Skip to main content

D2Rekall

This Script is part of the D2 (Deprecated) Pack.#

Executes Rekall on a system (usually a forensics workstation) and analyzes a memory dump file located on that system.

Script Data#


NameDescription
Script Typejavascript
Tagsagent, memory, forensics

Inputs#


Argument NameDescription
fileThe path to the memory dump file in the machine's filesystem.
formatThe format argument for Rekall. For example, json or text.

Outputs#


There are no outputs for this script.