System app database

Package

com.samsung.android.knox.zt.framework

KnoxZT Framework

37device profiles
52observations
0user-facing hits
18 Sep 2026last seen

Guidance

Disable with caution verified 4 Sep 2026

Labelled "KnoxZT Framework" on the device, this is a Samsung Knox component of around 20 MB, signed by a Samsung OEM key that also signs the Android framework, and it has no launcher icon. The name matches Samsung's Knox Zero Trust Framework, the enterprise feature set Samsung documents under its Knox mobile security whitepaper; Samsung's documentation does not name this package, so that mapping is inferred here from the package name and label rather than taken from a Samsung statement. Samsung describes the Knox Zero Trust Framework as requiring an EMM or UEM and as building on Android 14 to provide advanced security capabilities. Its documented parts include the Knox Security Log, an on-device database held in an isolated Linux domain outside the main operating system and reachable only through the Knox framework, which gathers security signals for threat detection with privacy filters applied to redact sensitive user data, and Knox Suspicious URL Detection, which uses on-device machine learning to spot phishing links. Samsung documents the Knox Security Log as available only for fully managed company-owned devices enrolled in Knox Asset Intelligence, and documents Knox Suspicious URL Detection as enabled and configured for devices using Knox Asset Intelligence as part of Knox Security Logs, so those capabilities are realised through that service rather than on a standalone device. For Android Enterprise, EMM and kiosk deployments this is enterprise security telemetry rather than bloatware. If you use Knox Asset Intelligence or a UEM that consumes Knox security signals, disabling this component risks silently removing the detection you are paying for, so treat it as caution. On a device with no EMM and no Knox Asset Intelligence subscription there should be less for it to do, but Samsung does not document what it does in that state, so do not assume it is inert. Version note: Samsung ties the framework to Android 14 and states that the Knox Security Log is supported on devices running Android 15 or later, so what this component contributes depends on the Android version of the device. Samsung's page does not name the Knox or One UI release that introduced the framework, and on this site the package is recorded only with target SDKs 34 to 36 (Android 14 to 16), which is consistent with a recent addition but is not a substitute for a documented introduction date.

Package intelligence

Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.

1
signing cert
consistent across devices
16
permissions
largest set observed
18.9 MB – 21.6 MB
APK size
34 – 36
target SDK
1.0.00.22 → 1.4.00.23
versions observed
18
device profiles
Declared permissions (16)

Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.

PermissionDescription
CAMERA This app can take pictures and record videos using the camera while the app is in use.
INTERACT_ACROSS_USERS Signature or privileged system permission.
MANAGE_EXTERNAL_STORAGE Signature-level system permission, for platform-signed apps. docs ↗
MANAGE_USERS Signature or privileged system permission.
NETWORK_SETTINGS Signature-level system permission, for platform-signed apps.
POST_NOTIFICATIONS Allows the app to show notifications
SCHEDULE_EXACT_ALARM This app can schedule work to happen at a desired time in the future. This also means that the app can run when you\u2019re not actively using the device.
WAKE_LOCK Allows the app to prevent the phone from going to sleep.
WRITE_SETTINGS Allows the app to modify the system's settings data. Malicious apps may corrupt your system's configuration.
com.samsung.android.kfbp.BIND_SERVICE -
com.samsung.android.knox.permission.KNOX_ANALYTICS_INTERNAL -
com.samsung.android.knox.permission.KNOX_PROTECTED_KEYSTORE -
com.samsung.android.knox.permission.SECURE_LOG_ACCESS_PROVIDER -
com.samsung.android.knox.zt.framework.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION -
com.samsung.android.knox.zt.permission.ACCESS_PROVIDER -
com.samsung.android.security.permission.SAMSUNG_KEYSTORE_PERMISSION -

Manage on devices

ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.

Disable for the current user
adb shell pm disable-user --user 0 com.samsung.android.knox.zt.framework
Remove for the current user - a per-user uninstall; the APK stays on /system, so Restore re-adds it (-k keeps app data)
adb shell pm uninstall -k --user 0 com.samsung.android.knox.zt.framework
Re-enable
adb shell pm enable com.samsung.android.knox.zt.framework
Restore (re-install for the current user)
adb shell pm install-existing com.samsung.android.knox.zt.framework

Seen on

Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.

OEMModelAndroidProvenanceObservationsLast seen
Samsung SM-A135F Android 14 OEM Samsung 3 21 Jan 2026
Samsung SM-A137F Android 14 - 1 17 Jan 2026
Samsung SM-A236B Android 14 OEM Samsung 2 10 Apr 2026
Samsung SM-A266B Android 15 - 2 21 Aug 2025
Samsung SM-A266B Android 16 - 1 26 Jan 2026
Samsung SM-A346B Android 15 OEM Samsung 1 27 Jul 2026
Samsung SM-A536B Android 15 - 1 19 Jun 2025
Samsung SM-A536B Android 16 OEM Samsung 1 29 Jul 2026
Samsung SM-A556B Android 15 - 1 1 Jul 2025
Samsung SM-A566B Android 16 OEM Samsung 3 12 Sep 2026
Samsung SM-F721B Android 15 - 1 9 Jul 2025
Samsung SM-F766B Android 16 - 1 11 Nov 2025
Samsung SM-F971B Android 17 OEM Samsung 1 18 Sep 2026
Samsung SM-G766B Android 15 - 1 17 Oct 2025
Samsung SM-G766B Android 16 OEM Samsung 1 5 Sep 2026
Samsung SM-G991B Android 15 OEM Samsung 1 19 Apr 2026
Samsung SM-S721U Android 15 - 5 5 Aug 2025
Samsung SM-S731B Android 16 OEM Samsung 1 11 Aug 2026
Samsung SM-S906B Android 15 - 1 2 Jun 2025
Samsung SM-S908U Android 16 OEM Samsung 2 17 Sep 2026
Samsung SM-S921B Android 15 OEM Samsung 2 22 Jul 2025
Samsung SM-S921B Android 16 OEM Samsung 1 17 Sep 2026
Samsung SM-S921U Android 15 - 1 19 Jun 2025
Samsung SM-S926B Android 16 OEM Samsung 1 14 Apr 2026
Samsung SM-S928B Android 16 OEM Samsung 2 12 Jun 2026
Samsung SM-S928U1 Android 15 - 1 12 Sep 2025
Samsung SM-S931B Android 15 - 1 20 Sep 2025
Samsung SM-S931B Android 16 - 1 23 Nov 2025
Samsung SM-S936B Android 16 - 1 18 Dec 2025
Samsung SM-S937B Android 15 - 1 25 Aug 2025
Samsung SM-S938B Android 15 - 2 25 Aug 2025
Samsung SM-S942B Android 17 OEM Samsung 1 25 May 2026
Samsung SM-S948U Android 16 - 1 9 Sep 2026
Samsung SM-T636B Android 15 - 2 12 Oct 2025
Samsung SM-X716B Android 15 - 1 27 Jun 2025
Samsung SM-X910 Android 14 - 1 26 Jun 2025
Samsung SM-X910 Android 15 - 1 12 Sep 2025

Known labels

Locale-aware display names seen in the wild.

LabelLocaleSeen
KnoxZT Framework en 20
KnoxZT Framework en-gb 18
KnoxZT Framework en-us 17
KnoxZT Framework it-IT 5
KnoxZT Framework nl-nl 4
KnoxZT Framework en-nl 3
KnoxZT Framework de-de 2
KnoxZT Framework en-GB 2
KnoxZT Framework es-ES 2
KnoxZT Framework es-es 2
KnoxZT Framework it-it 2
KnoxZT Framework ru-ru 1
KnoxZT Framework en-au 1
KnoxZT Framework pl-PL 1
KnoxZT Framework pl-pl 1
KnoxZT Framework fr-fr 1