Another platform that is similar to Volatility is Rekall. Rekall was developed by Google and purports to be the most complete memory analysis framework. The software is available for Linux, macOS, and Windows platforms. Instructions on how to download and set up Rekall can be found at The one major advantage that Rekall has over Volatility is that Google has also released the memory acquisition tool Pmem. This tool is designed to work with the Rekall framework giving a single point for the acquisition and analysis toolset.

Rekall has some deep similarities with Volatility. For example, there are a number of plugins that are similarly named and that perform very similar functions(the site ...

Get Digital Forensics and Incident Response now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.