Unified Android Security Research & Forensic Platform
Python First Rust Accelerated
Case-driven workflows, credential recovery, and advanced forensic modules.
Comprehensive Security Arsenal
From password recovery to AI-powered threat detection — LockKnife covers every aspect of Android security research.
Multiple Attack Vectors
Recover lock screen credentials with gesture patterns, dictionary attacks, and brute force methods.
WhatsApp • Telegram • Signal • Browser Saved Logins
Rust-Accelerated SQLite Correlation • Artifact Registry
ML Malware Detection • Anomaly AI
Real-time CTI feeds, IOC detection, app reputation
Profile isolation & data extraction
Executive • Technical • Compliance
Comprehensive Compatibility
From legacy devices to the latest Android 16 — LockKnife adapts to each version's security model.
Legacy Support
Mainstream Surface
Modern Hardening
Experimental/Bleeding Edge
Next-Gen Ready
LockKnife supports all major ARMv8 and ARMv9 mobile chipsets including Qualcomm Snapdragon, Samsung Exynos, MediaTek Dimensity, and Google Tensor processors.
Simple & Powerful
Three simple steps to unlock powerful Android security research.
Start a new investigation by initializing a case workspace. LockKnife tracks evidence lineage and integrity across the entire lifecycle.
Launch the TUI and select from 20+ specialized modules for credential recovery, extraction, and AI-powered analysis.
Execute your analysis and automatically register outputs into the case manifest. Export professional technical or executive reports.
Comprehensive Modules
From password recovery to professional reporting — every tool you need.
Default full-screen operator workspace for cases
Secondary interface for automation and scripting
Deep data capture and artifact reconstruction
ML Malware detection and threat feed enrichment
Professional multi-format forensic generation
Default full-screen operator workspace for cases
Secondary interface for automation and scripting
Deep data capture and artifact reconstruction
ML Malware detection and threat feed enrichment
Professional multi-format forensic generation
Product Evaluation
Superior performance, deeper extraction, and modern Android support that leaves traditional tools behind.
| Feature Matrix | Recommended LockKnife | Others |
|---|---|---|
Core Forensic Capabilities | ||
Full Disk Encryption (FBE) Analysis | ||
Credential Manager Vault Extraction | ||
SQLite Database Pattern Matching | ||
Timeline Reconstruction (Artifact Reg) | ||
Modern Android Support | ||
Android 15 Private Space Analysis | ||
Passkey & FIDO2 Artifact Discovery | ||
Quantum-Ready Forensic Primitives | ||
Performance & Intelligence | ||
Rust-Accelerated Extraction Core | ||
AI/ML Anomaly & Malware Detection | ||
Integrated CTI Feeds (IOC Search) | ||
What's Next
LockKnife is constantly evolving with new security research capabilities.
Successfully migrated from shell-reliant scripts to a Python orchestration layer with Rust performance primitives.
Developing a native SDK for community-driven artifact parsers and custom forensic logic modules.
Integrating live device telemetry and process monitoring directly into the investigation workspace.
Got Questions?
Everything you need to know about LockKnife.