google/rekall
Rekall Memory Forensic Framework observed · 2026-08-28
Health v2 · maintenance only
10/100
- Activity 0
- Release rhythm 8
- Longevity 100
Flags: archived
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 4492
- days_rel: n/a
- days_push: 2145
- n_releases_24m: 0
Adoption not part of the score
2007 stars · 402 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Rekall is a Python-based memory forensic framework for extracting and analyzing digital artifacts from physical memory images of Windows, Linux, and macOS systems. It also provides memory acquisition tools and was forked from the Volatility project, but is now officially discontinued and archived.
Use cases
- analyze a Windows memory dump for malware
- extract running processes from a Linux memory image
- perform incident response memory forensics
- acquire a physical memory sample from a live system
- investigate macOS memory captures
- find injected code in a 64-bit memory dump
When to choose
- you need to analyze legacy memory images and already have a working environment
- you want to study memory forensics techniques or fork the codebase
- you need a GPL-2.0 open-source memory analysis tool with no licensing constraints
When to avoid
- you need an actively maintained memory forensics tool - the project is discontinued and archived
- you are starting a new incident response workflow - consider Volatility or YARA-based approaches instead
- you need memory acquisition on Windows - use the separately maintained WinPmem project
Facets
cli-tool · maturity abandoned
security reverse-engineering security developer-tools operating-systems python windows cli cross-platform memory-forensics incident-response digital-forensics memory-acquisition discontinued forensics linux macos
2 sources
- readme: https://github.com/google/rekall · fetched 2026-08-28 · cd783b86cc1b
- homepage: http://www.rekall-forensic.com · fetched 2026-08-29 · 904a12bbb66f
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| google/rekall | main | 10 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem