KnockKnock

Objective-See Foundation · A Mac persistence inspector that lists automatically launched software, shows signing details and optionally checks file hashes with VirusTotal.

CaskSecurity & PrivacyChip Apple · Intel
Inicio
De homebrew/cask
Instalaciones en los últimos 30 días325Puesto 367 en Apps
Instalaciones del último año5,6 milTotal de los últimos 365 días
Última versión4.1.0ayer · 7 oct
Tamaño de descarga2,6MBarm64 / x86_64 · zip
Frecuencia de actualizaciónIrregular1 versión en 30 días

Descripción

KnockKnock is Objective-See Foundation's macOS persistence inspection tool. It enumerates software configured to run automatically at startup, login or another application's launch, helping users and security analysts investigate what remains installed on a Mac. It is an inspection aid, not a guarantee that the machine is free of malware.

What a scan shows

Categories include background managed tasks, launch items, cron jobs, browser extensions and other persistence mechanisms. Selecting a category shows item paths and signing information, with controls to inspect details or reveal an item in Finder. Version 4 adds shell-configuration inspection and an optional Start at Login workflow; 4.1.0 expands enumeration and improves launchd override handling.

By default, known platform and signed Apple items are filtered. Legitimate third-party software is still displayed. Appearance in a scan is not a malware verdict, and a missing or unknown VirusTotal result does not establish maliciousness. Inspect the item's publisher, path, purpose and behavior before taking action.

Save findings as JSON and compare a completed current scan with a previous result to identify additions, removals or modifications. The application bundle also provides a command-line scan mode for repeatable inspection. Elevated scans can cover additional areas such as other users' cron jobs; 4.1.0 introduces an always-run-as-root preference while retaining the console user's relevant preferences and paths.

Installation and compatibility

Download the official ZIP, unpack it and launch KnockKnock.app. The publisher says it can run from anywhere without a separate installation; the Homebrew cask copies it as an application with brew install --cask knockknock. The official product page specifies macOS 10.15 or later. The exact CPU architecture of the current ZIP has not been independently verified, so no Universal claim is made.

The official 4.1.0 GitHub release records the ZIP as 2,552,206 bytes and supplies a SHA-256 checksum. The cask declares no extra Homebrew formula dependency or named conflict. Scan coverage may require Full Disk Access, which the app can prompt you to grant through System Settings. Administrator/root authorization is relevant for an elevated scan or the explicit root preference; it is not a reason to blindly elevate every downloaded security tool.

VirusTotal, accounts and privacy

VirusTotal integration is optional and configurable. Provide your own VirusTotal API key if you want hash-based reputation lookups, and observe its quota and terms. Ordinary local inspection does not describe a mandatory Objective-See account. Disable VirusTotal integration to avoid its lookup requests, and disable automatic update checks if your policy requires that behavior.

Hash lookups and uploading files are different actions. Reputation checks send a binary's hash; explicit submission of an unknown file sends the file itself to VirusTotal. Do not upload confidential, proprietary or personal files without understanding the service's sharing policy. Version 4.0.3 changes submission checkboxes to start unchecked. JSON scan exports can reveal installed applications, file paths and other sensitive system details; protect them before sharing.

Cost, license and interpretation

KnockKnock is free and its source repository is licensed under GNU GPL version 3. Objective-See Foundation accepts sponsorship and donations. VirusTotal and other external services have independent terms. An open-source inspection utility is not a replacement for backups, incident-response expertise or a broader security policy.

Code signatures and notarization provide useful provenance signals but do not settle every security question. Persisted shell or Python interpreters may run a separate script that deserves inspection even when the interpreter itself is signed. Avoid deleting launch agents, libraries or system configuration merely because they are unfamiliar. Verify the owner and purpose and keep a recovery route before modifying persistent software.

Sources: Official product and usage guide, Publisher source, 4.1.0 release, License.

Novedades Novedades de 4.1.0 7 oct · Editado por OpenNavo

  • AddedAdds an always-run-as-root preference using console-user settings.
  • FixedFixes Full Disk Access detection on macOS 27.
  • ImprovedIsolates plug-in scans and guards malformed or oversized input files.

Interfaz gráfica de código abierto para Homebrew. La instalación se realiza desde el cliente de macOS o con el comando brew.

X · @opennavo

© 2026 OpenNavo