LockKnife : The Ultimate Android Security Research Tool - Your Complete Android Security Research Arsenal! ποΈπ¬π Dive deep into Android security with this enterprise-grade command-line tool featuring advanced runtime analysis, SSL pinning bypass, comprehensive APK analysis, hardware security assessment, bootloader exploitation, and 20+ specialized modules. Recover lock screen credentials, perform dynamic behavior analysis, bypass security measures, analyze firmware, assess hardware security (TEE, keystores, biometrics), extract cloud backups, detect malware, scan vulnerabilities, and conduct professional forensic investigations. Connect your device and unleash the full power of Android security research! ππ«π
- Modular Architecture: Complete rewrite with modular components for better maintainability and extensibility
- Advanced Memory Analysis: Comprehensive memory dumping, analysis, and leak detection capabilities
- Kernel & SELinux Analysis: Deep kernel module analysis, SELinux policy inspection, and security feature assessment
- Cloud Backup Extraction: Extract data from Google Drive, Samsung Cloud, and other cloud services
- Malware Analysis: Built-in malware detection and analysis capabilities with YARA integration
- Vulnerability Scanning: Automated vulnerability assessment and security auditing
- Biometric Data Analysis: Extract and analyze fingerprint and facial recognition data
- System Service Analysis: Monitor and analyze Android system services and frameworks
- Firmware Analysis: Extract and analyze device firmware and bootloader information
- Enhanced Security Features: Improved encryption, secure deletion, and anonymous operation modes
- Performance Optimizations: Multi-threaded processing and optimized algorithms
- Extended App Support: Analysis for 15+ popular applications with specialized extraction tools
- Configuration Enhancements: Expanded configuration options for all new features
- Advanced Logging: Multi-format logging (txt, json, csv) with performance metrics
- Dependency Management: Improved dependency checking and installation
- Runtime Analysis Module: Comprehensive runtime monitoring with process analysis, dynamic behavior tracking, system call tracing, Frida integration, and anti-debugging detection
- SSL Pinning Bypass Module: Complete SSL pinning bypass capabilities with Frida scripts, certificate management, proxy configuration, and network interception tools
- Advanced APK Analysis Module: Static and dynamic APK analysis including manifest parsing, permission analysis, code decompilation, vulnerability scanning, malware detection, and signature verification
- Hardware Security Analysis Module: Deep hardware security assessment covering TEE analysis, hardware-backed keystores, secure elements, biometric hardware, cryptographic acceleration, and attack surface analysis
- Bootloader & Firmware Security Module: Bootloader status checking, vulnerability assessment, OEM unlock analysis, boot/recovery image analysis, and comprehensive security reporting
- Enhanced Menu System: Reorganized 20-option main menu with categorized features for better usability
- Modular Architecture Improvements: Better module loading system and renamed config.sh to config_manager.sh for clarity
- Advanced Frida Integration: Runtime instrumentation capabilities with SSL bypass, method hooking, and memory dumping
- System Integrity Verification: Rootkit detection, system integrity checks, and comprehensive security assessments
- π Password Recovery: Retrieve / Crack lock screen passwords (PIN, pattern, password) effortlessly.
- πΆ Wi-Fi Password Extraction: Easily recover saved Wi-Fi passwords from device.
- π± Multiple Android Versions Supported: Tailored options for different Android versions:
- Android 5 and Older
- Android 6 to 9
- Android 10+ and Newer Versions (Android 14)
- βοΈ Attack Methods:
- Dictionary Attack: Use custom wordlists to recover alphanumeric passwords.
- Brute Force: Try all possible combinations for 4, 6, or 8-digit PINs.
- Parallel Processing: Multi-core support for faster attacks.
- Pattern Recognition: Precomputed gesture pattern hash mapping.
- Gatekeeper Analysis: Extract and analyze modern credential storage.
- π Runtime Analysis:
- Process Monitoring: Real-time process analysis and memory mapping.
- Dynamic Behavior Tracking: Monitor app behavior and system calls.
- Frida Integration: Runtime instrumentation and hooking capabilities.
