Unified Android Security Research & Forensic Platform. Python orchestration meets Rust-accelerated core. Case-driven workflows, credential recovery, and advanced forensic modules.
// ARSENAL_OVERVIEW
From native Rust-accelerated SQLite carving and FIDO2 passkeys to Verified Boot AVB 2.0 posture and multi-chain crypto forensics — LockKnife gives operators complete visibility with 15 production-ready engines.
Multi-Vector Bruteforce Engine
Python orchestration seamlessly bridging to a 100x Rust-accelerated FFI core.
WhatsApp, WA Business, Signal (SQLCipher), Telegram, Browser Saved Logins. Bulk SQLite parsing.
Android 15+ profile isolation detection and volume extraction.
// UNIVERSAL_ARCHITECTURE
LockKnife bypasses version fragmentation, providing low-level hardware access and kernel-level hooks across the entire Android ecosystem.
Android 5.0 through 16+
ARMv8 • ARMv9 • AArch64
Bypass standard API limitations. LockKnife interfaces directly with the Android kernel, secure enclaves, and low-level block devices for absolute extraction capability.
// INVESTIGATION_LIFECYCLE
LockKnife treats every extraction as a structured cryptographic case, maintaining unbroken chain-of-custody from initialization to final report.
Initialize a cryptographically sound case directory. LockKnife establishes local SQL databases to track evidence lineage, integrity hashes, and operation history.
Launch the interactive TUI workspace or orchestrate headless pipelines. Link your target device and extract messaging, crypto wallets, and system security posture.
Correlate extracted SQLite artifacts into normalized timelines. Generate professional HTML/JSON/CSV reports complete with SHA-256 integrity proofs.
// SYSTEM_COMPONENTS
From Verified Boot and hardware TEE posture to native SQLite carving, passkeys, and multi-chain crypto recovery — LockKnife gives you an integrated engine built for high-stakes investigations.
Verified Boot AVB 2.0, TEE attestation, SELinux & port scoring
Native SQLite B-Tree deleted record carving & ALEAPP normalizer
Rust multi-threaded PIN/password cracking & FIDO2 passkey recovery
Multi-user CE/DE paths, GNSS satellite metadata & private messaging
Tamper-evident SQLite vaults, artifact manifests & SHA-256 custody
Multi-chain address carving (ETH/BTC/SOL/TRX) & BIP-39 mnemonic seeds
// CAPABILITY_AUDIT
Live forensic capability inventory across 32 subsystems, verified against LockKnife v1.3.0. Filter by operational maturity, review CLI invocation, and inspect host requirements.
lockknife --cli featuresStable automation and scripting surface.
lockknife --cli[COPY]Primary operator interface; requires the native extension.
lockknife[COPY]Device visibility depends on host ADB and device authorization.
lockknife device ...[COPY]Rust-powered offline workflows.
lockknife crack pin|password|password-rules[COPY]Hardened credential extraction with modern APEX / multi-user paths, root staging, and synthetic password diagnostics.
lockknife crack pin-device|gesture|wifi[COPY]Structured passkey SQLite parsing (FIDO2, Android 14+ Credential Provider, Chromium Web Data) and Keystore 2.0 APEX inventory.
lockknife crack keystore|passkeys[COPY]Broad coverage with multi-user CE/DE paths, root staging, and ContentProvider fallback.
lockknife extract sms|contacts|call-logs|browser|media|location[COPY]Modern WhatsApp 'message' table, WhatsApp Business, Signal SQLCipher passphrase recovery, and Telegram metadata.
lockknife extract messaging[COPY]Core offline investigation flows are solid.
lockknife forensics sqlite|timeline|correlate[COPY]Case workspaces, lineage graphs, artifact manifest, and resumable/retryable job execution.
lockknife case ...[COPY]Native SQLite B-Tree deleted record carving and freeblock reconstruction with string fragment analysis.
lockknife forensics recover|carve[COPY]Privileged device archive snapshot workflows with integrity metadata.
lockknife forensics snapshot[COPY]Universal multi-format normalization engine supporting JSON and CSV artifacts across ALEAPP categories.
