LockKnife
LockKnife
>// FEATURES>// PLATFORMS>// WORKFLOW>// MODULES>// MATRIX>// CHANGELOG
[ SRC ]
LockKnife
LockKnife

The Ultimate Android Security Research Tool. Password Recovery. Forensics. AI Analysis. Open Source.

Product

  • Features
  • Platforms
  • How It Works
  • Modules
  • Feature Matrix
  • Comparison
  • Roadmap
  • FAQ

Resources

  • GitHub
  • Releases
  • Issues
  • License

Developer

  • Github
  • Twitter/X

© 2026 LockKnife. Licensed under GPLv3.

Designed & Developed with by @ImKKingshuk

INITIALIZING_

AndroidSecurityResearch

Unified Android Security Research & Forensic Platform. Python orchestration meets Rust-accelerated core. Case-driven workflows, credential recovery, and advanced forensic modules.

Rust Core
Python CLI
Forensics
lockknife[SYSTEM_SECURE]
Target Acquired
IP: 192.0.2.x
ID: pixel-9-pro_v15
STATUS: CONNECTED
Active Case
CASE: CASE-001
[x] verified_boot_audit
RUNNING: sqlite_carve
[10:42:01] Rust core & AES-GCM primitives... OK
[10:42:01] Verified Boot: AVB 2.0 (dm-verity ENFORCED)
[10:42:02] Hardware TEE: Trusty / QSEE Attestation OK
[10:42:03] Extracting keystore & FIDO2 passkeys:
-> credential: passkey.google.com [FIDO2]
-> keymaster: hardware_backed_0x4f
[10:42:04] Case workspace: ./cases/CASE-001 locked.
[10:42:05] Bounded SQLite carving: 0 cell duplicates
[10:42:05] Rust PIN brute-force active (18.5k/s)
Cracking:█▓▒░

// ARSENAL_OVERVIEW

32 CAPABILITIES.
12 INTEGRATED MODULES.

From native Rust-accelerated SQLite carving and FIDO2 passkeys to Verified Boot AVB 2.0 posture and multi-chain crypto forensics — LockKnife gives operators complete visibility with 15 production-ready engines.

Password Recovery

Multi-Vector Bruteforce Engine

MOD_ID: LK-CRD
STATUS: PROD_READY
PIN Cracking [Rust] 18.5k/s
KEYS: 4,321,09884%
Gesture BypassREADY
PATTERN: L-SHAPE DETECTED

Hybrid Core

Python orchestration seamlessly bridging to a 100x Rust-accelerated FFI core.

Python [Orchestrator]
CLIWorkflowsReporting
Rust [Accelerator]
CryptoBruteforceSQLite

Data Extraction

WhatsApp, WA Business, Signal (SQLCipher), Telegram, Browser Saved Logins. Bulk SQLite parsing.

PasskeysAndroid 14+

Crypto Forensics

BTCETHSOLTRXMetaMask
Seed Phrase ExtractorRUNNING...
alpha
orbit
galaxy
shield
derive
[CRACK]
****
****
****
Ledger Intel
0x4b2a...9f1e+1.42 ETH
0x91cd...2b8a-0.05 BTC

Threat Intel

VirusTotal[OK]
AlienVault OTX[OK]
CVE Scanning[RUN]

Network / PCAP

[SSL]api.target/auth
[WSS]wss://chat.local
[TCP]192.0.2.x:443

Private Space

Android 15+ profile isolation detection and volume extraction.

Isolated Vol Mount
Open Source
GPLv3 / No Telemetry
Reporting & Integrity
PDF, HTML, JSON, Chain of Custody & SHA-256 Audit
Runtime Inst.
Frida Hooks & Mem Editing

// UNIVERSAL_ARCHITECTURE

BUILT FOR
EVERY LAYER.

LockKnife bypasses version fragmentation, providing low-level hardware access and kernel-level hooks across the entire Android ecosystem.

OS Support

Android 5.0 through 16+

TARGET: OS_LEVEL
INTEGRITY: COMPROMISED
V1
Legacy
Android 5-9
[Auth Bypass]
V2
Modern
Android 10-13
[FBE Decrypt]
V3
Hardened
Android 14-15
[MTE Isolation]
V4
Next-Gen
Android 16+
[Sandboxing]

Silicon Arch

ARMv8 • ARMv9 • AArch64

Snapdragon[VULNERABLE]
Tensor[EXPLOITED]
Exynos[BYPASSED]
Dimensity[ANALYZING...]

