Download Latest Version Release 1.7.1 source code.zip (6.7 MB)
Email in envelope

Get an email when there's a new version of Rekall

Home / v1.5.1
Name Modified Size InfoDownloads / Week
Parent folder
linpmem-2.1.post4 2016-05-24 7.3 MB
osxpmem-2.1.post4.zip 2016-05-24 3.8 MB
Rekall_1.5.1_Furka_x64.exe 2016-05-24 21.3 MB
Rekall_1.5.1_Furka_x86.exe 2016-05-24 21.5 MB
winpmem-2.1.post4.exe 2016-05-24 2.2 MB
README.md 2016-05-24 788 Bytes
Release 1.5.1 Furka source code.tar.gz 2016-05-24 4.5 MB
Release 1.5.1 Furka source code.zip 2016-05-24 5.5 MB
Totals: 8 Items   66.1 MB 15

This is the next point release in the 1.5 (Furka) series.

Some highlights of this release:

  • New windows plugins allowing inspection of the PFN database. This allows mapping of physical memory back to the owning process and file (if it is mapped from a file).
  • Improved scanning framework: Most scanners can now operate on specific memory regions, like process memory, kernel memory, pool memory etc. This allows scanners to be much faster because they are more targeted.

Releases are now also available here: http://releases.rekall-forensic.com/ We also make releases available in our own pypi repository. This allows us to host binary wheels which avoids the need for compilers on windows and osx at all. Visit http://pypi.rekall-forensic.com/ for directions about how to use that.

Source: README.md, updated 2016-05-24