Ross ROSS = Recommend OSS · open-source software intelligence for agents

google/rekall

Rekall Memory Forensic Framework observed · 2026-08-28

github.com/google/rekall · homepage · Python · GPL-2.0 (copyleft) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4492
  • days_rel: n/a
  • days_push: 2145
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2007 stars · 402 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Rekall is a Python-based memory forensic framework for extracting and analyzing digital artifacts from physical memory images of Windows, Linux, and macOS systems. It also provides memory acquisition tools and was forked from the Volatility project, but is now officially discontinued and archived.

Use cases

  • analyze a Windows memory dump for malware
  • extract running processes from a Linux memory image
  • perform incident response memory forensics
  • acquire a physical memory sample from a live system
  • investigate macOS memory captures
  • find injected code in a 64-bit memory dump

When to choose

  • you need to analyze legacy memory images and already have a working environment
  • you want to study memory forensics techniques or fork the codebase
  • you need a GPL-2.0 open-source memory analysis tool with no licensing constraints

When to avoid

  • you need an actively maintained memory forensics tool - the project is discontinued and archived
  • you are starting a new incident response workflow - consider Volatility or YARA-based approaches instead
  • you need memory acquisition on Windows - use the separately maintained WinPmem project

Facets

cli-tool · maturity abandoned

security reverse-engineering security developer-tools operating-systems python windows cli cross-platform memory-forensics incident-response digital-forensics memory-acquisition discontinued forensics linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
google/rekallmain10

For agents

markdown · JSON · MCP: product_card(name="google/rekall")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem