Skip to content
Sections
>> Trisquel >> Packages >> etiona >> utils >> rekall-core
etiona  ]
[ Source: rekall  ]

Package: rekall-core (1.6.0+dfsg-2)

memory analysis and incident response framework

The Rekall Framework is a completely open collection of tools for the extraction and analysis of digital artifacts computer systems.

Rekall supports investigations of the following 32bit and 64bit memory images:

 - Microsoft Windows XP Service Pack 2 and 3
 - Microsoft Windows 7 Service Pack 0 and 1
 - Microsoft Windows 8 and 8.1
 - Microsoft Windows 10
 - Linux Kernels 2.6.24 to 4.4.
 - OSX 10.7-10.12.x.

Rekall also provides a complete memory sample acquisition capability for all major operating systems.

Other Packages Related to rekall-core

  • depends
  • recommends
  • suggests
  • dep: python
    interactive high-level object-oriented language (default version)
  • dep: python-ipython (>= 5.0.0)
    Enhanced interactive Python shell (Python 2 version)
  • dep: python-rekall-core (= 1.6.0+dfsg-2)
    memory analysis and incident response framework -- core Python modules

Download rekall-core

Download for all available architectures
Architecture Package Size Installed Size Files
all 5.8 kB22 kB [list of files]