- Anti-Debugging Detection: Identify debugging and reverse engineering attempts.
- Memory Runtime Analysis: Live memory inspection and analysis.
- π SSL Pinning Bypass:
- Certificate Pinning Detection: Identify SSL pinning implementations.
- Frida SSL Bypass: Runtime SSL pinning bypass with Frida.
- Network Interception: MITM proxy setup and certificate management.
- Burp Suite Integration: Seamless Burp Suite proxy configuration.
- π± Advanced APK Analysis:
- Static Analysis: Manifest parsing, permission analysis, resource inspection.
- Code Analysis: DEX/SMALI decompilation and method signature analysis.
- Vulnerability Scanning: Automated security vulnerability detection.
- Malware Detection: Built-in malware scanning with signature analysis.
- Signature Verification: APK signature validation and certificate inspection.
- π§ Hardware Security Analysis:
- TEE Analysis: Trusted Execution Environment assessment and capabilities.
- Hardware-Backed Keystore: Secure key storage analysis and validation.
- Secure Element Analysis: eSE/UICC security evaluation.
- Biometric Hardware: Fingerprint/face recognition security assessment.
- Cryptographic Acceleration: Hardware crypto capabilities analysis.
- π© Bootloader & Firmware Security:
- Bootloader Assessment: Lock status, vulnerability scanning, OEM unlock analysis.
- Firmware Extraction: Partition dumping, boot image analysis, recovery inspection.
- Security Verification: Verified boot status and integrity checking.
- Unlock Capabilities: Bootloader unlocking procedures and safety checks.
- π Advanced Memory Analysis:
- Memory Dumping: Extract and analyze process memory contents.
- Memory Leak Detection: Identify memory leaks and excessive allocations.
- Heap Analysis: Analyze application heap for sensitive data.
- Stack Analysis: Examine stack memory for security vulnerabilities.
- π§ Kernel & SELinux Analysis:
- Kernel Module Analysis: Inspect loaded kernel modules for anomalies.
- SELinux Policy Analysis: Review security policies and contexts.
- Security Feature Assessment: Evaluate kernel hardening features.
- AVC Denial Monitoring: Track SELinux access vector cache denials.
- π Forensic Analysis:
- File System Snapshot: Capture device file system for offline analysis.
- App Data Analysis: Extract and analyze application data.
- Search Functionality: Find sensitive information in snapshots.
- SQLite Database Extraction: Pull and analyze databases.
- App-Specific Extraction: Specialized tools for popular apps:
- WhatsApp: Extract and analyze msgstore.db and contacts
- Telegram: Extract databases and MTProto traces
- Signal: Extract secure messaging data (requires root)
- Browsers: Extract history, cookies, and saved passwords from Chrome/Firefox/Brave/Edge
- NEW: Instagram, Facebook, Twitter, Snapchat, TikTok, and more
- βοΈ Cloud Backup Extraction:
- Google Drive: Extract synced data and backups.
- Samsung Cloud: Access Samsung account data.
- iCloud: Cross-platform cloud data analysis (when available).
- π¦ Malware Analysis:
- Malware Detection: Scan for suspicious applications and files.
- Behavior Analysis: Monitor app behavior for malicious activity.
- Signature Scanning: Check against known malware signatures.
- π Vulnerability Scanning:
- System Vulnerabilities: Scan for known Android security issues.
- App Vulnerabilities: Analyze installed apps for security flaws.
- Configuration Issues: Identify insecure system settings.
- π Biometric Data Analysis:
- Fingerprint Data: Extract fingerprint templates and metadata.
- Facial Recognition: Analyze face unlock data.
- Biometric Security: Assess biometric authentication strength.
- π Network Analysis:
- Traffic Capture: Record network traffic with tcpdump.
- Protocol Analysis: Analyze captured traffic for security issues.
- Unencrypted Traffic Detection: Identify potentially insecure communications.
- SSL/TLS Inspection: Examine encrypted communications.
- βοΈ System Service Analysis:
- Service Monitoring: Track Android system services.
- Intent Analysis: Analyze inter-process communications.
- Binder Analysis: Inspect Android's IPC mechanism.
