LockKnife Android Investigation Workbench

Collect, analyze, and report Android security and forensic evidence from one terminal workspace.

Stars
★ 544
Last updated
1d ago
License
GPL-3.0
Primary language
Python

At a glance

How it runs
CLI
Works with
Universal · cross-platform
Cost
Free, no paid service needed
Setup effort
Medium · a few setup steps
You'll need
Python 3.12+Android platform-tools (adb)JADX or apktool (for APK decompilation)Frida server (for runtime instrumentation)device tcpdump (for device traffic capture)Shell / CLINetwork accessLocal filesystem
Typical use
A forensic analyst needs to acquire accessible records from an authorized Android device and keep the output organized by case.
Not a fit if
  • Teams that need recovery of modern hardware-backed Android credentials
  • People working on devices, apps, or networks without authorization

What does this agent do, and when should you use it?

LockKnife is an Android security research and digital forensics toolkit for security researchers, forensic analysts, and mobile penetration testers. It offers a full-screen terminal interface alongside a repeatable headless CLI, with Python orchestration and a Rust-accelerated core. Users can collect accessible data from authorized devices or analyze APKs, SQLite databases, PCAPs, and exported evidence offline. Artifacts, analysis, sessions, and reports can be organized into cases, with source tracing, registered-hash checks, and case-bundle export. It installs on macOS, Linux, and Windows; device work requires Android platform-tools and device authorization, while some features need optional components or external tools.

Use lockknife --cli device list to inspect devices, then lockknife --cli extract to acquire accessible SMS, contacts, call logs, browser records, media, location data, and supported messaging-app data; access depends on permissions and app versions. For local evidence, lockknife --cli forensics sqlite inspects databases, while other workflows build timelines, correlate identifiers, or import ALEAPP results. For APKs, lockknife --cli apk decompile selects JADX, apktool, or unpacking modes, and YARA rules can scan app contents. With a compatible Frida server, runtime hooks, method tracing, and memory searches are available; network workflows analyze PCAPs, discover visible API endpoints, and capture device traffic when tcpdump is accessible. The toolkit also includes supported legacy PIN/password recovery, credential and wallet evidence inspection, device security indicators, optional threat-intelligence lookups, and case summaries, integrity reports, HTML reports, and case exports.

  1. A forensic analyst needs to acquire accessible records from an authorized Android device and keep the output organized by case.
  2. An investigator receives SQLite, PCAP, or exported data and wants to build a timeline and correlate evidence offline.
  3. A mobile security researcher needs to inspect an APK's manifest, permissions, exported components, DEX metadata, and YARA findings.
  4. A penetration tester needs to trace methods or search memory in an authorized app using Frida.
  5. An incident responder needs to turn device and network findings into verifiable case records and technical or executive reports.

How do you install or deploy this agent?

On macOS, install with Homebrew; macOS and Linux also have an installer script, and Windows users can install with Scoop. Python environments require Python 3.12+ and can install a platform-matched prebuilt wheel from Releases. Device operations need Android platform-tools (adb) and device authorization. APK decompilation, Frida, extended PCAP analysis, and YARA scanning may require additional dependencies or external tools.

How do you use this agent?

Check the installation and device, then initialize a case and run an extraction. Replace the example placeholders with an authorized device, case, and examiner; offline analysis does not require a connected device.

What are this agent's strengths and limitations?

Pros
  • Offers both a TUI and headless CLI for interactive investigations and repeatable individual commands.
  • Combines device acquisition, offline forensics, APK analysis, Frida runtime inspection, and network evidence workflows.
  • Cases can connect evidence and analysis, verify registered hashes and audit records, and produce HTML reports and case bundles.
  • Supports macOS, Linux, and Windows with several installation options.
Limitations
  • Device acquisition depends on permissions, app versions, and encryption; protected paths may need root, and collecting an encrypted database does not decrypt it.
  • JADX/apktool, a Frida server, and device tcpdump have separate requirements; some capabilities also need optional Python extras.
  • Credential recovery covers specific legacy hashes and accessible artifacts; recovery of modern screen locks or hardware-backed keys is not guaranteed.
  • Threat-intelligence lookups send selected indicators to external providers, and reports and case bundles are not encrypted by default.

How does this agent compare with similar options?

Key facts side by side with the most closely related agents.

Agent Source review Form / cost Stars Updated Language Full support on
LockKnife Android Investigation Workbench This agent 58 · Major gaps CLIFree ★ 544 1d ago Python —
Open-AutoGLM Phone Agent 55 · Major gaps CLIFree + model costs ★ 26k 7mo ago Python —
mobile-use: Automate Your Phone with Natural Language 33 · Major gaps CLIFree + model costs ★ 3.2k 25d ago Python OpenAI API · Claude API
ClickClickClick 23 · Major gaps CLIFree + model costs ★ 713 6mo ago Python OpenAI API

How does FollowAgents rate this agent?

FollowAgents source review · FARS-2.1
Major gaps
58/ 100 5-point scale 2.9 / 5
Trust 13/29
Reliability 6/14
Adaptability 12/18
Convention 15/18
Effectiveness 7/13
Verifiability 5/8
Why each dimension lost points
Trust13 / 29 · 2.2/5

The documentation requires authorized use, describes that selected indicators are sent for some external lookups, and advises protecting credentials, case data, and unencrypted reports; this supports meaningful data-flow and sensitive-data guidance. Device acquisition, runtime hooks, and network workflows have broad effects, while confirmation and rollback steps are not adequately documented. CI configuration includes pinned actions and pip-audit/cargo-deny checks, but no results from this revision are supplied. Publisher identity is unknown; the author field is only a name, and vulnerability reporting is documented without clear ongoing maintenance ownership.

Reliability6 / 14 · 2.1/5

The README, project metadata, and workflows describe a Python/Rust project, optional dependencies, and configured checks, but there is a concrete mismatch: the README says the full extras omit PDF while pyproject includes pdf in full. External tools and optional dependencies are listed clearly. Troubleshooting points to doctor/features commands and an installation guide, though the supplied material has few concrete failure-output examples.

Adaptability12 / 18 · 3.3/5

The project names security researchers, forensic analysts, and mobile penetration testers and covers device acquisition and offline analysis through both TUI and CLI workflows. It documents boundaries such as permissions, encryption, optional dependencies, and PoC/simulated capabilities, but gives little detail on the autonomous Agent's trigger boundaries or intended scope. Installation paths cover macOS, Linux, and Windows, with device operations depending on platform tools and external components.

Convention15 / 18 · 4.2/5

The README is organized around features, installation, quick start, and guides, with stepwise examples, an FAQ, and dedicated security/privacy documentation. Installation notes cover multiple platforms and optional components; GPL-3.0-only is supported by both LICENSE and metadata. A version and release workflow are visible and a changelog is linked, but the supplied material does not include its detailed entries. Maintainer identity and continuing ownership are unclear.

Effectiveness7 / 13 · 2.7/5

Case-linked artifacts, provenance, integrity checks, and technical or executive reports can turn collection and analysis into organized deliverables, while TUI and CLI support different workflows. The feature set is broad and tied to concrete investigation tasks, but the material offers no evidence about cost, performance, or real result quality. Many capabilities require external tools, optional packages, or device permissions, adding setup cost.

Verifiability5 / 8 · 3.1/5

The README's main capabilities and limitations receive some corroboration from installation and security documentation, project metadata, workflows, and a small set of CLI tests. The docs state conditions and limits for several capabilities and distinguish PoC/simulated functions from verified live exploits. The supplied tests assert only a few CLI paths and do not establish broad product claims or execution correctness; dependency scan results are also absent.

Risks and how to mitigate them
  • Use only on devices, applications, and networks within an explicitly authorized scope; runtime hooks, acquisition, and wireless functions may affect targets or expose sensitive data.
  • Case exports and reports are not encrypted by default; external intelligence lookups send selected indicators, so review contents and protect them under your organization's policy before sharing.
  • The README and pyproject disagree about whether the full optional extra includes PDF; check required components before installation.
Evidence confidence: Low Reviewed Oct 09, 2026 Reviewed revision 44020a8f5a5d
See the full review method →

FAQ

Do I need a connected device or root access?
No for offline analysis of SQLite databases, APKs, PCAPs, and supported exports. Device operations need a connection and authorization; protected app or system paths often require elevated access.
Can LockKnife unlock every Android device?
No. Recovery supports specific hashes and accessible artifacts. Modern hardware-backed credentials, encryption, and device protections cannot be assumed recoverable or bypassable.
Which features need extra setup?
APK decompilation uses JADX or apktool, runtime instrumentation needs a compatible Frida server, and device traffic capture needs accessible tcpdump. Extended features may also need their corresponding extras.
Is case data sent to external services?
Local analysis does not require threat-intelligence services. Explicit VirusTotal or OTX lookups send selected indicators to those providers.
Are reports and case exports encrypted?
They are not encrypted by default. Review and protect reports and bundles before sharing.
View on GitHub ↗ Install ↓

Related agents