Open benwingerter opened 6 years ago
I have tried in the last week with no success. You can check $593 for my questions.
tl;dr
: I could not make it work.
Rekall is still available in GRR if you set a flag during installation. However, as also described in https://github.com/google/grr/issues/593, there might be issues and GRR team can only provide very limited support for Rekall at this time.
How can I do memory analysis without rekall(Memory flow)? Yara process scan is hard to user for memory forensics >_<
Are there any memory forensics tools built into GRR? Most online resources point to Rekall, but according to #448, Rekall support has been deprecated.