System-Level Integration

Bypass standard API limitations. LockKnife interfaces directly with the Android kernel, secure enclaves, and low-level block devices for absolute extraction capability.

TEE ExploitationBlock-Level ImagingKernel HooksSELinux Bypass

// INVESTIGATION_LIFECYCLE

SEAMLESS
ORCHESTRATION.

LockKnife treats every extraction as a structured cryptographic case, maintaining unbroken chain-of-custody from initialization to final report.

Init Workspace

Initialize a cryptographically sound case directory. LockKnife establishes local SQL databases to track evidence lineage, integrity hashes, and operation history.

$ lockknife case init ./cases/CASE-001 --case-id CASE-001
01
02

Execute Modules

Launch the interactive TUI workspace or orchestrate headless pipelines. Link your target device and extract messaging, crypto wallets, and system security posture.

Verified Boot
SQLite Carving
Crypto Vaults
Rust Brute

Export Evidence

Correlate extracted SQLite artifacts into normalized timelines. Generate professional HTML/JSON/CSV reports complete with SHA-256 integrity proofs.

$ lockknife report generate ./cases/CASE-001 --format html
SHA256 SignedCourt Ready
03

// SYSTEM_COMPONENTS

CORE MODULES.
COMPLETE COVERAGE.

From Verified Boot and hardware TEE posture to native SQLite carving, passkeys, and multi-chain crypto recovery — LockKnife gives you an integrated engine built for high-stakes investigations.

[PROCESS_MONITOR]UPTIME: 99.9%

Security Posture

PROD_READY
MOD_SEC_01

Verified Boot AVB 2.0, TEE attestation, SELinux & port scoring

AVB / dm-verityTEE AttestationPort Risk Engine

Forensics & Recovery

PROD_READY
MOD_FRX_02

Native SQLite B-Tree deleted record carving & ALEAPP normalizer

Zero Duplicate CarvingFreelist ReconstructTimeline Engine

Credentials & Passkeys

PROD_READY
MOD_CRD_03

Rust multi-threaded PIN/password cracking & FIDO2 passkey recovery

Passkeys SQLiteKeystore 2.0Rayon Brute-force

Deep Extraction

PROD_READY
MOD_EXT_04

Multi-user CE/DE paths, GNSS satellite metadata & private messaging

WhatsApp / Signal / TGGNSS Raw DataSafe Root Staging

Case Workspaces

PROD_READY
MOD_CAS_05

Tamper-evident SQLite vaults, artifact manifests & SHA-256 custody

Lineage GraphResumable JobsCourt-Ready Hash Audit

Crypto Forensics

PROD_READY
MOD_CRY_06

Multi-chain address carving (ETH/BTC/SOL/TRX) & BIP-39 mnemonic seeds

BIP-39 MnemonicWeb3 KeystoresMobile Vault Discovery
[TELEMETRY]
Core Usage
CPU84%
MEM62%
IO91%
Data Stream
> AVB 2.0 chain verified
> TEE Keymaster 4.1 ready
> Case: ./cases/CASE-001
> SQLite B-tree carving
> 0 duplicate live cells
> 3 FIDO2 passkeys mapped
> GNSS raw metadata parsed
> Hash integrity audit: OK

// CAPABILITY_AUDIT

FEATURE MATURITY
MATRIX.

Live forensic capability inventory across 32 subsystems, verified against LockKnife v1.3.0. Filter by operational maturity, review CLI invocation, and inspect host requirements.

32 CAPABILITIES
|
[PROD_READY: 15]
[FUNCTIONAL: 7]
[GATED: 7]
[BEST_EFFORT: 3]
CLI query:lockknife --cli features
corePROD_READY

CLI + orchestration

Stable automation and scripting surface.

REQ:base install
lockknife --cli[COPY]
coreFUNCTIONAL

Default TUI

Primary operator interface; requires the native extension.

REQ:Rust extension
lockknife[COPY]
deviceFUNCTIONAL

ADB management

Device visibility depends on host ADB and device authorization.

REQ:adb
lockknife device ...[COPY]
credentialsPROD_READY

Offline PIN/password cracking

Rust-powered offline workflows.

REQ:Rust extension
lockknife crack pin|password|password-rules[COPY]
credentialsPROD_READY

Device-side credential recovery

Hardened credential extraction with modern APEX / multi-user paths, root staging, and synthetic password diagnostics.

