AI summary
Deep multi-layer root and hook framework detector with 71 native C++ and 68 Kotlin checks. Scans for su binaries, Zygisk/LSPosed modules, SELinux tampering, mount namespace abuse, and hardware attestation status. Open source under MIT license. Bug fixes include improved KernelSU temporary root detection and reduced false positives on OnePlus/Oppo/Realme devices.
Generated by AI. May contain inaccuracies.
Screenshots
About this app
kknd Root Detector is an Android application that performs deep, multi-layer detection of root access, hook frameworks, SELinux policy tampering, and system integrity violations, using both Kotlin and native C++ checks.
Features
Native layer (C++), 71 checks:
- Binary scans: su, root manager packages, suspicious paths - Mount namespace: bind-mounts, overlayfs, namespace isolation - Property tampering: resetprop scan across all partition prop files, __system_property_serial drift, PIF/TrickyStore spoof configs - SELinux: attr/current write probe (root contexts in policy), DirtySepolicy selinux_check_access rule checks - Zygisk / LSPosed: module presence, memory maps, JNI hook traces - Hardware security: keystore attestation, TEE status, boot state
Kotlin layer, 68 checks:
Mirrors the native layer with JVM-level checks: package manager scans, reflection-based SELinux.checkSELinuxAccess, property reads, Play Integrity API integration, and certificate chain validation.
Use cases
- Testing rooted Android devices - Studying root and hook framework detection techniques - Learning Android native security (SELinux, properties, mount namespaces) - Developing root detection in production apps
Interface language:
- English
License
MIT
What's new
- Bug fixes
- Kernel patch window: raised the grace period to 90 days, removed the easily spoofed boot-state check, and added tiered severity (WARNING 91–180 days, HIGH over 180 days). - Fixed SELinux bypass for KernelSU temporary root detection. - Improved SELinux detection.
- New detections
- KernelSU temporary root: direct probes for known KSU staging files. - Socket scan for temp_su and ksud sockets, always readable and bypassing directory permission restrictions. - Added KSU-specific filenames to the native suspicious artifact list.
- Removed
- Removed Oplus/OplusEx directory detection, which caused false positives on stock OnePlus, Oppo and Realme devices.
About this version
- Version
- 3.3 (6)
- Size
- 2.64 MB
- Requires Android
- 8.0
- Target SDK
- 26
- Architecture
- arm64-v8a
- Downloads
- 11
- Updated
- Oct 1, 2026
- Package
- com.juanma0511.rootdetector
Similar apps
Ratings & reviews
- 50
- 40
- 30
- 20
- 10