Papers

The following papers were published by the Rekall team in various conferences and scientific journals. These papers describe some of the deep research and novel solutions developed and implemented within the Rekall framework.
SelectionFile type iconFile nameDescriptionSizeRevisionTimeUser
Ċ
View Download
Anti-Forensic Resilient Memory Acquisition. Johannes Stuttgen and Michael Cohen. The proceedings of The Digital Forensic Research Conference DFRWS 2013 USA  979k v. 1 Jul 31, 2017, 12:59 AM Mike Cohen
Ċ
View Download
Robust Linux Memory Acquisition with Minimal Target Impact. Johannes Stuettgen and Michael Cohen. The proceedings of The Digital Forensic Research Conference DFRWS 2014 EU Amsterdam, NL   913k v. 2 Jul 31, 2017, 1:00 AM Mike Cohen
Ċ
View Download
Characterization Of The Windows Kernel Version Variability For Accurate Memory Analysis. Michael Cohen. The proceedings of The Digital Forensic Research Conference DFRWS 2015 EU Dublin, Ireland  2806k v. 1 Jul 31, 2017, 1:01 AM Mike Cohen
Ċ
View Download
Automatic profile generation for live Linux Memory analysis. Arkadiusz Socała, Michael Cohen. DFRWS 2016 Europe d Proceedings of the Third Annual DFRWS Europe  2684k v. 1 Jul 31, 2017, 12:58 AM Mike Cohen
Ċ
View Download
Using GRR and Rekall for Scalable Memory Analysis  4243k v. 1 Aug 14, 2017, 1:03 AM Mike Cohen
Ċ
View Download
Cohen, M., 2017. Scanning memory with Yara. Digital Investigation, 20, pp.34-43.  370k v. 1 Jul 31, 2017, 1:04 AM Mike Cohen
Ċ
View Download
Forensic Analysis of Windows User space Applications through Heap allocations. Michael Cohen. 3rd IEEE International Workshop on Security and Forensics in Communication Systems 2015  490k v. 1 Jul 31, 2017, 1:02 AM Mike Cohen
Ċ
View Download
Open Source Digital Forensics Conference 2017 https://www.osdfcon.org/2017-event/2017-abstracts/#RekallAgent  1473k v. 1 Oct 17, 2017, 10:50 AM Mike Cohen
Ċ
View Download
Rekall Agent Workshop DFRWS 2017  2677k v. 1 Oct 17, 2017, 12:36 AM Mike Cohen
Ċ
View Download
DFRWS 2017 Rekall Agent workshop guide.  2677k v. 2 Aug 14, 2017, 1:33 AM Mike Cohen