Capture and Verify Memory¶
Prepare the acquisition¶
Create a case-specific destination on a separate controlled volume. Confirm its free space exceeds the endpoint's installed memory, record the endpoint identity and system time, and open Command Prompt as administrator.
Do not write the image back to the source volume
A memory image can be large and the acquisition changes the live system. Use an authorised destination, retain command output and stop if the source, destination or authority does not match the case plan.
Run WinPmem¶
The preserved SUSA procedure uses the following raw acquisition command:
Watch the console for driver, access, space or write errors. Record the exact command and the acquisition start and finish times.
Confirm and preserve the output¶
After completion, confirm that physmem.raw exists in C:\Labs\memory.
Record the output size, create a cryptographic hash using an approved utility, retain the acquisition log, and create a clearly labelled verified working copy for analysis. File existence alone is not sufficient validation.
Acquisition record¶
| Record | Minimum detail |
|---|---|
| Authority | Case reference and authorised endpoint |
| Tool | WinPmem filename, release and executable hash |
| Timing | Start, finish, system time and time zone |
| Output | Path, filename, size and destination identity |
| Integrity | Hash algorithm and value |
| Limitations | Errors, warnings, delays and security-tool interference |

