Skip to content

Capture and Verify Memory

Prepare the acquisition

Create a case-specific destination on a separate controlled volume. Confirm its free space exceeds the endpoint's installed memory, record the endpoint identity and system time, and open Command Prompt as administrator.

Do not write the image back to the source volume

A memory image can be large and the acquisition changes the live system. Use an authorised destination, retain command output and stop if the source, destination or authority does not match the case plan.

Run WinPmem

The preserved SUSA procedure uses the following raw acquisition command:

winpmem_mini_x64.exe C:\Labs\memory\physmem.raw

Run WinPmem from an administrator Command Prompt.

Watch the console for driver, access, space or write errors. Record the exact command and the acquisition start and finish times.

Confirm and preserve the output

After completion, confirm that physmem.raw exists in C:\Labs\memory.

Confirm that the memory image exists in the controlled destination.

Record the output size, create a cryptographic hash using an approved utility, retain the acquisition log, and create a clearly labelled verified working copy for analysis. File existence alone is not sufficient validation.

Acquisition record

Record Minimum detail
Authority Case reference and authorised endpoint
Tool WinPmem filename, release and executable hash
Timing Start, finish, system time and time zone
Output Path, filename, size and destination identity
Integrity Hash algorithm and value
Limitations Errors, warnings, delays and security-tool interference