REQ:adb + device access
lockknife crack pin-device|gesture|wifi[COPY]
credentialsPROD_READY

Keystore / passkey artifact export

Structured passkey SQLite parsing (FIDO2, Android 14+ Credential Provider, Chromium Web Data) and Keystore 2.0 APEX inventory.

REQ:adb + device access
lockknife crack keystore|passkeys[COPY]
extractionPROD_READY

Primary artifacts

Broad coverage with multi-user CE/DE paths, root staging, and ContentProvider fallback.

REQ:adb + device access
lockknife extract sms|contacts|call-logs|browser|media|location[COPY]
extractionPROD_READY

Messaging artifacts

Modern WhatsApp 'message' table, WhatsApp Business, Signal SQLCipher passphrase recovery, and Telegram metadata.

REQ:adb + app access
lockknife extract messaging[COPY]
forensicsPROD_READY

SQLite analysis / timeline / correlation

Core offline investigation flows are solid.

REQ:local files
lockknife forensics sqlite|timeline|correlate[COPY]
casePROD_READY

Case workspaces & job orchestration

Case workspaces, lineage graphs, artifact manifest, and resumable/retryable job execution.

REQ:base install
lockknife case ...[COPY]
forensicsPROD_READY

SQLite deleted record recovery & carving

Native SQLite B-Tree deleted record carving and freeblock reconstruction with string fragment analysis.

REQ:Rust extension or base install
lockknife forensics recover|carve[COPY]
forensicsFUNCTIONAL

Device snapshots

Privileged device archive snapshot workflows with integrity metadata.

REQ:adb + root
lockknife forensics snapshot[COPY]
forensicsPROD_READY

ALEAPP-style parsing

Universal multi-format normalization engine supporting JSON and CSV artifacts across ALEAPP categories.

REQ:local evidence directory
lockknife forensics parse[COPY]
reportingPROD_READY

HTML/JSON/CSV reporting

Case-aware multi-format reporting with workspace inventory, integrity summaries, and evidence aggregation.

REQ:base install
lockknife report generate[COPY]
reportingGATED_EXTRAS

PDF reporting

Requires an installed PDF backend.

REQ:weasyprint or xhtml2pdf
lockknife report generate --format pdf[COPY]
reportingPROD_READY

Chain of custody

Derives audit-ready evidence custody trails directly from managed case manifests and artifact lineage.

REQ:base install
lockknife report chain-of-custody[COPY]
reportingPROD_READY

Case integrity verification

Cryptographically verifies artifact SHA-256 hashes inside managed case workspaces and flags discrepancies.

REQ:base install
lockknife report integrity[COPY]
apkGATED_EXTRAS

APK permissions / manifest / heuristics

Static triage is now materially stronger with component, signing, code-signal, and transparent risk outputs, but it is still below full MobSF/Androguard replacement depth.

REQ:lockknife[apk]
lockknife apk permissions|analyze|vulnerability[COPY]
apkBEST_EFFORT

APK unpack / decompile workflow

Structured stage reporting and better decompile posture now exist, but full source-recovery depth still depends on external tooling.

REQ:lockknife[apk]
lockknife apk decompile[COPY]
apkFUNCTIONAL

YARA / pattern scanning

Local scanning is available today.

REQ:Rust extension; optional yara fallback
lockknife apk scan[COPY]
runtimeGATED_EXTRAS

Frida runtime instrumentation

Useful helpers exist, but session ergonomics need more work.

REQ:lockknife[frida] + Frida server
lockknife runtime ...[COPY]
runtimeBEST_EFFORT

Bypass / trace / memory workflows

Highly target- and environment-dependent.

REQ:lockknife[frida] + compatible target
lockknife runtime bypass-ssl|bypass-root|trace|memory-search|heap-dump[COPY]
securityPROD_READY

Device posture / SELinux / bootloader / hardware

Deep security posture engines: Verified Boot chain & AVB analysis, TEE/attestation/biometric assessment, network exposure scoring with port risk classification, gatekeeper, lockscreen, and Play Protect auditing.

REQ:adb + device access
lockknife security scan|selinux|bootloader|hardware|network-scan[COPY]
securityFUNCTIONAL

Malware scanning

Pattern scanning is available without optional YARA extras.

REQ:Rust extension; optional yara fallback
lockknife security malware[COPY]
securityFUNCTIONAL

OWASP mapping

Good helper for mapping existing findings to MASTG categories.

REQ:input artifacts
lockknife security owasp[COPY]
intelGATED_EXTRAS

VirusTotal / OTX reputation

Installed package and configured credentials both required.

