Package
com.samsung.android.knox.kpecore
KPECore
Guidance
Labelled "KPECore", this is a Samsung system component belonging to Knox Platform for Enterprise (KPE), Samsung's enterprise security layer on Galaxy devices. Samsung describes KPE as bringing "hardware-based security, policy management, and compliance capabilities beyond the standard features commonplace in the mobile device market", requiring a valid Knox licence, and applied by administrators through the Knox Service Plugin in their UEM. It has no launcher icon and nothing a user opens. Samsung does not publicly document this package by name, so rather than guess at its internals the evidence is set out plainly. On this site's provenance data it is Samsung platform-signed and its permissions are almost entirely Knox ones, including KNOX_KPECORE_INTERNAL, KNOX_LICENSE_INTERNAL, KNOX_SECURITY, KNOX_DEVICE_CONFIGURATION, KNOX_CUSTOM_SETTING and KNOX_WIFI, alongside platform permissions such as WRITE_SECURE_SETTINGS, MANAGE_ROLE_HOLDERS, MANAGE_USERS, SET_TIME and INSTALL_SELF_UPDATES. That is the shape of a core on-device service for applying Knox policy and handling Knox licensing, and it can update itself, which fits a component Samsung services independently of firmware releases. For Android Enterprise, EMM and kiosk use, treat this as part of the Samsung management stack rather than something to trim. If your EMM applies Knox policy through the Knox Service Plugin, interfering with this package risks breaking that policy path, so it is rated caution. Samsung-specific configuration should be changed through the Knox Service Plugin and your EMM, not by disabling system packages. Version note: KPE is the Knox 3.x-era model. Samsung's container documentation records that from Knox 3.0 onward the Knox Platform for Enterprise extends the standard Android Enterprise work profile rather than requiring the older proprietary Knox Workspace container, and Samsung's admin documentation states that KPE depends on a valid Knox licence. Whether this particular package's role has changed across Knox or One UI releases is not something the available sources establish, so it is flagged here as an open question rather than asserted. This site records it on API 31 through API 37 devices, with versions ranging from 2.1.10.25 to 2.6.04.9.
Package intelligence
Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.
- Signed by the device maker's own signing key (Samsung), so it is an OEM preinstall, but 2 different certificates appear across the fleet, so OEMs ship their own builds of it. It also signs the Android framework, so it is a platform-level key on its device(s). Inferred from the certificate appearing only on Samsung devices (508 packages, 10196 observations).
- Its largest observed manifest declares 27 permissions: 7 signature or system-level, 5 install-time and 15 vendor or uncatalogued.
- Never reported as user-facing, so it runs as a background or system component rather than an app the user opens.
Declared permissions (27)
Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.
| Permission | Description |
|---|---|
ACCESS_LOCAL_NETWORK |
- |
ACCESS_NETWORK_STATE |
Allows the app to view information about network connections such as which networks exist and are connected. |
FOREGROUND_SERVICE |
Allows the app to make use of foreground services. |
INSTALL_SELF_UPDATES |
Signature or privileged system permission. |
INTERACT_ACROSS_USERS_FULL |
Signature-level system permission, for platform-signed apps. |
INTERNET |
Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. |
MANAGE_ROLE_HOLDERS |
Signature-level system permission, for platform-signed apps. |
MANAGE_USERS |
Signature or privileged system permission. |
REAL_GET_TASKS |
Signature or privileged system permission. |
RECEIVE_BOOT_COMPLETED |
Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the phone and allow the app to slow down the overall phone by always running. |
SET_TIME |
Signature or privileged system permission. |
WAKE_LOCK |
Allows the app to prevent the phone from going to sleep. |
WRITE_SECURE_SETTINGS |
Signature or privileged system permission. |
com.android.permissioncontroller.permission.MANAGE_ROLES_FROM_CONTROLLER |
- |
com.samsung.android.knox.permission.KNOX_ANALYTICS_INTERNAL |
- |
com.samsung.android.knox.permission.KNOX_CUSTOM_SETTING |
- |
com.samsung.android.knox.permission.KNOX_CUSTOM_SYSTEM |
- |
com.samsung.android.knox.permission.KNOX_DATE_TIME |
- |
com.samsung.android.knox.permission.KNOX_DEVICE_CONFIGURATION |
- |
com.samsung.android.knox.permission.KNOX_HW_CONTROL |
- |
com.samsung.android.knox.permission.KNOX_KPECORE_INTERNAL |
- |
com.samsung.android.knox.permission.KNOX_LICENSE_INTERNAL |
- |
com.samsung.android.knox.permission.KNOX_PROXY_ADMIN_INTERNAL |
- |
com.samsung.android.knox.permission.KNOX_RTLS |
- |
com.samsung.android.knox.permission.KNOX_SECURITY |
- |
com.samsung.android.knox.permission.KNOX_WIFI |
- |
com.samsung.android.mcfds.permission.START_SERVICE |
- |
Manage on devices
ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.
/system, so Restore re-adds it (-k keeps app data)Seen on
Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.
| OEM | Model | Android | Provenance | Observations | Last seen |
|---|---|---|---|---|---|
| Samsung | SM-A125F | Android 12 | OEM Samsung | 1 | 21 Jan 2026 |
| Samsung | SM-A135F | Android 14 | OEM Samsung | 3 | 21 Jan 2026 |
| Samsung | SM-A137F | Android 14 | - | 1 | 17 Jan 2026 |
| Samsung | SM-A236B | Android 14 | OEM Samsung | 2 | 10 Apr 2026 |
| Samsung | SM-A266B | Android 15 | - | 2 | 21 Aug 2025 |
| Samsung | SM-A266B | Android 16 | - | 1 | 26 Jan 2026 |
| Samsung | SM-A346B | Android 15 | OEM Samsung | 1 | 27 Jul 2026 |
| Samsung | SM-A515F | Android 13 | - | 1 | 30 Jun 2025 |
| Samsung | SM-A528B | Android 13 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 16 | OEM Samsung | 1 | 29 Jul 2026 |
| Samsung | SM-A556B | Android 15 | - | 1 | 1 Jul 2025 |
| Samsung | SM-A566B | Android 16 | OEM Samsung | 3 | 12 Sep 2026 |
| Samsung | SM-F721B | Android 15 | - | 1 | 9 Jul 2025 |
| Samsung | SM-F766B | Android 16 | - | 1 | 11 Nov 2025 |
| Samsung | SM-F971B | Android 17 | OEM Samsung | 1 | 18 Sep 2026 |
| Samsung | SM-G766B | Android 15 | - | 1 | 17 Oct 2025 |
| Samsung | SM-G766B | Android 16 | OEM Samsung | 1 | 5 Sep 2026 |
| Samsung | SM-G780F | Android 13 | OEM Samsung | 1 | 29 Dec 2025 |
| Samsung | SM-G973U | Android 12 | OEM Samsung | 2 | 10 Jun 2026 |
| Samsung | SM-G991B | Android 15 | OEM Samsung | 1 | 19 Apr 2026 |
| Samsung | SM-N986B | Android 13 | - | 9 | 17 Jul 2025 |
| Samsung | SM-S721U | Android 15 | - | 5 | 5 Aug 2025 |
| Samsung | SM-S731B | Android 16 | OEM Samsung | 1 | 11 Aug 2026 |
| Samsung | SM-S906B | Android 15 | - | 1 | 2 Jun 2025 |
| Samsung | SM-S908U | Android 16 | OEM Samsung | 2 | 17 Sep 2026 |
| Samsung | SM-S921B | Android 15 | OEM Samsung | 2 | 22 Jul 2025 |
| Samsung | SM-S921B | Android 16 | OEM Samsung | 1 | 17 Sep 2026 |
| Samsung | SM-S921U | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-S926B | Android 16 | OEM Samsung | 1 | 14 Apr 2026 |
| Samsung | SM-S928B | Android 16 | OEM Samsung | 2 | 12 Jun 2026 |
| Samsung | SM-S928U1 | Android 15 | - | 1 | 12 Sep 2025 |
| Samsung | SM-S931B | Android 15 | - | 1 | 20 Sep 2025 |
| Samsung | SM-S931B | Android 16 | - | 1 | 23 Nov 2025 |
| Samsung | SM-S936B | Android 16 | - | 1 | 18 Dec 2025 |
| Samsung | SM-S937B | Android 15 | - | 1 | 25 Aug 2025 |
| Samsung | SM-S938B | Android 15 | - | 2 | 25 Aug 2025 |
| Samsung | SM-S942B | Android 17 | OEM Samsung | 1 | 25 May 2026 |
| Samsung | SM-S948U | Android 16 | - | 1 | 9 Sep 2026 |
| Samsung | SM-T636B | Android 15 | - | 2 | 12 Oct 2025 |
| Samsung | SM-T976B | Android 13 | - | 1 | 21 Jul 2025 |
| Samsung | SM-X200 | Android 14 | - | 1 | 27 Aug 2025 |
| Samsung | SM-X716B | Android 15 | - | 1 | 27 Jun 2025 |
| Samsung | SM-X910 | Android 14 | - | 1 | 26 Jun 2025 |
| Samsung | SM-X910 | Android 15 | - | 1 | 12 Sep 2025 |
Known labels
Locale-aware display names seen in the wild.
| Label | Locale | Seen |
|---|---|---|
| KPECore | en-gb | 26 |
| KPECore | en | 20 |
| KPECore | en-us | 18 |
| KPECore | it-IT | 5 |
| KPECore | nl-nl | 5 |
| KPECore | de-de | 3 |
| KPECore | en-nl | 3 |
| KPECore | es-us | 3 |
| KPECore | it-it | 2 |
| KPECore | es-ES | 2 |
| KPECore | en-GB | 2 |
| KPECore | es-es | 2 |
| KPECore | 2 | |
| KPECore | fr-fr | 2 |
| KPECore | ru-ru | 1 |
| KPECore | en-US | 1 |
| KPECore | en-au | 1 |
| KPECore | es-US | 1 |
| KPECore | fr-FR | 1 |
| KPECore | pl-PL | 1 |
| KPECore | pl-pl | 1 |