pip install rekall-core==1.7.2rc1

Rekall Memory Forensic Framework

Source
Among top 50% packages on PyPI.
Over 3.9K downloads in the last 90 days.

Commonly used with rekall-core

Based on how often these packages appear together in public requirements.txt files on GitHub.

rekall

Rekall Memory Forensic Framework

binplist

A binary plist parser

efilter

EFILTER query language

acora

Fast multi-keyword search engine for text strings

distorm3

The goal of diStorm3 is to decode x86/AMD64 binary streams and return a structure that describes each instruction.

WMI

Windows Management Instrumentation

pyinstaller

PyInstaller bundles a Python application and all its dependencies into a single package.

HspellPy

Python wrapper for Hspell

FXrays

Computes extremal rays with filtering

rekall-capstone

Capstone disassembly engine

artifacts

ForensicArtifacts.com Artifact Repository.

pyaff4

Advanced Forensic Format Version 4 (AFF4) Python module.

cypari

Sage's PARI extension, modified to stand alone.

pyrekall

A wrapper for the Rekall framework

spherogram

Spherical diagrams for 3-manifold topology

aff4-snappy

Python library for the snappy compression library from Google

bottle-utils-form

Form utilities for developing apps with Bottle web framework

wazimap-mapit

Uses Mapit to load maps and boundaries in Wazimap

odrive

Control utilities for the ODrive high performance motor controller

Version usage of rekall-core

Proportion of downloaded versions in the last 3 months (only versions over 1%).

1.7.2rc1

24.43%

1.7.1

5.39%

1.5.3.post1

5.37%

1.5.2.post1

3.97%

1.5.2

3.95%

1.5.3

3.92%

1.5.1

3.92%

1.5.0.post3

3.87%

1.5.0.post4

3.84%

1.5.0.post5

3.84%

1.5.0.post1

3.82%

1.5.0.post2

3.74%

1.5.0

3.74%

1.6.0

3.64%

1.4.1

2.48%

1.5.3rc3

2.01%

1.5.0.post0.dev3

1.99%

1.4.0

1.93%

1.5.3rc2

1.93%

1.4.0.pre4

1.91%

1.5.2rc1

1.91%

1.4.0.post.dev1

1.88%

1.4.0.pre3

1.86%

1.7.0rc1

1.78%

1.4.0.pre1

1.44%

1.4.pre0

1.42%