LockKnife Android Investigation Workbench
Collect, analyze, and report Android security and forensic evidence from one terminal workspace.
- Source repo
- ImKKingshuk/LockKnife
- Stars
- ★ 544
- Last updated
- 1d ago
- License
- GPL-3.0
- Primary language
- Python
- FA score
- 58/100 · Major gaps
At a glance
- How it runs
- Works with
- Universal · cross-platform
- Cost
- Free, no paid service needed
- Setup effort
- Medium · a few setup steps
- You'll need
- Typical use
- A forensic analyst needs to acquire accessible records from an authorized Android device and keep the output organized by case.
- Not a fit if
- Teams that need recovery of modern hardware-backed Android credentials
- People working on devices, apps, or networks without authorization
- Source review
- 58/100 · Major gaps
What does this agent do, and when should you use it?
LockKnife is an Android security research and digital forensics toolkit for security researchers, forensic analysts, and mobile penetration testers. It offers a full-screen terminal interface alongside a repeatable headless CLI, with Python orchestration and a Rust-accelerated core. Users can collect accessible data from authorized devices or analyze APKs, SQLite databases, PCAPs, and exported evidence offline. Artifacts, analysis, sessions, and reports can be organized into cases, with source tracing, registered-hash checks, and case-bundle export. It installs on macOS, Linux, and Windows; device work requires Android platform-tools and device authorization, while some features need optional components or external tools.
Use lockknife --cli device list to inspect devices, then lockknife --cli extract to acquire accessible SMS, contacts, call logs, browser records, media, location data, and supported messaging-app data; access depends on permissions and app versions. For local evidence, lockknife --cli forensics sqlite inspects databases, while other workflows build timelines, correlate identifiers, or import ALEAPP results. For APKs, lockknife --cli apk decompile selects JADX, apktool, or unpacking modes, and YARA rules can scan app contents. With a compatible Frida server, runtime hooks, method tracing, and memory searches are available; network workflows analyze PCAPs, discover visible API endpoints, and capture device traffic when tcpdump is accessible. The toolkit also includes supported legacy PIN/password recovery, credential and wallet evidence inspection, device security indicators, optional threat-intelligence lookups, and case summaries, integrity reports, HTML reports, and case exports.
- A forensic analyst needs to acquire accessible records from an authorized Android device and keep the output organized by case.
- An investigator receives SQLite, PCAP, or exported data and wants to build a timeline and correlate evidence offline.
- A mobile security researcher needs to inspect an APK's manifest, permissions, exported components, DEX metadata, and YARA findings.
- A penetration tester needs to trace methods or search memory in an authorized app using Frida.
- An incident responder needs to turn device and network findings into verifiable case records and technical or executive reports.
How do you install or deploy this agent?
On macOS, install with Homebrew; macOS and Linux also have an installer script, and Windows users can install with Scoop. Python environments require Python 3.12+ and can install a platform-matched prebuilt wheel from Releases. Device operations need Android platform-tools (adb) and device authorization. APK decompilation, Frida, extended PCAP analysis, and YARA scanning may require additional dependencies or external tools.
How do you use this agent?
Check the installation and device, then initialize a case and run an extraction. Replace the example placeholders with an authorized device, case, and examiner; offline analysis does not require a connected device.
What are this agent's strengths and limitations?
- Offers both a TUI and headless CLI for interactive investigations and repeatable individual commands.
- Combines device acquisition, offline forensics, APK analysis, Frida runtime inspection, and network evidence workflows.
- Cases can connect evidence and analysis, verify registered hashes and audit records, and produce HTML reports and case bundles.
- Supports macOS, Linux, and Windows with several installation options.
- Device acquisition depends on permissions, app versions, and encryption; protected paths may need root, and collecting an encrypted database does not decrypt it.
- JADX/apktool, a Frida server, and device tcpdump have separate requirements; some capabilities also need optional Python extras.
- Credential recovery covers specific legacy hashes and accessible artifacts; recovery of modern screen locks or hardware-backed keys is not guaranteed.
- Threat-intelligence lookups send selected indicators to external providers, and reports and case bundles are not encrypted by default.
How does this agent compare with similar options?
Key facts side by side with the most closely related agents.
| Agent | Source review | Form / cost | Stars | Updated | Language | Full support on |
|---|---|---|---|---|---|---|
| LockKnife Android Investigation Workbench This agent | 58 · Major gaps | CLIFree | ★ 544 | 1d ago | Python | — |
| Open-AutoGLM Phone Agent | 55 · Major gaps | CLIFree + model costs | ★ 26k | 7mo ago | Python | — |
| mobile-use: Automate Your Phone with Natural Language | 33 · Major gaps | CLIFree + model costs | ★ 3.2k | 25d ago | Python | OpenAI API · Claude API |
| ClickClickClick | 23 · Major gaps | CLIFree + model costs | ★ 713 | 6mo ago | Python | OpenAI API |
How does FollowAgents rate this agent?
Why each dimension lost points
The documentation requires authorized use, describes that selected indicators are sent for some external lookups, and advises protecting credentials, case data, and unencrypted reports; this supports meaningful data-flow and sensitive-data guidance. Device acquisition, runtime hooks, and network workflows have broad effects, while confirmation and rollback steps are not adequately documented. CI configuration includes pinned actions and pip-audit/cargo-deny checks, but no results from this revision are supplied. Publisher identity is unknown; the author field is only a name, and vulnerability reporting is documented without clear ongoing maintenance ownership.
The README, project metadata, and workflows describe a Python/Rust project, optional dependencies, and configured checks, but there is a concrete mismatch: the README says the full extras omit PDF while pyproject includes pdf in full. External tools and optional dependencies are listed clearly. Troubleshooting points to doctor/features commands and an installation guide, though the supplied material has few concrete failure-output examples.
The project names security researchers, forensic analysts, and mobile penetration testers and covers device acquisition and offline analysis through both TUI and CLI workflows. It documents boundaries such as permissions, encryption, optional dependencies, and PoC/simulated capabilities, but gives little detail on the autonomous Agent's trigger boundaries or intended scope. Installation paths cover macOS, Linux, and Windows, with device operations depending on platform tools and external components.
The README is organized around features, installation, quick start, and guides, with stepwise examples, an FAQ, and dedicated security/privacy documentation. Installation notes cover multiple platforms and optional components; GPL-3.0-only is supported by both LICENSE and metadata. A version and release workflow are visible and a changelog is linked, but the supplied material does not include its detailed entries. Maintainer identity and continuing ownership are unclear.
Case-linked artifacts, provenance, integrity checks, and technical or executive reports can turn collection and analysis into organized deliverables, while TUI and CLI support different workflows. The feature set is broad and tied to concrete investigation tasks, but the material offers no evidence about cost, performance, or real result quality. Many capabilities require external tools, optional packages, or device permissions, adding setup cost.
The README's main capabilities and limitations receive some corroboration from installation and security documentation, project metadata, workflows, and a small set of CLI tests. The docs state conditions and limits for several capabilities and distinguish PoC/simulated functions from verified live exploits. The supplied tests assert only a few CLI paths and do not establish broad product claims or execution correctness; dependency scan results are also absent.
- Use only on devices, applications, and networks within an explicitly authorized scope; runtime hooks, acquisition, and wireless functions may affect targets or expose sensitive data.
- Case exports and reports are not encrypted by default; external intelligence lookups send selected indicators, so review contents and protect them under your organization's policy before sharing.
- The README and pyproject disagree about whether the full optional extra includes PDF; check required components before installation.