# den4uk/andriller

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive acquisition from Android devices.

Repository: https://github.com/den4uk/andriller
Canonical: https://ross.abutalabs.com/products/andriller
Language: Python
License: MIT
License Family: permissive
Topics: forensics, python, android
Last push: 2022-06-27T22:00:44+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2455, "days_push": 1528, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1599, forks 254 (observed 2026-08-28T04:05:09.333401+00:00)

## What it is
Andriller CE is a Python-based forensic toolkit for Android smartphones that performs read-only, non-destructive data acquisition from devices. It includes lockscreen cracking, app database decoders (including encrypted WhatsApp databases), and generates HTML/Excel forensic reports via a GUI or CLI.

## Use cases
- extract data from an android device for forensic analysis
- crack android lockscreen pattern pin or password
- decode whatsapp message databases from a device backup
- parse android backup ab files and nandroid tarballs
- generate forensic reports from android app databases
- acquire data from a non-rooted android phone
- screen capture an android device display

## When to choose
- you need forensically sound, read-only android data acquisition
- you want automated decoding of android app databases into reports
- you need to crack or recover android lockscreen credentials during an investigation
- you work in DFIR and want a free open-source android forensic tool

## When to avoid
- you need iOS or Windows Phone acquisition as the primary target
- you need ongoing updates - the latest release is from 2022 and supports Python 3.6-3.10
- you need remote or network-based acquisition rather than USB/ADB
- you want a modern commercial-grade forensic suite with vendor support

## Facets
- artifact type: application
- maturity: maintenance
- function: security, gui, parser, cryptography, data-science
- domain: security, android-tools, developer-tools, privacy
- platform: python, windows, cli
- tags: android-forensics, dfir, adb, data-extraction, lockscreen-cracking, whatsapp-decryption, digital-forensics, linux, macos, desktop

## Member repositories
- den4uk/andriller (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:09.333401+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:53:13.271494+00:00, confidence not recorded.
  - readme: https://github.com/den4uk/andriller (fetched 2026-08-28T04:05:09.333401+00:00, sha c1e95465b420)
  - registry_pypi: https://pypi.org/pypi/andriller/json (fetched 2026-08-29T11:24:28.634790+00:00, sha 396e5c8da026)
- Data as of 2026-08-30T08:39:29.467469+00:00.
