Skip to content

Latest commit

 

History

246 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

LockKnife: Android security research and digital forensics. Evidence, case context, and findings in one workspace.

LockKnife

Investigate Android. Keep the whole case in view.

Android security research · Digital forensics · APK reverse engineering

Collect evidence, investigate applications, and deliver clear reports from one terminal workspace.


Get LockKnife Read the Guides

Release Platforms Python License


Features   /   Installation   /   Quick Start   /   User Guides   /   Website



LockKnife is an open-source Android security research and digital forensics toolkit for security researchers, forensic analysts, and mobile penetration testers. Bring device extraction, offline evidence analysis, APK reverse engineering, Frida instrumentation, network forensics, and reporting into a single investigation.

Work interactively in a full-screen terminal interface or use focused CLI commands. Keep related outputs in a case, trace findings back to their inputs, and turn evidence into technical or executive reports.

One case. Connected evidence.
Artifacts, analysis, sessions, and reports together.
Your workflow. Your interface.
Interactive terminal or repeatable CLI commands.
Device or offline.
Collect from Android or inspect existing evidence.

Features

From First Artifact to Final Finding

01   Collect Android Evidence

Acquire accessible messages, contacts, call logs, browser records, media, and location artifacts. Explore supported WhatsApp, Telegram, and Signal data.

Device acquisition · App artifacts · Batch extraction

02   Reconstruct the Story

Inspect SQLite databases, build timelines, correlate identifiers, import ALEAPP results, and review record-recovery candidates alongside their source evidence.

Offline forensics · Timelines · Artifact correlation

03   Look Inside Android Apps

Review manifests, permissions, and exported components. Decompile APKs with JADX or apktool, inspect DEX metadata, and scan application contents with YARA rules.

APK analysis · Reverse engineering · YARA scanning

04   Observe Apps in Motion

Use Frida hooks, method tracing, memory searches, and case-linked sessions. Test supported SSL-pinning and root-detection hooks on authorized targets.

Runtime instrumentation · Memory inspection · Frida

05   Follow Traffic and Indicators

Inspect PCAPs, discover visible API endpoints, capture device traffic, and review device security indicators. Enrich selected findings with VirusTotal or OTX.

Network forensics · Device security · Threat intelligence

06   Deliver a Traceable Case

Follow artifact lineage, verify registered hashes and audit records, create technical or executive reports, and export case bundles for protected handoff.

Evidence provenance · Integrity checks · Reporting

Also included: supported legacy PIN/password recovery, credential-artifact inspection, wallet forensics, optional log anomaly scoring, and Bluetooth, Wi-Fi, and TCP discovery or protocol tools. Rust-powered hashing, recovery, and native analysis helpers support demanding tasks.

Note

Investigation examples use dummy identifiers and file paths, not real devices or evidence. Replace EXAMPLE_* values, com.example.placeholder, and example input paths with your authorized inputs before running a command. Installation links point to the actual project.

Android extraction and offline forensics   /   See command examples

Create a case first, replace EXAMPLE_DEVICE_SERIAL with your authorized device's serial, and substitute the input paths with your evidence files.

lockknife --cli extract browser --serial EXAMPLE_DEVICE_SERIAL --app chrome --kind history --case-dir ./cases/EXAMPLE_CASE
lockknife --cli extract messaging --serial EXAMPLE_DEVICE_SERIAL --app whatsapp --case-dir ./cases/EXAMPLE_CASE
lockknife --cli forensics sqlite ./example-evidence/messages.db --case-dir ./cases/EXAMPLE_CASE
lockknife --cli forensics correlate --input ./example-evidence/artifacts.json --case-dir ./cases/EXAMPLE_CASE

Acquisition depends on permissions, app versions, and encryption. Protected paths may require root; collecting an encrypted database does not decrypt its messages. Carved records are recovery candidates, not automatic proof of deletion.

APK analysis and reverse engineering   /   Modes and examples
Mode What You Get
auto JADX, then apktool, then archive unpacking as fallbacks
jadx Reconstructed Java-like source
apktool Decoded resources, manifest, and Smali
unpack Raw application files
hybrid Combined JADX and apktool output
lockknife --cli apk decompile ./example-app.apk --mode auto --output ./example-decompiled
lockknife --cli apk scan --apk ./example-app.apk --yara ./example-rules/example.yar

Automated security findings require review. Archive unpacking is not source-code reconstruction.

