Trees
Indices
Help
Rekall Memory Forensics
Package rekall
::
Package plugins
:: Package addrspaces
[
frames
] |
no frames
]
Package addrspaces
source code
Submodules
rekall.plugins.addrspaces.accelerated
:
The module provides alternate implementations utilizing C extension modules.
rekall.plugins.addrspaces.aff4
:
This Address Space allows us to open aff4 images.
rekall.plugins.addrspaces.amd64
:
This is based on Jesse Kornblum's patch to clean up the standard AS's.
rekall.plugins.addrspaces.arm
:
An address space to read ARM memory images.
rekall.plugins.addrspaces.crash
:
An Address Space for processing crash dump files.
rekall.plugins.addrspaces.elfcore
:
An Address Space for processing ELF64 coredumps.
rekall.plugins.addrspaces.ewf
:
This Address Space allows us to open ewf files
rekall.plugins.addrspaces.hibernate
:
A Hiber file Address Space
rekall.plugins.addrspaces.intel
:
Implement the base translating address spaces.
rekall.plugins.addrspaces.lime
:
This is an address space for the Lime file format.
rekall.plugins.addrspaces.macho
:
An Address Space for processing Mach-O coredumps.
rekall.plugins.addrspaces.mips
rekall.plugins.addrspaces.mmap_address_space
:
These are standard address spaces supported by Rekall Memory Forensics
rekall.plugins.addrspaces.pagefile
:
This address space overlays a pagefile into the physical address space.
rekall.plugins.addrspaces.pmem
:
Address spaces specific to pmem live here.
rekall.plugins.addrspaces.standard
:
These are standard address spaces supported by Rekall Memory Forensics
rekall.plugins.addrspaces.vmem
rekall.plugins.addrspaces.win32
:
This is a windows specific address space.
rekall.plugins.addrspaces.xpress
Variables
__package__
=
'
rekall.plugins.addrspaces
'
Trees
Indices
Help
Rekall Memory Forensics
Generated by Epydoc 3.0.1 on Mon Oct 9 03:27:46 2017
http://epydoc.sourceforge.net