Ok that was the trick. I believe I have winpmem working now. However when I go to try running a command in rekall I get an error like below. The system I am running this on (live) is Windows 8.1 x64.
C:\rekall>rekall -f \\.\pmem imageinfo
Traceback (most recent call last):
File "C:\Python27\Scripts\rekall-script.py", line 9, in <module>
load_entry_point('rekall==1.0.3', 'console_scripts', 'rekall')()
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\rekal.py", line 122, in main
flags = args.parse_args(argv=argv, user_session=user_session)
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\args.py", line 253, in parse_args
LoadProfileIntoSession(parser, argv, user_session)
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\args.py", line 219, in LoadProfileIntoSession
state.Set("logging", "warn")
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\session.py", line 242, in __exit__
hook()
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\session.py", line 170, in _set_filename
profile_parameter = self.session.GetParameter("profile")
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\session.py", line 404, in GetParameter
result = self._RunParameterHook(item)
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\session.py", line 424, in _RunParameterHook
result = hook.calculate()
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\plugins\guess_profile.py", line 270, in calculate
return self.ScanProfiles()
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\plugins\guess_profile.py", line 174, in ScanProfiles
"nt/GUID/%s" % rsds.GUID_AGE)
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\plugins\guess_profile.py", line 123, in VerifyWinPro
file
return self.ApplyFindDTB(win_common.WinFindDTB, profile)
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\plugins\guess_profile.py", line 132, in ApplyFindDTB
find_dtb_plugin = find_dtb_cls(session=self.session)
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\registry.py", line 56, in __call__
res = super(UniqueObjectIdMetaclass, cls).__call__(*args, **kwargs)
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\plugins\windows\common.py", line 112, in __init__
super(WinFindDTB, self).__init__(**kwargs)
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\plugin.py", line 245, in __init__
super(PhysicalASMixin, self).__init__(**kwargs)
File "C:\Python27\lib\site-packages\rekall-1.0.3-py2.7.egg\rekall\plugin.py", line 181, in __init__
raise PluginError("Profile not specified. (use vol(
plugins.info) "
rekall.plugin.PluginError: Profile not specified. (use vol(
plugins.info) to see available profiles.).
C:\rekall>