Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Android Security
  3. Andriller

Andriller

MITPython3.6.3

A forensic software utility for read-only, non-destructive data acquisition and analysis from Android smartphones.

GitHubGitHub
1.6k stars257 forks0 contributors

What is Andriller?

Andriller is a forensic software utility that provides a collection of tools for acquiring and analyzing data from smartphones, primarily Android devices. It performs read-only, non-destructive data extraction to maintain forensic integrity while decoding app databases, cracking lockscreens, and generating investigative reports. The tool supports both rooted and non-rooted devices, parsing backups and producing outputs in HTML and Excel formats.

Target Audience

Digital forensic investigators, law enforcement professionals, cybersecurity analysts, and researchers who need to conduct forensic examinations of Android smartphones. It is also suitable for IT security teams performing internal investigations or data recovery.

Value Proposition

Developers choose Andriller for its comprehensive, forensically sound approach to mobile data acquisition without altering device evidence. Its unique selling point is the combination of lockscreen cracking, app-specific decoders, and support for multiple extraction methods (backup, ADB, root) in a single Python-based utility.

Overview

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive acquisition from Android devices.

Use Cases

Best For

  • Conducting forensic investigations on Android smartphones
  • Cracking Pattern, PIN, or Password lockscreens on Android devices
  • Decoding and analyzing data from Android app databases (e.g., WhatsApp, communications)
  • Extracting data from Android backup files (.ab, tarballs) forensically
  • Performing read-only data acquisition from rooted or non-rooted Android devices
  • Generating forensic reports in HTML or Excel format for legal or investigative purposes

Not Ideal For

  • Investigations focusing primarily on iOS or Windows Phone devices, as support is limited to some database parsing and not comprehensive forensic analysis.
  • Real-time forensic analysis or live device monitoring during active use, since Andriller is designed for static data acquisition from backups and connected devices.
  • Environments requiring certified forensic tools with commercial support, training, and integration into enterprise suites, as it's open-source and community-driven.

Pros & Cons

Pros

Forensic Integrity Focus

Emphasizes read-only, non-destructive acquisition to preserve evidence integrity, ensuring data is not altered during extraction, as stated in the philosophy.

Lockscreen Cracking Power

Powerfully cracks Pattern, PIN, and Password lockscreens (excluding gatekeeper), enabling access to secured Android devices for investigative purposes.

Comprehensive App Decoding

Custom decoders parse Android app databases for communications, with some support for iOS and Windows, allowing deep analysis of extracted data.

Flexible Extraction Methods

Supports both non-rooted (via Android Backup) and rooted devices (via ADB, recovery, or SU), providing multiple acquisition paths for different scenarios.

Cons

Limited Non-Rooted Support

Non-rooted extraction relies on Android Backup with varied/limited support, mainly for Android 4.x, which may not cover newer versions without root access.

System Dependency Complexity

Requires external tools like adb and Python 3.6-3.10 with specific setup, adding installation hurdles compared to all-in-one forensic software packages.

Community-Driven Limitations

As an open-source project, it lacks commercial support, regular updates, and certification that proprietary forensic tools offer for legal admissibility.

Frequently Asked Questions

Quick Stats

Stars1,589
Forks257
Contributors0
Open Issues11
Last commit4 years ago
CreatedSince 2019

Tags

#digital-forensics#android-forensics#adb-tools#python-utility#android#data-acquisition#forensic-analysis#python#forensics

Built With

a
adb
T
Tkinter
P
Python

Included in

Android Security9.3k
Auto-fetched 4 hours ago

Related Projects

Mobile-Security-Framework MobSFMobile-Security-Framework MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

Stars21,483
Forks3,732
Last commit2 days ago
DrozerDrozer

The Leading Security Assessment Framework for Android.

Stars4,578
Forks842
Last commit3 months ago
Runtime Mobile Security (RMS)Runtime Mobile Security (RMS)

Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

Stars3,052
Forks411
Last commit2 days ago
InspeckageInspeckage

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

Stars2,976
Forks522
Last commit5 years ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub