Package
com.samsung.android.knox.zt.framework
KnoxZT Framework
Guidance
Labelled "KnoxZT Framework" on the device, this is a Samsung Knox component of around 20 MB, signed by a Samsung OEM key that also signs the Android framework, and it has no launcher icon. The name matches Samsung's Knox Zero Trust Framework, the enterprise feature set Samsung documents under its Knox mobile security whitepaper; Samsung's documentation does not name this package, so that mapping is inferred here from the package name and label rather than taken from a Samsung statement. Samsung describes the Knox Zero Trust Framework as requiring an EMM or UEM and as building on Android 14 to provide advanced security capabilities. Its documented parts include the Knox Security Log, an on-device database held in an isolated Linux domain outside the main operating system and reachable only through the Knox framework, which gathers security signals for threat detection with privacy filters applied to redact sensitive user data, and Knox Suspicious URL Detection, which uses on-device machine learning to spot phishing links. Samsung documents the Knox Security Log as available only for fully managed company-owned devices enrolled in Knox Asset Intelligence, and documents Knox Suspicious URL Detection as enabled and configured for devices using Knox Asset Intelligence as part of Knox Security Logs, so those capabilities are realised through that service rather than on a standalone device. For Android Enterprise, EMM and kiosk deployments this is enterprise security telemetry rather than bloatware. If you use Knox Asset Intelligence or a UEM that consumes Knox security signals, disabling this component risks silently removing the detection you are paying for, so treat it as caution. On a device with no EMM and no Knox Asset Intelligence subscription there should be less for it to do, but Samsung does not document what it does in that state, so do not assume it is inert. Version note: Samsung ties the framework to Android 14 and states that the Knox Security Log is supported on devices running Android 15 or later, so what this component contributes depends on the Android version of the device. Samsung's page does not name the Knox or One UI release that introduced the framework, and on this site the package is recorded only with target SDKs 34 to 36 (Android 14 to 16), which is consistent with a recent addition but is not a substitute for a documented introduction date.
Package intelligence
Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.
- Signed by the device maker's own signing key (Samsung), so it is an OEM preinstall, and that single certificate is consistent across all 18 device profiles. It also signs the Android framework, so it is a platform-level key on its device(s). Inferred from the certificate appearing only on Samsung devices (508 packages, 10196 observations).
- Its largest observed manifest declares 16 permissions: 2 runtime (user-granted), 6 signature or system-level, 1 install-time and 7 vendor or uncatalogued.
- Never reported as user-facing, so it runs as a background or system component rather than an app the user opens.
Declared permissions (16)
Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.
| Permission | Description |
|---|---|
CAMERA |
This app can take pictures and record videos using the camera while the app is in use. |
INTERACT_ACROSS_USERS |
Signature or privileged system permission. |
MANAGE_EXTERNAL_STORAGE |
Signature-level system permission, for platform-signed apps. docs ↗ |
MANAGE_USERS |
Signature or privileged system permission. |
NETWORK_SETTINGS |
Signature-level system permission, for platform-signed apps. |
POST_NOTIFICATIONS |
Allows the app to show notifications |
SCHEDULE_EXACT_ALARM |
This app can schedule work to happen at a desired time in the future. This also means that the app can run when you\u2019re not actively using the device. |
WAKE_LOCK |
Allows the app to prevent the phone from going to sleep. |
WRITE_SETTINGS |
Allows the app to modify the system's settings data. Malicious apps may corrupt your system's configuration. |
com.samsung.android.kfbp.BIND_SERVICE |
- |
com.samsung.android.knox.permission.KNOX_ANALYTICS_INTERNAL |
- |
com.samsung.android.knox.permission.KNOX_PROTECTED_KEYSTORE |
- |
com.samsung.android.knox.permission.SECURE_LOG_ACCESS_PROVIDER |
- |
com.samsung.android.knox.zt.framework.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION |
- |
com.samsung.android.knox.zt.permission.ACCESS_PROVIDER |
- |
com.samsung.android.security.permission.SAMSUNG_KEYSTORE_PERMISSION |
- |
Manage on devices
ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.
