Android security research · Digital forensics · APK reverse engineering
Collect evidence, investigate applications, and deliver clear reports from one terminal workspace.
Features / Installation / Quick Start / User Guides / Website
LockKnife is an open-source Android security research and digital forensics toolkit for security researchers, forensic analysts, and mobile penetration testers. Bring device extraction, offline evidence analysis, APK reverse engineering, Frida instrumentation, network forensics, and reporting into a single investigation.
Work interactively in a full-screen terminal interface or use focused CLI commands. Keep related outputs in a case, trace findings back to their inputs, and turn evidence into technical or executive reports.
| One case. Connected evidence. Artifacts, analysis, sessions, and reports together. |
Your workflow. Your interface. Interactive terminal or repeatable CLI commands. |
Device or offline. Collect from Android or inspect existing evidence. |
|
Acquire accessible messages, contacts, call logs, browser records, media, and location artifacts. Explore supported WhatsApp, Telegram, and Signal data. Device acquisition · App artifacts · Batch extraction |
Inspect SQLite databases, build timelines, correlate identifiers, import ALEAPP results, and review record-recovery candidates alongside their source evidence. Offline forensics · Timelines · Artifact correlation |
|
Review manifests, permissions, and exported components. Decompile APKs with JADX or apktool, inspect DEX metadata, and scan application contents with YARA rules. APK analysis · Reverse engineering · YARA scanning |
Use Frida hooks, method tracing, memory searches, and case-linked sessions. Test supported SSL-pinning and root-detection hooks on authorized targets. Runtime instrumentation · Memory inspection · Frida |
|
Inspect PCAPs, discover visible API endpoints, capture device traffic, and review device security indicators. Enrich selected findings with VirusTotal or OTX. Network forensics · Device security · Threat intelligence |
Follow artifact lineage, verify registered hashes and audit records, create technical or executive reports, and export case bundles for protected handoff. Evidence provenance · Integrity checks · Reporting |
Also included: supported legacy PIN/password recovery, credential-artifact inspection, wallet forensics, optional log anomaly scoring, and Bluetooth, Wi-Fi, and TCP discovery or protocol tools. Rust-powered hashing, recovery, and native analysis helpers support demanding tasks.
Note
Investigation examples use dummy identifiers and file paths, not real devices or evidence. Replace EXAMPLE_* values, com.example.placeholder, and example input paths with your authorized inputs before running a command. Installation links point to the actual project.
Android extraction and offline forensics / See command examples
Create a case first, replace EXAMPLE_DEVICE_SERIAL with your authorized device's serial, and substitute the input paths with your evidence files.
lockknife --cli extract browser --serial EXAMPLE_DEVICE_SERIAL --app chrome --kind history --case-dir ./cases/EXAMPLE_CASE
lockknife --cli extract messaging --serial EXAMPLE_DEVICE_SERIAL --app whatsapp --case-dir ./cases/EXAMPLE_CASE
lockknife --cli forensics sqlite ./example-evidence/messages.db --case-dir ./cases/EXAMPLE_CASE
lockknife --cli forensics correlate --input ./example-evidence/artifacts.json --case-dir ./cases/EXAMPLE_CASEAcquisition depends on permissions, app versions, and encryption. Protected paths may require root; collecting an encrypted database does not decrypt its messages. Carved records are recovery candidates, not automatic proof of deletion.
APK analysis and reverse engineering / Modes and examples
| Mode | What You Get |
|---|---|
auto |
JADX, then apktool, then archive unpacking as fallbacks |
jadx |
Reconstructed Java-like source |
apktool |
Decoded resources, manifest, and Smali |
unpack |
Raw application files |
hybrid |
Combined JADX and apktool output |
lockknife --cli apk decompile ./example-app.apk --mode auto --output ./example-decompiled
lockknife --cli apk scan --apk ./example-app.apk --yara ./example-rules/example.yarAutomated security findings require review. Archive unpacking is not source-code reconstruction.
Frida runtime instrumentation / Hooks and memory inspection
lockknife --cli runtime bypass-ssl com.example.placeholder --device-id EXAMPLE_DEVICE_SERIAL --case-dir ./cases/EXAMPLE_CASE
lockknife --cli runtime memory-search com.example.placeholder --device-id EXAMPLE_DEVICE_SERIAL --pattern "EXAMPLE_SEARCH_TEXT"Frida requires a compatible target server and sufficient permissions. Built-in hooks depend on the app implementation and can change its behavior. Explicitly stop active sessions when your work is complete.
Network forensics and device security / Capture analysis and posture checks
lockknife --cli network api-discovery ./example-evidence/capture.pcap --case-dir ./cases/EXAMPLE_CASE
lockknife --cli security scan --serial EXAMPLE_DEVICE_SERIALDevice capture requires accessible on-device tcpdump. Encrypted traffic may conceal endpoints and payloads; reported device properties do not independently establish hardware security.
Credential recovery and wallet forensics / Supported evidence workflows
lockknife --cli crack pin --hash EXAMPLE_SHA1_HASH --algo sha1 --length 4
lockknife --cli crypto-wallet scan-device --serial EXAMPLE_DEVICE_SERIAL --case-dir ./cases/EXAMPLE_CASEEXAMPLE_SHA1_HASH is a placeholder, not a usable hash. Replace it with the 40-character hexadecimal SHA-1 value you are authorized to test. Credential tools support specific legacy hashes and accessible artifacts; they do not guarantee recovery of modern Android screen locks or hardware-backed private keys. Wallet workflows depend on the supported app format and available data.
