
This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity snapshots.
Breaking Windows Recall. Again.
image
When Microsoft redesigned Recall with VBS enclaves, AES-256-GCM encryption, Windows Hello authentication, and a Protected Process Light host, the message was clear: the data is locked in a vault.
The vault is solid. The delivery truck is not.
AIXHost.exe, the process that renders the Recall timeline, has no PPL, no AppContainer, no code integrity enforcement. Any process running as the logged-in user can inject code into it and call the same COM APIs the legitimate UI uses. Once the user authenticates with Windows Hello, decrypted screenshots, OCR text, and metadata flow through AIXHost.exe as live COM objects. TotalRecall Reloaded sits inside that process and extracts everything.
No admin required. Standard user. No kernel exploit. No crypto bypass. Just COM calls.
TotalRecall Reloaded is two files: an injector (totalrecall.exe) and a payload DLL (totalrecall_payload.dll).
The injector finds AIXHost.exe via CreateToolhelp32Snapshot, allocates memory in the target with VirtualAllocEx, writes the DLL path with WriteProcessMemory, and spawns a remote thread pointing at LoadLibraryW. Classic DLL injection. Nothing fancy, because nothing fancy is needed. AIXHost.exe has zero protections against it.
This works from standard user privilege. No elevation, no SeDebugPrivilege. The default Windows DACL allows same-user processes full access to each other. Verified: the token runs at Medium mandatory level with BUILTIN\Administrators set to deny-only.
The VBS enclave won't decrypt anything without Windows Hello. The tool doesn't bypass that. It makes the user do it, silently rides along when the user does it, or waits for the user to do it.
--launch simulates Win+J via keybd_event, the keyboard shortcut that opens the Recall timeline. The user sees a Hello prompt (face, fingerprint, or PIN), authenticates, and the enclave starts serving decrypted data. From the user's perspective, Recall just opened normally. From ours, the payload is already inside, waiting.
--stealth is the fully silent mode. It works like this:
AIXHost.exe (always running) and patches DiscardDataAccess to a no-opAIXHost.exe dies and respawns. The tool detects the restart and re-injects into the new processaihost.exe (revocation was blocked). Extraction begins immediately--wait is the passive counterpart to --launch. Instead of simulating Win+J, the tool sits idle while the user opens Recall on their own — from the taskbar, a shortcut, or any other path. When AIXHost.exe appears and the user completes Hello naturally, the payload is injected and extraction begins. Useful on a machine being observed, or when the Recall session needs to look entirely user-initiated with no synthetic keyboard input.
Once inside AIXHost.exe, the payload initializes a COM apartment with CoInitializeEx(COINIT_APARTMENTTHREADED) and sets up proxy identity forwarding with CoSetProxyBlanket(EOAC_DYNAMIC_CLOAKING). This is critical. Without dynamic cloaking, the COM proxy doesn't carry the authenticated identity to the server.
The extraction follows the same path the legitimate Recall UI uses:
Enclave initialization: DataManager.Load() triggers enclave key loading. DataStoreManager.DecryptDatabase() (slot 37) prepares decrypted views. The payload polls DataManager.DataStatus until it returns 3 (unlocked).
Entity enumeration: MemoryEntityStatics.GetLightMemoryItemsBefore() (slot 9) returns a vector of lightweight entity references. Each carries a context ID at offset +8. On a typical machine, this returns hundreds of entities spanning days or weeks of activity.
Per-entity extraction: For each context ID, the payload loads the full entity via ContextEngine2.TryGetEntityForId() (slot 6), unwraps it through IEntityWrapper (slot 6), and QueryInterface to IMemoryEntity. From there:
TryGetBitmapCaptureAsync() (slot 19) returns a SoftwareBitmap. QueryInterface to ISoftwareBitmapNative, call GetData(IID_IWICBitmap) to get a WIC bitmap, encode as PNG via IWICBitmapEncoderContextEngine2.TryGetMemoryEntityDetailsForIdAsync() (slot 8) returns entity details. QI to IMemoryEntityDetails for OcrLines (slot 7), IMemoryEntityDetails2 for NER text entities (people, emails, addresses), and IMemoryEntityDetails4 for AI activity descriptionsRetry rounds: Baker.dll (the Recall UI library) populates the ContextEngine cache asynchronously. After the initial pass, the payload pumps Windows messages for 3 seconds (PeekMessage/DispatchMessage loop) and retries any entities that weren't available. Each round typically yields ~12 additional entities. Up to 10 retry rounds.
Every call is wrapped in __try/__except because a single access violation on a COM proxy call permanently kills the RPC channel to aihost.exe. There's no recovery. You'd have to restart AIXHost.exe. The SEH wrappers catch crashes from wrong parameter types and keep the session alive.
Several operations work without any Hello authentication:
Screenshot Extraction: RecallPrivacyIndicatorSettings (CLSID {42C63551-...}) exposes GetRecentCaptureThumbnail(width, height) at slot 13. The method name says "thumbnail" but the server doesn't enforce a resolution cap. Passing 3840x3840 returns the most recent Recall capture at full resolution. The IRandomAccessStream result is converted to an IStream via CreateStreamOverRandomAccessStream (shcore.dll) and dumped as BMP.
Data Destruction: IDataStoreManager::DeleteEvents() (slot 12) wipes the entire capture history. No parameters, no authentication. Ghidra analysis confirmed: the delete handler at FUN_1802ddd10 contains zero calls to the authorization gate function. The auth check was never wired in.
Metadata Disclosure: Storage paths (including the user-specific UKP GUID), database size, retention policy, capture state, and the most recent capture context ID are all readable without auth via IDataStoreManagerStatics and RecallPrivacyIndicatorSettings.
image
totalrecall.exe --launch Open Recall, trigger Hello, extract everything
totalrecall.exe --stealth Silent extraction (patches auth revocation, waits)
totalrecall.exe --wait Wait for user to manually open Recall
totalrecall.exe --preauth Grab latest screenshot + settings (no Hello)
totalrecall.exe --search "password" Search OCR text in latest extraction
totalrecall.exe --destroy Wipe all Recall data (confirmation required, no Hello)