/system, so Restore re-adds it (-k keeps app data)Seen on
Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.
| OEM | Model | Android | Provenance | Observations | Last seen |
|---|---|---|---|---|---|
| Samsung | SM-A135F | Android 14 | OEM Samsung | 3 | 21 Jan 2026 |
| Samsung | SM-A137F | Android 14 | - | 1 | 17 Jan 2026 |
| Samsung | SM-A236B | Android 14 | OEM Samsung | 2 | 10 Apr 2026 |
| Samsung | SM-A266B | Android 15 | - | 2 | 21 Aug 2025 |
| Samsung | SM-A266B | Android 16 | - | 1 | 26 Jan 2026 |
| Samsung | SM-A346B | Android 15 | OEM Samsung | 1 | 27 Jul 2026 |
| Samsung | SM-A536B | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 16 | OEM Samsung | 1 | 29 Jul 2026 |
| Samsung | SM-A556B | Android 15 | - | 1 | 1 Jul 2025 |
| Samsung | SM-A566B | Android 16 | OEM Samsung | 3 | 12 Sep 2026 |
| Samsung | SM-F721B | Android 15 | - | 1 | 9 Jul 2025 |
| Samsung | SM-F766B | Android 16 | - | 1 | 11 Nov 2025 |
| Samsung | SM-F971B | Android 17 | OEM Samsung | 1 | 18 Sep 2026 |
| Samsung | SM-G766B | Android 15 | - | 1 | 17 Oct 2025 |
| Samsung | SM-G766B | Android 16 | OEM Samsung | 1 | 5 Sep 2026 |
| Samsung | SM-G991B | Android 15 | OEM Samsung | 1 | 19 Apr 2026 |
| Samsung | SM-S721U | Android 15 | - | 5 | 5 Aug 2025 |
| Samsung | SM-S731B | Android 16 | OEM Samsung | 1 | 11 Aug 2026 |
| Samsung | SM-S906B | Android 15 | - | 1 | 2 Jun 2025 |
| Samsung | SM-S908U | Android 16 | OEM Samsung | 2 | 17 Sep 2026 |
| Samsung | SM-S921B | Android 15 | OEM Samsung | 2 | 22 Jul 2025 |
| Samsung | SM-S921B | Android 16 | OEM Samsung | 1 | 17 Sep 2026 |
| Samsung | SM-S921U | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-S926B | Android 16 | OEM Samsung | 1 | 14 Apr 2026 |
| Samsung | SM-S928B | Android 16 | OEM Samsung | 2 | 12 Jun 2026 |
| Samsung | SM-S928U1 | Android 15 | - | 1 | 12 Sep 2025 |
| Samsung | SM-S931B | Android 15 | - | 1 | 20 Sep 2025 |
| Samsung | SM-S931B | Android 16 | - | 1 | 23 Nov 2025 |
| Samsung | SM-S936B | Android 16 | - | 1 | 18 Dec 2025 |
| Samsung | SM-S937B | Android 15 | - | 1 | 25 Aug 2025 |
| Samsung | SM-S938B | Android 15 | - | 2 | 25 Aug 2025 |
| Samsung | SM-S942B | Android 17 | OEM Samsung | 1 | 25 May 2026 |
| Samsung | SM-S948U | Android 16 | - | 1 | 9 Sep 2026 |
| Samsung | SM-T636B | Android 15 | - | 2 | 12 Oct 2025 |
| Samsung | SM-X716B | Android 15 | - | 1 | 27 Jun 2025 |
| Samsung | SM-X910 | Android 14 | - | 1 | 26 Jun 2025 |
| Samsung | SM-X910 | Android 15 | - | 1 | 12 Sep 2025 |
Known labels
Locale-aware display names seen in the wild.
| Label | Locale | Seen |
|---|---|---|
| KnoxZT Framework | en | 20 |
| KnoxZT Framework | en-gb | 18 |
| KnoxZT Framework | en-us | 17 |
| KnoxZT Framework | it-IT | 5 |
| KnoxZT Framework | nl-nl | 4 |
| KnoxZT Framework | en-nl | 3 |
| KnoxZT Framework | de-de | 2 |
| KnoxZT Framework | en-GB | 2 |
| KnoxZT Framework | es-ES | 2 |
| KnoxZT Framework | es-es | 2 |
| KnoxZT Framework | it-it | 2 |
| KnoxZT Framework | ru-ru | 1 |
| KnoxZT Framework | en-au | 1 |
| KnoxZT Framework | pl-PL | 1 |
| KnoxZT Framework | pl-pl | 1 |
| KnoxZT Framework | fr-fr | 1 |