This is the Linux app named Rekall whose latest release can be downloaded as Release1.7.1sourcecode.tar.gz. It can be run online in the free hosting provider OnWorks for workstations.
Download and run online this app named Rekall with OnWorks for free.
Follow these instructions in order to run this app:
- 1. Downloaded this application in your PC.
- 2. Enter in our file manager https://www.onworks.net/myfiles.php?username=XXXXX with the username that you want.
- 3. Upload this application in such filemanager.
- 4. Start the OnWorks Linux online or Windows online emulator or MACOS online emulator from this website.
- 5. From the OnWorks Linux OS you have just started, goto our file manager https://www.onworks.net/myfiles.php?username=XXXXX with the username that you want.
- 6. Download the application, install it and run it.
SCREENSHOTS
Ad
Rekall
DESCRIPTION
Rekall is a powerful memory forensics framework that turns raw RAM captures—or live system state—into structured artifacts investigators can query and script. It ships with a large collection of plugins that parse OS internals to recover processes, modules, sockets, registry hives, and file objects, even when rootkits try to hide them. The design emphasizes repeatability: investigators run well-defined analyses that produce timelines, indicators, and reports suitable for case work or automation. Rekall supports profile-free operation for many targets, reducing setup friction and making it easier to handle varied images in the field. Extensibility is a core theme, with a plugin API and notebook-friendly workflows for custom hunts and triage. Used well, it compresses what would be hours of manual sleuthing into scripted passes over a consistent object model.
Features
- Rich plugin set for processes, drivers, sockets, registry, and files
- Works with offline memory images and live response modes
- Artifact-centric object model for repeatable investigations
- Profile-free parsing paths for many operating systems
- Scripting and notebook workflows for custom hunts
- Reporting and timeline generation for DFIR casework
Programming Language
Python
Categories
This is an application that can also be fetched from https://sourceforge.net/projects/rekall.mirror/. It has been hosted in OnWorks in order to be run online in an easiest way from one of our free Operative Systems.