Package
com.samsung.android.knox.app.networkfilter
KnoxNetworkFilter
Guidance
Labelled "KnoxNetworkFilter" on the device, this is a small Samsung Knox component (roughly 150 to 190 KB in our sample) signed by a Samsung OEM key that also signs the Android framework. It has no launcher icon. Its declared permissions are network-oriented: access to network and Wi-Fi state, internet access, use of restricted networks, the ability to act across users, the ability to query all installed packages, and a Knox analytics permission. Samsung documents the Knox Firewall as the enterprise feature that fits this shape. Knox Firewall lets an administrator allow, deny or redirect access to specific IP addresses, allow or deny whole domains or sub-domains, and apply those rules to a single app or the whole device, with logs of blocked domain access attempts. In the Knox SDK the same capability appears as the Firewall and DomainFilterRule APIs that an EMM calls, where domain rules work by filtering DNS resolution and IP rules are enforced through iptables once the firewall is enabled. Note that Samsung's published documentation describes the feature without naming this package, so the link between the two is inferred here from the package name, its on-device label and its declared permissions rather than taken from a Samsung statement. For Android Enterprise, EMM and kiosk deployments this matters if your profile applies Knox firewall or URL filtering rules, since disabling a component that filtering may depend on could quietly leave a device unfiltered while the console still reports the policy as applied. Treat it as caution: leave it in place on managed Samsung hardware, and if you are trimming an image, verify your filtering policies still block what they should on a test device afterwards. Version note: no Android or One UI release that changed this package's role could be sourced. On the feature side, Samsung documents that Knox SDK 3.3 added the ability to use domain name rules and IP firewall rules at the same time, so what an EMM can express through Knox firewall policy depends on the Knox version on the device rather than on Android alone.
Package intelligence
Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.
- Signed by the device maker's own signing key (Samsung), so it is an OEM preinstall, and that single certificate is consistent across all 18 device profiles. It also signs the Android framework, so it is a platform-level key on its device(s). Inferred from the certificate appearing only on Samsung devices (508 packages, 10196 observations).
- Its largest observed manifest declares 8 permissions: 2 signature or system-level, 4 install-time and 2 vendor or uncatalogued.
- Never reported as user-facing, so it runs as a background or system component rather than an app the user opens.
Declared permissions (8)
Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.
| Permission | Description |
|---|---|
ACCESS_LOCAL_NETWORK |
- |
ACCESS_NETWORK_STATE |
Allows the app to view information about network connections such as which networks exist and are connected. |
ACCESS_WIFI_STATE |
Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. |
CONNECTIVITY_USE_RESTRICTED_NETWORKS |
Signature or privileged system permission. |
INTERACT_ACROSS_USERS_FULL |
Signature-level system permission, for platform-signed apps. |
INTERNET |
Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. |
QUERY_ALL_PACKAGES |
Allows an app to see all installed packages. |
com.samsung.android.knox.permission.KNOX_ANALYTICS_INTERNAL |
- |
Manage on devices
ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.
/system, so Restore re-adds it (-k keeps app data)Seen on
Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.
| OEM | Model | Android | Provenance | Observations | Last seen |
|---|---|---|---|---|---|
| Samsung | SM-A135F | Android 14 | OEM Samsung | 3 | 21 Jan 2026 |
| Samsung | SM-A137F | Android 14 | - | 1 | 17 Jan 2026 |
| Samsung | SM-A236B | Android 14 | OEM Samsung | 2 | 10 Apr 2026 |
| Samsung | SM-A266B | Android 15 | - | 2 | 21 Aug 2025 |
| Samsung | SM-A266B | Android 16 | - | 1 | 26 Jan 2026 |
| Samsung | SM-A346B | Android 15 | OEM Samsung | 1 | 27 Jul 2026 |
| Samsung | SM-A536B | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 16 | OEM Samsung | 1 | 29 Jul 2026 |
| Samsung | SM-A556B | Android 15 | - | 1 | 1 Jul 2025 |
| Samsung | SM-A566B | Android 16 | OEM Samsung | 3 | 12 Sep 2026 |
| Samsung | SM-F721B | Android 15 | - | 1 | 9 Jul 2025 |
| Samsung | SM-F766B | Android 16 | - | 1 | 11 Nov 2025 |
| Samsung | SM-F971B | Android 17 | OEM Samsung | 1 | 18 Sep 2026 |
| Samsung | SM-G766B | Android 15 | - | 1 | 17 Oct 2025 |
| Samsung | SM-G766B | Android 16 | OEM Samsung | 1 | 5 Sep 2026 |
| Samsung | SM-G991B | Android 15 | OEM Samsung | 1 | 19 Apr 2026 |
| Samsung | SM-S721U | Android 15 | - | 5 | 5 Aug 2025 |
| Samsung | SM-S731B | Android 16 | OEM Samsung | 1 | 11 Aug 2026 |
| Samsung | SM-S906B | Android 15 | - | 1 | 2 Jun 2025 |
| Samsung | SM-S908U | Android 16 | OEM Samsung | 2 | 17 Sep 2026 |
| Samsung | SM-S921B | Android 15 | OEM Samsung | 2 | 22 Jul 2025 |
| Samsung | SM-S921B | Android 16 | OEM Samsung | 1 | 17 Sep 2026 |
| Samsung | SM-S921U | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-S926B | Android 16 | OEM Samsung | 1 | 14 Apr 2026 |
| Samsung | SM-S928B | Android 16 | OEM Samsung | 2 | 12 Jun 2026 |
| Samsung | SM-S928U1 | Android 15 | - | 1 | 12 Sep 2025 |
| Samsung | SM-S931B | Android 15 | - | 1 | 20 Sep 2025 |
| Samsung | SM-S931B | Android 16 | - | 1 | 23 Nov 2025 |
| Samsung | SM-S936B | Android 16 | - | 1 | 18 Dec 2025 |
| Samsung | SM-S937B | Android 15 | - | 1 | 25 Aug 2025 |
| Samsung | SM-S938B | Android 15 | - | 2 | 25 Aug 2025 |
| Samsung | SM-S942B | Android 17 | OEM Samsung | 1 | 25 May 2026 |
| Samsung | SM-S948U | Android 16 | - | 1 | 9 Sep 2026 |
| Samsung | SM-T636B | Android 15 | - | 2 | 12 Oct 2025 |
| Samsung | SM-X200 | Android 14 | - | 1 | 27 Aug 2025 |
| Samsung | SM-X716B | Android 15 | - | 1 | 27 Jun 2025 |
| Samsung | SM-X910 | Android 14 | - | 1 | 26 Jun 2025 |
| Samsung | SM-X910 | Android 15 | - | 1 | 12 Sep 2025 |
Known labels
Locale-aware display names seen in the wild.
| Label | Locale | Seen |
|---|---|---|
| KnoxNetworkFilter | en | 20 |
| KnoxNetworkFilter | en-gb | 18 |
| KnoxNetworkFilter | en-us | 17 |
| KnoxNetworkFilter | it-IT | 5 |
| KnoxNetworkFilter | nl-nl | 4 |
| KnoxNetworkFilter | en-nl | 3 |
| KnoxNetworkFilter | de-de | 2 |
| KnoxNetworkFilter | en-GB | 2 |
| KnoxNetworkFilter | es-ES | 2 |
| KnoxNetworkFilter | es-es | 2 |
| KnoxNetworkFilter | it-it | 2 |
| KnoxNetworkFilter | es-us | 1 |
| KnoxNetworkFilter | ru-ru | 1 |
| KnoxNetworkFilter | en-au | 1 |
| KnoxNetworkFilter | pl-PL | 1 |
| KnoxNetworkFilter | pl-pl | 1 |
| KnoxNetworkFilter | fr-fr | 1 |