Module index
source code
This module implements profile indexing.
Rekall relies on accurate profiles for reliable analysis of memory
artifacts. We depend on selecting the correct profile from the profile
repository, but sometimes its hard to determine the exact profile to use.
For windows, the profile must match exactly the GUID in the driver.
However, sometimes, the GUID is unavailable or it could be
manipulated. In that case we would like to determine the profile version
by applying the index.
The profile repository has an index for each kernel module stored. We
can use this index to determine the exact version of the profile very
quickly - even if the RSDS GUID is not available or incorrect.
Author:
Michael Cohen <scudette@google.com>
|
__package__ = ' rekall.plugins.windows '
|