We can remember it for you wholesale!

What is Rekall?

Rekall is the most complete Memory Analysis framework. Rekall provides an end-to-end solution to incident responders and forensic analysts. From state of the art acquisition tools, to the most advanced open source memory analysis framework. Rekall at a glance.


Rekall's approach to memory analysis is unqiue - Rekall leverages exact debugging information provided by the operating system vendors to precisely locate significant kernel data structures. While other tools rely on heuristics and signatures, Rekall aims to be the most stable and reliable memory analysis framework.

Rekall maintains the largest public profile repository for many operating system versions.


One of Rekall's main goals is to be usable as a library, as part of a larger system. For this end, Rekall has developed library friendly APIs, such as JSON bases data exporting, progress reporting and thread safe behaviour.

Rekall is now tested automatically - click for dashboard.