Important
Use device-changing and wireless workflows only within your authorized scope. Check lockknife --cli features for requirements and capability status; PoC, simulated, or unavailable functions are not verified live exploits.
| macOS | Linux | Windows |
|---|---|---|
| Homebrew or installer | One-line installer | Scoop |
| Apple Silicon / ARM64 | x86-64 or ARM64 | x86-64 |
Homebrew · macOS
brew install ImKKingshuk/tap/lockknifeOne-line installer · macOS and Linux
curl -fsSL https://lockknife.vercel.app/install | bashScoop · Windows
With Scoop installed:
scoop bucket add imkkingshuk https://github.com/ImKKingshuk/scoop-bucket
scoop install imkkingshuk/lockknifePrefer a Python environment? / Install a prebuilt wheel
Download the matching wheel from GitHub Releases. Use Python 3.12 or newer:
python -m pip install /path/to/EXAMPLE_WHEEL.whlChoose a wheel matching the operating system and architecture listed above.
/path/to/EXAMPLE_WHEEL.whl is a dummy path. Replace it with the full path and filename of the wheel you downloaded.
Optional features / Dependencies and setup
For wheel installations, select the extras you need:
python -m pip install '/path/to/EXAMPLE_WHEEL.whl[apk,network]'
python -m pip install '/path/to/EXAMPLE_WHEEL.whl[full]'| Extra | Enables |
|---|---|
apk |
APK analysis |
frida |
Runtime instrumentation |
network |
Extended PCAP analysis |
yara |
YARA rule scanning |
threat-intel |
VirusTotal and OTX clients |
ml |
Machine-learning analysis helpers |
full |
All investigation extras above |
External tools still apply: JADX/apktool for decompilation, a target Frida server for instrumentation, and device tcpdump for capture. PDF rendering and Bleak are separate dependencies, not included in full. Install optional Python dependencies in the environment containing LockKnife, not an unrelated system Python.
Device work requires Android platform-tools (adb) and device authorization. Offline analysis does not require a connected device. See Installation and Troubleshooting for updates and setup help.
|
Browse devices and modules, fill in action forms, and review results in a full-screen terminal.
|
Run individual tasks, repeat an investigation workflow, or analyze evidence without opening the TUI.
|
flowchart LR
A[Collect] --> B[Analyze]
B --> C[Verify]
C --> D[Report]
classDef collect fill:#dafbe1,stroke:#1a7f37,color:#116329
classDef analyze fill:#ddf4ff,stroke:#0969da,color:#0550ae
classDef verify fill:#fff8c5,stroke:#9a6700,color:#633c01
classDef report fill:#f6f8fa,stroke:#57606a,color:#24292f
class A collect
class B analyze
class C verify
class D report
Start with device or local evidence, inspect artifacts and applications, verify registered hashes and case events, then share reviewed findings.
1. Check your installation and authorized device.
lockknife --version
lockknife --cli doctor
lockknife --cli device listReplace EXAMPLE_DEVICE_SERIAL with a serial returned by device list. The examples use ./cases/EXAMPLE_CASE; choose private storage for actual case data.
2. Create a case and collect accessible evidence.
lockknife --cli case init --case-id EXAMPLE_CASE --examiner "EXAMPLE_EXAMINER" --title "Example Android Assessment" --output ./cases/EXAMPLE_CASE
lockknife --cli device info --serial EXAMPLE_DEVICE_SERIAL
lockknife --cli extract sms --serial EXAMPLE_DEVICE_SERIAL --format json --case-dir ./cases/EXAMPLE_CASE
lockknife --cli extract call-logs --serial EXAMPLE_DEVICE_SERIAL --format json --case-dir ./cases/EXAMPLE_CASE3. Review, verify, and report.
lockknife --cli case summary --case-dir ./cases/EXAMPLE_CASE
lockknife --cli report integrity --case-dir ./cases/EXAMPLE_CASE --format json
lockknife --cli report generate --case-dir ./cases/EXAMPLE_CASE --template technical --format html
lockknife --cli case export --case-dir ./cases/EXAMPLE_CASE --include-registered-artifacts --output ./example-case-bundle.zipUse the output paths printed by each command. HTML reports are available with the base installation; PDF requires an optional renderer. Reports and bundles are not encrypted by default, so review and protect them before sharing.
Explore more commands / Help, capabilities, and classic menus
lockknife --cli --help
lockknife --cli features
lockknife --cli actions --format jsonUse --help on an individual command to see its options. Prefer numbered menus? Run lockknife --cli interactive and follow the classic menu guide.
| Get Started | Investigate | Protect and Share |
|---|---|---|
| Installation and troubleshooting | Interactive TUI walkthrough | Case integrity and privacy |
| Classic menu guide | CLI investigation walkthrough | Security and privacy |
Follow release notes in the changelog to see what's changed between versions.
Do I need root or a connected Android device?
Not for offline analysis or case review. You can inspect local SQLite databases, APKs, PCAP files, and supported exported artifacts. Device-backed operations need a connection; protected app and system paths often need elevated access.
Can LockKnife unlock every Android device?
No. Credential recovery supports specific hashes and accessible artifacts. Modern hardware-backed credentials, encryption, and device protections cannot be assumed recoverable or bypassable.
Why does a feature need additional setup?
Some workflows need optional dependencies, external tools, provider credentials, or target permissions. Run lockknife --cli doctor and lockknife --cli features to check requirements before starting.
Are my investigation results sent to external services?
Local analysis does not require threat intelligence services. Explicit external lookups send selected indicators to their providers. Review your data-sharing policy and the case privacy guide before using those integrations.
Authorized research. Responsible evidence handling.
Use LockKnife only on devices, applications, and networks you are authorized to examine. Follow applicable laws and protect collected personal data.