Frida runtime instrumentation   /   Hooks and memory inspection
lockknife --cli runtime bypass-ssl com.example.placeholder --device-id EXAMPLE_DEVICE_SERIAL --case-dir ./cases/EXAMPLE_CASE
lockknife --cli runtime memory-search com.example.placeholder --device-id EXAMPLE_DEVICE_SERIAL --pattern "EXAMPLE_SEARCH_TEXT"

Frida requires a compatible target server and sufficient permissions. Built-in hooks depend on the app implementation and can change its behavior. Explicitly stop active sessions when your work is complete.

Network forensics and device security   /   Capture analysis and posture checks
lockknife --cli network api-discovery ./example-evidence/capture.pcap --case-dir ./cases/EXAMPLE_CASE
lockknife --cli security scan --serial EXAMPLE_DEVICE_SERIAL

Device capture requires accessible on-device tcpdump. Encrypted traffic may conceal endpoints and payloads; reported device properties do not independently establish hardware security.

Credential recovery and wallet forensics   /   Supported evidence workflows
lockknife --cli crack pin --hash EXAMPLE_SHA1_HASH --algo sha1 --length 4
lockknife --cli crypto-wallet scan-device --serial EXAMPLE_DEVICE_SERIAL --case-dir ./cases/EXAMPLE_CASE

EXAMPLE_SHA1_HASH is a placeholder, not a usable hash. Replace it with the 40-character hexadecimal SHA-1 value you are authorized to test. Credential tools support specific legacy hashes and accessible artifacts; they do not guarantee recovery of modern Android screen locks or hardware-backed private keys. Wallet workflows depend on the supported app format and available data.

Important

Use device-changing and wireless workflows only within your authorized scope. Check lockknife --cli features for requirements and capability status; PoC, simulated, or unavailable functions are not verified live exploits.

Installation

Pick Your Platform

macOS Linux Windows
Homebrew or installer One-line installer Scoop
Apple Silicon / ARM64 x86-64 or ARM64 x86-64

Homebrew · macOS

brew install ImKKingshuk/tap/lockknife

One-line installer · macOS and Linux

curl -fsSL https://lockknife.vercel.app/install | bash

Scoop · Windows

With Scoop installed:

scoop bucket add imkkingshuk https://github.com/ImKKingshuk/scoop-bucket
scoop install imkkingshuk/lockknife
Prefer a Python environment?   /   Install a prebuilt wheel

Download the matching wheel from GitHub Releases. Use Python 3.12 or newer:

python -m pip install /path/to/EXAMPLE_WHEEL.whl

Choose a wheel matching the operating system and architecture listed above.

/path/to/EXAMPLE_WHEEL.whl is a dummy path. Replace it with the full path and filename of the wheel you downloaded.

Optional features   /   Dependencies and setup

For wheel installations, select the extras you need:

python -m pip install '/path/to/EXAMPLE_WHEEL.whl[apk,network]'
python -m pip install '/path/to/EXAMPLE_WHEEL.whl[full]'
Extra Enables
apk APK analysis
frida Runtime instrumentation
network Extended PCAP analysis
yara YARA rule scanning
threat-intel VirusTotal and OTX clients
ml Machine-learning analysis helpers
full All investigation extras above

External tools still apply: JADX/apktool for decompilation, a target Frida server for instrumentation, and device tcpdump for capture. PDF rendering and Bleak are separate dependencies, not included in full. Install optional Python dependencies in the environment containing LockKnife, not an unrelated system Python.

Device work requires Android platform-tools (adb) and device authorization. Offline analysis does not require a connected device. See Installation and Troubleshooting for updates and setup help.

