Skip to content

WinPmem Hands-on Labs

Choose a lab

Choose the Interactive Lab for a short, guided browser exercise. Try the Full Lab after reviewing the tool guide and preparing an isolated, authorised environment.

How to use these labs

Start with the browser-based route to practise the workflow and evidence decisions without touching a real system. Use the Full Lab only in an isolated, authorised environment, and compare its outcome with the corresponding tool guide.

Interactive Lab

Browser-based · 10–20 min

WinPmem Interactive Lab

No installation

Practise a guided WinPmem workflow in a safe browser simulation with immediate feedback.

W
Case SUSA-052: unexpected PowerShell activityCapture Windows memory from the command line and verify the completed image.
Task 1 of 4
Safe simulationThis interface models a WinPmem workflow. It does not run the product, access an endpoint, or change evidence.
  1. 1Source
  2. 2Configure
  3. 3Review
  4. 4Explain
Administrator: Command Prompt · WinPmemSUSA training case / read-only simulation
Task 01 · Select evidence

Choose the authorised, traceable source

The case question is bounded. Select the item that preserves scope and provenance.

Select a source to continue.

Choose the defensible source to begin.

Full Lab

Self-hosted · 45–90 min

WinPmem Full Lab

Evidence required

Hands-on DFIR proof of concept

Prepare it. Examine it. Explain it.

Use WinPmem to capture Windows memory from the command line and verify the completed image, retain the evidence trail and write a bounded finding another analyst can review.

⏱ Setup and core exercise: 45–90 min◆ Guided beginner✓ Evidence required

Safety boundary

Capture only an owned or authorised lab system. Memory can contain credentials and sensitive content.

Evidence

an authorised Windows lab VM and a controlled destination larger than installed RAM

Success evidence

a memory image with capture time, tool version, size, path, and integrity hash

Optional extension

Add a comparison

After the core succeeds, repeat the same focused task with one controlled change and explain the difference without widening the authorised scope.

Full Lab scenario

You are the first analyst reviewing a bounded training case. Your task is to capture Windows memory from the command line and verify the completed image. The result must be understandable to a second analyst who did not watch you perform the work.

01

Activity 1: Prepare the environment

  1. Restore an isolated Windows training VM named WIN11-LAB and record its snapshot, installed RAM, system time, time zone and case authority.
  2. Place the verified WinPmem x64 executable in C:\Tools\WinPmem. Record its release, filename, source and SHA-256 value.
  3. Attach a separate evidence volume as D: and create D:\SUSA-052\memory. Confirm free space exceeds installed RAM.
  4. Open Command Prompt as administrator and record the current time before loading the acquisition driver.
Milestone 1Acquisition boundary readyThe authorised host, tool, destination, available space, time context and clean snapshot are recorded.

02

Activity 2: Acquire and preserve memory

  1. Run winpmem_mini_x64.exe D:\SUSA-052\memory\WIN11-LAB.raw from the controlled tools directory. Record the exact command and start time.
  2. Watch for driver, access, write and space errors. Do not suppress or delete warnings; retain console output with the case material.
  3. After completion, record the finish time and output size. Confirm the image is on the separate evidence volume and not the endpoint system volume.
  4. Calculate and record a SHA-256 value with an approved hashing utility, then create a clearly labelled verified working copy for analysis.
Milestone 2Memory image preservedThe image, command, timing, size, acquisition messages and integrity value remain attributable to WIN11-LAB.

03

Activity 3: Validate and report

  1. Confirm the working copy matches the recorded acquisition hash before opening it with an analysis tool.
  2. Perform a small validation check such as identifying the Windows profile or listing processes. Record the tool and result; do not attempt a broad hunt.
  3. Write a bounded acquisition note covering observation, interpretation, confidence and limitations. Explain that collection is non-atomic and that a completed command does not establish the absence of missing memory.
  4. Protect the retained image and log, remove temporary credentials, and restore the disposable VM to its recorded snapshot.
Milestone 3Acquisition ready for reviewAnother analyst can identify the source, verify the image and understand collection changes, warnings and limitations.

Full Lab evidence checklist

This checklist applies to the self-hosted Full Lab. If you completed the Interactive Lab, retain its browser evidence summary instead.

  • Core completion

    Required to demonstrate a safe, attributable workflow.

  • Good analyst practice

    Supplementary records that improve reproducibility and review quality.

0 of 8 recorded Mark each item when you have saved the evidence.

Clean up

Protect retained output and case notes, remove harmless training material, clear temporary credentials or access and restore disposable systems to their recorded baseline. Confirm that no test collection remains active.