WinPmem Hands-on Labs¶
Choose a lab¶
Choose the Interactive Lab for a short, guided browser exercise. Try the Full Lab after reviewing the tool guide and preparing an isolated, authorised environment.
- Recommended first
- No installation
- Short guided scenario
- Isolated lab required
- Independent decisions
- Evidence or analyst outcome
How to use these labs
Start with the browser-based route to practise the workflow and evidence decisions without touching a real system. Use the Full Lab only in an isolated, authorised environment, and compare its outcome with the corresponding tool guide.
Interactive Lab¶
WinPmem Interactive Lab
Practise a guided WinPmem workflow in a safe browser simulation with immediate feedback.
- 1Source
- 2Configure
- 3Review
- 4Explain
Choose the authorised, traceable source
The case question is bounded. Select the item that preserves scope and provenance.
Guided hintStart with the case authority and endpoint identity. Choose the authorised 16 GB endpoint, not the analyst's personal system or a storage-volume description.
Select a source to continue.
Acquisition command
Do this nowEnter the requested value, then select Run command. Open the guided hint if you need an exact example.
Guided hintRun the verified x64 executable and write the case-linked RAW image to the separate D: evidence volume: winpmem_mini_x64.exe D:\SUSA-052\memory\WIN11-LAB.raw
Enter the acquisition command, then run the simulation.
Identify the result that answers the case question
Inspect the host, output, expected size and integrity fields. A completed tool run is not automatically a finding.
| Host | Output | Size | Integrity |
|---|---|---|---|
| WIN11-LAB | WIN11-LAB.raw | 16.0 GB | SHA-256 recorded |
| Background activity outside the case window | |||
Guided hintPreserve the row that connects the authorised host to the case-linked output, expected image size and recorded integrity value.
Select the row that should be preserved for analysis.
Choose the conclusion supported by the result
Guided hintChoose a conclusion that reports what was acquired and verified, identifies the next analysis step and does not claim that acquisition proves malicious intent.
Separate the acquired evidence from interpretation and state the next analytical step.
Full Lab¶
WinPmem Full Lab
Hands-on DFIR proof of concept
Prepare it. Examine it. Explain it.
Use WinPmem to capture Windows memory from the command line and verify the completed image, retain the evidence trail and write a bounded finding another analyst can review.
Safety boundary
Capture only an owned or authorised lab system. Memory can contain credentials and sensitive content.
an authorised Windows lab VM and a controlled destination larger than installed RAM
a memory image with capture time, tool version, size, path, and integrity hash
Recommended first
Beginner Core Lab¶
Complete one bounded WinPmem workflow using the documented source, settings and expected result.
Optional extension
Add a comparison¶
After the core succeeds, repeat the same focused task with one controlled change and explain the difference without widening the authorised scope.
Full Lab scenario¶
You are the first analyst reviewing a bounded training case. Your task is to capture Windows memory from the command line and verify the completed image. The result must be understandable to a second analyst who did not watch you perform the work.
01
Activity 1: Prepare the environment¶
- Restore an isolated Windows training VM named
WIN11-LABand record its snapshot, installed RAM, system time, time zone and case authority. - Place the verified WinPmem x64 executable in
C:\Tools\WinPmem. Record its release, filename, source and SHA-256 value. - Attach a separate evidence volume as
D:and createD:\SUSA-052\memory. Confirm free space exceeds installed RAM. - Open Command Prompt as administrator and record the current time before loading the acquisition driver.
02
Activity 2: Acquire and preserve memory¶
- Run
winpmem_mini_x64.exe D:\SUSA-052\memory\WIN11-LAB.rawfrom the controlled tools directory. Record the exact command and start time. - Watch for driver, access, write and space errors. Do not suppress or delete warnings; retain console output with the case material.
- After completion, record the finish time and output size. Confirm the image is on the separate evidence volume and not the endpoint system volume.
- Calculate and record a SHA-256 value with an approved hashing utility, then create a clearly labelled verified working copy for analysis.
03
Activity 3: Validate and report¶
- Confirm the working copy matches the recorded acquisition hash before opening it with an analysis tool.
- Perform a small validation check such as identifying the Windows profile or listing processes. Record the tool and result; do not attempt a broad hunt.
- Write a bounded acquisition note covering observation, interpretation, confidence and limitations. Explain that collection is non-atomic and that a completed command does not establish the absence of missing memory.
- Protect the retained image and log, remove temporary credentials, and restore the disposable VM to its recorded snapshot.
Full Lab evidence checklist¶
This checklist applies to the self-hosted Full Lab. If you completed the Interactive Lab, retain its browser evidence summary instead.
-
Core completion¶
Required to demonstrate a safe, attributable workflow.
-
Good analyst practice¶
Supplementary records that improve reproducibility and review quality.
Clean up¶
Protect retained output and case notes, remove harmless training material, clear temporary credentials or access and restore disposable systems to their recorded baseline. Confirm that no test collection remains active.