- π± Device Security:
- Keystore Monitoring: Track keystore access attempts.
- Bluetooth Security: Extract and analyze pairing keys.
- Side-Channel Analysis: Monitor Gatekeeper responses.
- Firmware Analysis: Extract and analyze device firmware.
- βοΈ Interactive Prompts: User-friendly interface with interactive prompts for seamless recovery.
- π Automatic Device Connection: Uses ADB to automatically connect to device via USB or IP.
- ποΈ Decryption: Decrypts password files and displays recovered passwords.
- π Locksettings Analysis: Analyzes locksettings for lock screen credentials on newer Android versions.
- π Auto Updates: Automatically checks for updates and updates itself to ensure you have the latest version of LockKnife.
- π Security Assessment: Check device's Android version, security patch level, and root status.
- π Custom Data Extraction: Pull and analyze custom files or databases from device.
- π§ͺ Debug Mode: Advanced debugging capabilities for security researchers.
- π Secure File Handling: All sensitive files are handled securely and securely deleted when done.
- βοΈ Modular Architecture: Extensible plugin system for adding new features.
- π Enhanced Security: Encryption, secure deletion, and anonymous operation modes.
- π Performance Optimized: Multi-threaded processing and optimized algorithms.
- βοΈ Customizable Configuration: Configure tool behavior via configuration files or command-line options.
- macOS, Linux, Windows
- Bash-compatible environment
- Android Device with ADB (Android Debug Bridge) enabled
- Android SDK Platform-Tools installed and added to your system's PATH
- sqlite3 required for Android 10+ support and enhanced data extraction features
- GNU Parallel recommended for faster password cracking (optional)
- tshark recommended for network traffic analysis (optional)
- openssl required for encryption/decryption features
- ent or alternative entropy analysis tools (optional)
- yara recommended for advanced malware analysis (optional)
- Python 3.x with additional libraries for advanced analysis features (optional)
Memory Analysis:
- gdb/lldb for advanced debugging capabilities
- valgrind for memory leak detection
Kernel Analysis:
- Kernel headers for advanced kernel inspection
- SELinux policy analysis tools
Malware Analysis:
- ClamAV or similar antivirus engines
- YARA for pattern matching
- Volatility for memory forensics
Network Analysis:
- tcpdump for traffic capture
- Wireshark/tshark for protocol analysis
- nmap for network scanning
Cloud Analysis:
- rclone for cloud storage access
- API keys for various cloud services (Google Drive, etc.)
To use LockKnife : The Ultimate Android Security Research Tool, follow these steps:
-
Connect your Android device to your computer with USB debugging enabled.
-
Run the following command in your terminal:
bash -c "$(curl -fsSL https://raw.githubusercontent.com/ImKKingshuk/LockKnife/main/LockKnife.sh)"For advanced debugging and verbose output, use:
bash -c "$(curl -fsSL https://raw.githubusercontent.com/ImKKingshuk/LockKnife/main/LockKnife.sh)" -- --debugTo create a default configuration file:
bash -c "$(curl -fsSL https://raw.githubusercontent.com/ImKKingshuk/LockKnife/main/LockKnife.sh)" -- --create-config=~/.config/lockknife/lockknife.conf
Follow the on-screen prompts to select your device and choose the desired features.
LockKnife looks for configuration files in the following locations (in order):
./lockknife.conf(current directory)$HOME/.config/lockknife/lockknife.conf(user config directory)/etc/lockknife.conf(system-wide config)
You can also specify a custom config file using the --config=FILE command-line option.
LockKnife : The Ultimate Android Security Research Tool is developed for research and educational purposes. It should be used responsibly and in compliance with all applicable laws and regulations. The developer of this tool is not responsible for any misuse or illegal activities conducted with this tool.
Password recovery tools should only be used for legitimate purposes and with proper authorization. Using such tools without proper authorization is illegal and a violation of privacy. Ensure proper authorization before using LockKnife for password recovery or data extraction. Always adhere to ethical hacking practices and comply with all applicable laws and regulations.
This project is licensed under the GPL-3.0-or-later License.