Quick Start

Choose How You Work

Interactive Workspace

Browse devices and modules, fill in action forms, and review results in a full-screen terminal.

lockknife

Follow the TUI walkthrough

Focused CLI Commands

Run individual tasks, repeat an investigation workflow, or analyze evidence without opening the TUI.

lockknife --cli --help

Follow the CLI walkthrough

Your First Investigation

flowchart LR
    A[Collect] --> B[Analyze]
    B --> C[Verify]
    C --> D[Report]
    classDef collect fill:#dafbe1,stroke:#1a7f37,color:#116329
    classDef analyze fill:#ddf4ff,stroke:#0969da,color:#0550ae
    classDef verify fill:#fff8c5,stroke:#9a6700,color:#633c01
    classDef report fill:#f6f8fa,stroke:#57606a,color:#24292f
    class A collect
    class B analyze
    class C verify
    class D report
Loading

Start with device or local evidence, inspect artifacts and applications, verify registered hashes and case events, then share reviewed findings.

1. Check your installation and authorized device.

lockknife --version
lockknife --cli doctor
lockknife --cli device list

Replace EXAMPLE_DEVICE_SERIAL with a serial returned by device list. The examples use ./cases/EXAMPLE_CASE; choose private storage for actual case data.

2. Create a case and collect accessible evidence.

lockknife --cli case init --case-id EXAMPLE_CASE --examiner "EXAMPLE_EXAMINER" --title "Example Android Assessment" --output ./cases/EXAMPLE_CASE
lockknife --cli device info --serial EXAMPLE_DEVICE_SERIAL
lockknife --cli extract sms --serial EXAMPLE_DEVICE_SERIAL --format json --case-dir ./cases/EXAMPLE_CASE
lockknife --cli extract call-logs --serial EXAMPLE_DEVICE_SERIAL --format json --case-dir ./cases/EXAMPLE_CASE

3. Review, verify, and report.

lockknife --cli case summary --case-dir ./cases/EXAMPLE_CASE
lockknife --cli report integrity --case-dir ./cases/EXAMPLE_CASE --format json
lockknife --cli report generate --case-dir ./cases/EXAMPLE_CASE --template technical --format html
lockknife --cli case export --case-dir ./cases/EXAMPLE_CASE --include-registered-artifacts --output ./example-case-bundle.zip

Use the output paths printed by each command. HTML reports are available with the base installation; PDF requires an optional renderer. Reports and bundles are not encrypted by default, so review and protect them before sharing.

Explore more commands   /   Help, capabilities, and classic menus
lockknife --cli --help
lockknife --cli features
lockknife --cli actions --format json

Use --help on an individual command to see its options. Prefer numbered menus? Run lockknife --cli interactive and follow the classic menu guide.

Documentation

Find Your Next Step

Get Started Investigate Protect and Share
Installation and troubleshooting Interactive TUI walkthrough Case integrity and privacy
Classic menu guide CLI investigation walkthrough Security and privacy

Follow release notes in the changelog to see what's changed between versions.

Frequently Asked Questions

Do I need root or a connected Android device?

Not for offline analysis or case review. You can inspect local SQLite databases, APKs, PCAP files, and supported exported artifacts. Device-backed operations need a connection; protected app and system paths often need elevated access.

Can LockKnife unlock every Android device?

No. Credential recovery supports specific hashes and accessible artifacts. Modern hardware-backed credentials, encryption, and device protections cannot be assumed recoverable or bypassable.

Why does a feature need additional setup?

Some workflows need optional dependencies, external tools, provider credentials, or target permissions. Run lockknife --cli doctor and lockknife --cli features to check requirements before starting.

Are my investigation results sent to external services?

Local analysis does not require threat intelligence services. Explicit external lookups send selected indicators to their providers. Review your data-sharing policy and the case privacy guide before using those integrations.


Authorized research. Responsible evidence handling.

Use LockKnife only on devices, applications, and networks you are authorized to examine. Follow applicable laws and protect collected personal data.

Website   ·   Download   ·   User Guides   ·   GPL-3.0-only License

About

LockKnife: The Ultimate Android Security Research Tool. A unified TUI workspace and headless CLI for deep Android security research, built for researchers and hackers. Powered by Python orchestration and a Rust-accelerated core, enabling AI agent–driven hacking, credential recovery/cracking, APK analysis, intelligence gathering, runtime inspection.

Topics

Resources

Security policy

Stars

542 stars

Watchers

14 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages