C:\winver
(note Windows version and build version, example Windows 10 1909 18363
F:\>winpmem.exe -o Windows10_1909_18363.aff4 -dd
-o denotes output location
-dd denotes verbosity
Default is to acquire as AFF4 which is a compressed container.
C3A contains system files and drivers acquired during memory acquisition (to support analysis)
PhysicalMemory is the physical memory stream
container.description contains AFF4 container GUID
information.turtle contains AFF4 stream data (drivers, physical memory, etc)
version.txt contains information relating to version of winpmem which was executed.