lockknife forensics parse[COPY]Case-aware multi-format reporting with workspace inventory, integrity summaries, and evidence aggregation.
lockknife report generate[COPY]Requires an installed PDF backend.
lockknife report generate --format pdf[COPY]Derives audit-ready evidence custody trails directly from managed case manifests and artifact lineage.
lockknife report chain-of-custody[COPY]Cryptographically verifies artifact SHA-256 hashes inside managed case workspaces and flags discrepancies.
lockknife report integrity[COPY]Static triage is now materially stronger with component, signing, code-signal, and transparent risk outputs, but it is still below full MobSF/Androguard replacement depth.
lockknife apk permissions|analyze|vulnerability[COPY]Structured stage reporting and better decompile posture now exist, but full source-recovery depth still depends on external tooling.
lockknife apk decompile[COPY]Local scanning is available today.
lockknife apk scan[COPY]Useful helpers exist, but session ergonomics need more work.
lockknife runtime ...[COPY]Highly target- and environment-dependent.
lockknife runtime bypass-ssl|bypass-root|trace|memory-search|heap-dump[COPY]Deep security posture engines: Verified Boot chain & AVB analysis, TEE/attestation/biometric assessment, network exposure scoring with port risk classification, gatekeeper, lockscreen, and Play Protect auditing.
lockknife security scan|selinux|bootloader|hardware|network-scan[COPY]Pattern scanning is available without optional YARA extras.
lockknife security malware[COPY]Good helper for mapping existing findings to MASTG categories.
lockknife security owasp[COPY]Installed package and configured credentials both required.
lockknife intel virustotal|reputation[COPY]Coverage is broad, with some feeds/queries gated by external services.
lockknife intel ioc|cve|stix|taxii[COPY]Useful workflow once scapy is installed.
lockknife network analyze|api-discovery[COPY]Capture depends heavily on device privileges and tooling.
lockknife network capture[COPY]Optional triage workflows, not authoritative findings.
lockknife ai anomaly|train-malware|classify-malware[COPY]Useful assistive workflow, not guaranteed recovery.
lockknife ai predict-password[COPY]Multi-chain address carving (ETH, BTC bech32/legacy, SOL, TRX), BIP-39 mnemonic seed recovery, Web3 keystores, and on-device mobile wallet vault discovery.
lockknife crypto-wallet wallet|scan-device[COPY]// PRODUCT_EVALUATION
Superior performance, deeper extraction, and modern Android support that leaves traditional tools behind.
| Feature Matrix | [RECOMMENDED] LockKnife | Legacy Tools |
|---|---|---|
Core Forensic Capabilities | ||
Verified Boot & AVB 2.0 Audit | Supported | |
Native SQLite B-Tree Deleted Record Carving | Supported | |
Case Lineage & Cryptographic Hash Custody | Supported | |
Isolated Root Staging & Content Fallback | Supported | |
Modern Android Support | ||
Android 15+ Private Space Analysis | Supported | |
Passkey & FIDO2 Artifact Discovery | Supported | |
Hardware TEE & Keymaster Auditing | Supported | |
Performance & Intelligence | ||
Rust-Accelerated Native Core | Supported | |
Multi-Chain Crypto Forensics | Supported | |
Integrated CTI & CVE Correlation | Supported | |
// DEVELOPMENT_PHASES
LockKnife is constantly evolving with new security research capabilities to match the pace of Android platform updates.
Tamper-evident SQLite case workspaces, artifact manifest lineage tracking, cryptographic SHA-256 integrity verification, and Bluetooth dry-run execution safety.
Full Verified Boot chain & AVB 2.0 analysis, TEE vendor & attestation posture, native SQLite deleted record carving, network exposure scoring, and isolated root staging.
Autonomous multi-stage extraction chains, extended Android 16+ kernel exploit audit, and live device telemetry visualization.
Check our experimental branch on GitHub to help shape the future of Android security research.
// QUERY_DATABASE
Everything you need to know about LockKnife operation, legality, and requirements.