Skip to content

Security

Security tools for rooted Android devices - root apps, Magisk modules, KernelSU modules, LSPosed modules and firewalls for hardening your device, controlling which apps can reach the network, and auditing what runs on it.

TIP

Related: Privacy covers data-access control and spoofing; Networking covers VPNs, proxies and connection tools.

Security Tools

NOTE

FLAG_SECURE is a window-level security flag in Android that prevents the window's content from appearing in screenshots or being captured during screen recordings.

  • ⭐ Enable Screenshot - Enabling screenshots in apps that normally wouldn't allow it, and disabling screenshot(Android 14+) and screen record(Android 15+) detection. FOSS [LSP]
  • ⭐ Flag Secure Patcher - Patch service.jar on device to disable secure lock and screenshot listeners. FOSS [M]
  • ⭐ Move Certificate - Move user certificates to system certificates. Supports Android 7-16. FOSS [M] [K]
  • ⭐ SSL Killer - Bypass multiple ssl pinning implementations. Proprietary [LSP]
  • AlternativeUnlockXposed - Unlock your Android phone with an alternative PIN. FOSS [LSP]
  • Always Trust User Certs - A Magisk/KernelSU module that automatically adds user certificates to the system root CA store. FOSS [M] [K]
  • Android-FlagSecure-Disabler - FlagSecure Disabler, Screenshot Observer Disabler & DRM Disabler. FOSS [M] [K]
  • Biometric App Lock - Locks apps you choose behind fingerprint or face unlock. FOSS [LSP]
  • Biometric Bypass Module - Fast-forwards face unlock by skipping the biometric confirmation step in System UI on Android 10+. FOSS [LSP]|
  • CaptureSposed - Disables the newly introduced screenshot detection API in Android 14. FOSS [LSP]
  • Cert-Fixer - Installs custom CA certificates to Android's system certificate store. FOSS [M]
  • Custom Certificate Authorities - Moves user-installed certificate authorities into the system trust store, making them trusted by all apps. FOSS [M]
  • Custom Certificates - A Magisk/KernelSU module which adds custom certificates to the system trust store. FOSS [M] [K]
  • Disable usb debugging - Disables USB Debugging after every reboot. FOSS [M]
  • DriFiCrack - Brute Force Tool to Crack Wi-Fi Passwords. FOSS [M]
  • ih8SecureLock - Prevent apps from blocking and listening to your screenshots with Zygisk. FOSS [M] [K]
  • Just Trust Me Pro - Disables SSL certificate checking for the purposes of auditing an app with cert pinning. FOSS [M]
  • OneShot Extended - Performs various WPS attacks without the requirement of monitor mode. FOSS [M] [K]
  • PinGuard - LSPosed module that requires fingerprint / password to unpin screen-pinned apps. FOSS [LSP]
  • Simple Flag Secure - Disable Secure Flag and allow taking screenshots/screen recording in apps supports KSU/APatch . FOSS [M] [K]
  • StrykerOSS - Bundles a curated set of network, wireless and web security tools into a single rooted-Android application for penetration testing. FOSS
  • TapDucky - Open-source DuckyScript runner for rooted Android with USB Gadget (ConfigFS) support. FOSS|

Firewalls & Filtering

  • AFWall+ - Iptables-based firewall. FOSS| |
  • Athena - Material You (Material 3) firewall and ad blocker that works seamlessly on both rooted and non-rooted devices. FOSS|
  • De1984 Firewall - A privacy-focused Firewall and Package Manager for Android devices. FOSS|
  • Fyrypt - Android firewall with UID + PID rules, dnscrypt-proxy management, and per-app live network monitoring. Proprietary
  • Net Switch - Isolate any app from Internet access. FOSS [M]
  • NetGuard - Block access to the internet. Apps and addresses can individually be allowed or denied access to your Wi-Fi and/or mobile connection. FOSS
  • PCAPdroid - Lets you track, analyze and block the connections made by the other apps in your device. FOSS| |
  • ShizuWall - Android firewall without VPN powered by Shizuku / local ADB daemon / Root. FOSS| |