Package rekall :: Package plugins :: Package windows :: Module procdump
[frames] | no frames]

Module procdump

source code

Classes
  PEDump
Dump a PE binary from memory.
  ProcExeDump
Dump a process to an executable file sample
  DLLDump
Dump DLLs from a process address space
  ModDump
Dump kernel drivers from kernel space.
Variables
  __package__ = 'rekall.plugins.windows'