REQ:lockknife[threat-intel] + API keys
lockknife intel virustotal|reputation[COPY]
intelFUNCTIONAL

IOC / CVE / STIX / TAXII

Coverage is broad, with some feeds/queries gated by external services.

REQ:some commands require threat-intel extras
lockknife intel ioc|cve|stix|taxii[COPY]
networkGATED_EXTRAS

PCAP analysis / API discovery

Useful workflow once scapy is installed.

REQ:lockknife[network]
lockknife network analyze|api-discovery[COPY]
networkBEST_EFFORT

Device capture

Capture depends heavily on device privileges and tooling.

REQ:lockknife[network] + root + tcpdump
lockknife network capture[COPY]
aiGATED_EXTRAS

Anomaly / classifier workflows

Optional triage workflows, not authoritative findings.

REQ:lockknife[ml]
lockknife ai anomaly|train-malware|classify-malware[COPY]
aiGATED_EXTRAS

Password prediction

Useful assistive workflow, not guaranteed recovery.

REQ:lockknife[ml]
lockknife ai predict-password[COPY]
crypto-walletPROD_READY

Wallet artifact parsing & device vault discovery

Multi-chain address carving (ETH, BTC bech32/legacy, SOL, TRX), BIP-39 mnemonic seed recovery, Web3 keystores, and on-device mobile wallet vault discovery.

REQ:local wallet DB / adb device
lockknife crypto-wallet wallet|scan-device[COPY]

// PRODUCT_EVALUATION

WHY PROFESSIONALS
CHOOSE LOCKKNIFE.

Superior performance, deeper extraction, and modern Android support that leaves traditional tools behind.

Feature Matrix
[RECOMMENDED]
LockKnife
Legacy Tools
Core Forensic Capabilities
Verified Boot & AVB 2.0 Audit

> dm-verity state, boot partition hash & anti-rollback indexing

Supported
Native SQLite B-Tree Deleted Record Carving

> Bounded freelist carving without active cell duplicates

Supported
Case Lineage & Cryptographic Hash Custody

> Tamper-evident SHA-256 artifact verification & lineage graph

Supported
Isolated Root Staging & Content Fallback

> Zero /sdcard data leaks; direct stream pull with safe fallback

Supported
Modern Android Support
Android 15+ Private Space Analysis

> Profile isolation, multi-user CE/DE & sandbox auditing

Supported
Passkey & FIDO2 Artifact Discovery

> Android 14+ Credential Provider & Chromium Web Data recovery

Supported
Hardware TEE & Keymaster Auditing

> Trusty, QSEE, TEEGRIS, and Kinibi attestation posture

Supported
Performance & Intelligence
Rust-Accelerated Native Core

> Rayon parallelized offline PIN/password brute-force (18.5k/s+)

Supported
Multi-Chain Crypto Forensics

> ETH, BTC bech32/legacy, SOL, TRX address carving & BIP-39 seeds

Supported
Integrated CTI & CVE Correlation

> Offline Android SDK CVE matrix, OSV queries & IOC DB

Supported
Consolidated Platform
Native Rust execution with Python orchestration.
Industry Standard

// DEVELOPMENT_PHASES

PRODUCT
ROADMAP.

LockKnife is constantly evolving with new security research capabilities to match the pace of Android platform updates.

RELEASED

Case Integrity & Execution Safety

VERSION: v1.2.0

Tamper-evident SQLite case workspaces, artifact manifest lineage tracking, cryptographic SHA-256 integrity verification, and Bluetooth dry-run execution safety.

Case Workspace EngineArtifact Lineage GraphBluetooth Dry-Run Safety
LATEST_STABLE
LATEST STABLE

Verified Boot Posture & Hardware Security

VERSION: v1.3.0

Full Verified Boot chain & AVB 2.0 analysis, TEE vendor & attestation posture, native SQLite deleted record carving, network exposure scoring, and isolated root staging.

Verified Boot & AVB 2.0TEE Hardware PostureNative SQLite CarvingSafe Root Staging
IN DEVELOPMENT

Autonomous Pipelines & Kernel Auditing

VERSION: v1.4.0

Autonomous multi-stage extraction chains, extended Android 16+ kernel exploit audit, and live device telemetry visualization.

Autonomous PipelinesKernel Exploit AuditingLive Telemetry Stream

Want to Contribute?

Check our experimental branch on GitHub to help shape the future of Android security research.

// QUERY_DATABASE

FREQUENTLY ASKED
QUESTIONS.

Everything you need to know about LockKnife operation, legality, and requirements.