleHost_history.txt

Screenshot: Review PowerShell history

Interpret the result

Record the source endpoint, user-profile path, collection time and profile alongside any relevant command. PowerShell history can be incomplete, disabled, cleared or produced by a different host process.

Treat the command string as a direct observation. Corroborate successful execution with suitable evidence such as PowerShell Operational logs, process creation telemetry, prefetch, Amcache, filesystem changes or other case data. Authorship requires separate identity and access evidence.

Evidence quality checklist

Record Why it matters
Authority and case reference Links the live collection to an approved purpose
Endpoint identity and system time Attributes the output and supports time interpretation
Magnet Response version and profile Makes the collection scope reviewable
Output path, completion status and errors Shows what finished and which gaps remain
Integrity information and working-copy record Supports later verification
Observation, interpretation and limitations Prevents a recovered string being overstated
Interpretation checkpoint`ConsoleHost_history.txt` contains a suspicious command. What can you conclude?