KnockKnock
Objective-See Foundation · A Mac persistence inspector that lists automatically launched software, shows signing details and optionally checks file hashes with VirusTotal.
Описание
KnockKnock is Objective-See Foundation's macOS persistence inspection tool. It enumerates software configured to run automatically at startup, login or another application's launch, helping users and security analysts investigate what remains installed on a Mac. It is an inspection aid, not a guarantee that the machine is free of malware.
What a scan shows
Categories include background managed tasks, launch items, cron jobs, browser extensions and other persistence mechanisms. Selecting a category shows item paths and signing information, with controls to inspect details or reveal an item in Finder. Version 4 adds shell-configuration inspection and an optional Start at Login workflow; 4.1.0 expands enumeration and improves launchd override handling.
By default, known platform and signed Apple items are filtered. Legitimate third-party software is still displayed. Appearance in a scan is not a malware verdict, and a missing or unknown VirusTotal result does not establish maliciousness. Inspect the item's publisher, path, purpose and behavior before taking action.
Save findings as JSON and compare a completed current scan with a previous result to identify additions, removals or modifications. The application bundle also provides a command-line scan mode for repeatable inspection. Elevated scans can cover additional areas such as other users' cron jobs; 4.1.0 introduces an always-run-as-root preference while retaining the console user's relevant preferences and paths.
Installation and compatibility
Download the official ZIP, unpack it and launch KnockKnock.app. The publisher says it can run from anywhere without a separate installation; the Homebrew cask copies it as an application with brew install --cask knockknock. The official product page specifies macOS 10.15 or later. The official4.1.0 ZIP was unpacked without launching or installing it. Its executable is a verified Universal Mach-O with x86_64 and arm64 slices, supporting Intel and Apple silicon; its Info.plist confirms macOS10.15 as the minimum.
The official 4.1.0 GitHub release records the ZIP as 2,552,206 bytes and supplies a SHA-256 checksum. The cask declares no extra Homebrew formula dependency or named conflict. Scan coverage may require Full Disk Access, which the app can prompt you to grant through System Settings. Administrator/root authorization is relevant for an elevated scan or the explicit root preference; it is not a reason to blindly elevate every downloaded security tool.
VirusTotal, accounts and privacy
VirusTotal integration is optional and configurable. Provide your own VirusTotal API key if you want hash-based reputation lookups, and observe its quota and terms. Ordinary local inspection does not describe a mandatory Objective-See account. Disable VirusTotal integration to avoid its lookup requests, and disable automatic update checks if your policy requires that behavior.
Hash lookups and uploading files are different actions. Reputation checks send a binary's hash; explicit submission of an unknown file sends the file itself to VirusTotal. Do not upload confidential, proprietary or personal files without understanding the service's sharing policy. Version 4.0.3 changes submission checkboxes to start unchecked. JSON scan exports can reveal installed applications, file paths and other sensitive system details; protect them before sharing.
Cost, license and interpretation
KnockKnock is free and its source repository is licensed under GNU GPL version 3. Objective-See Foundation accepts sponsorship and donations. VirusTotal and other external services have independent terms. An open-source inspection utility is not a replacement for backups, incident-response expertise or a broader security policy.
Code signatures and notarization provide useful provenance signals but do not settle every security question. Persisted shell or Python interpreters may run a separate script that deserves inspection even when the interpreter itself is signed. Avoid deleting launch agents, libraries or system configuration merely because they are unfamiliar. Verify the owner and purpose and keep a recovery route before modifying persistent software.
Sources: Official product and usage guide, Publisher source, 4.1.0 release, License.
Новая версия Что нового в 4.1.0 7 окт. · Редакция OpenNavo
- AddedAdds an always-run-as-root preference using console-user settings.
- FixedFixes Full Disk Access detection on macOS 27.
- ImprovedIsolates plug-in scans and guards malformed or oversized input files.