Android Enterprise Security Lab PoC
Open-Source Security Research PoC | Apache 2.0

Understanding Android
Enterprise MDM & Knox Lock

A comprehensive security research framework and analytical environment for studying Android DevicePolicyManager APIs, Work Profile permissions, OEM Config, and financing lock app behavior.

bash ~ adb_mdm_inspector.sh
Android 14 (API 34)

# Initializing Android MDM Device Owner Inspection...

$ adb shell dumpsys device_policy

Current Active Device Owner:

-> ComponentName{com.enterprise.mdm.guard/com.enterprise.mdm.AdminReceiver}

-> User ID: 0 (System Default)

-> Key Policies: DISALLOW_FACTORY_RESET, DISALLOW_SAFE_BOOT, SYSTEM_ALERT_WINDOW

[!] Knox Guard eFuse Verification: HARDWARE_ENFORCED

[✓] System privilege scan completed. 0 unauthorized modifications detected.

Core Knowledge Base

Why Financing Apps Lock Devices

Financing lock applications (such as ShopUp, PayJoy, or Knox Guard) do not rely on standard user app permissions. They integrate directly into the Android System Policy Framework.

Device Owner Privileges

The lock agent is registered as a Device Admin or Device Owner (`dpm`). This allows it to block factory resets, disable developer mode, and render un-dismissible full-screen system overlays.

Hardware Root of Trust

Advanced platforms like Samsung Knox Guard bind device compliance to hardware eFuses and Serial/IMEI cloud attestation. Hard resets won't remove locks if the cloud flags installment defaults.

ADB & Package Inspection

This open-source lab documents how researchers analyze active package states, inspect policy manager configurations, and audit device management boundaries safely.

System Stack Analysis

Android Security Layer Architecture

System Overlay & Screen Lockdown

TYPE_APPLICATION_OVERLAY / SYSTEM_ALERT_WINDOW

Financing lock applications draw an inescapable view over all other system windows when an installment is overdue. This window intercepts touch events, hides the status bar, and prevents launching the System Settings menu or other applications.

Analytical Framework

Research Methodology & Capabilities

Package State Detection

Identification of registered enterprise receivers, active package signatures, and component visibility across dual user profiles (`user 0` and work containers).

ADB Shell Privilege Auditing

Automated scripts to query `dumpsys device_policy`, inspect active administrative component names, and verify USB Debugging policy flags.

Knox & eFuse Resilience Testing

Evaluation of hardware-backed attestation security. Analysis of why software-only modifications fail against hardware trust anchors.

Defensive Remediation Guidelines

Documentation for Android developers and financial app architects on hardening MDM implementations using Play Integrity and zero-trust verification.

Interactive Proof-of-Concept

Terminal & Inspection Scripts

#!/usr/bin/env bash
# Android Enterprise MDM Package Inspector - Educational PoC

echo "[+] Scanning active Device Administrator packages..."
adb shell pm list packages -e | grep -E "admin|mdm|lock|knox|pay"

echo "[+] Auditing DevicePolicyManager owner status..."
adb shell dumpsys device_policy | grep -A 5 "Device Owner:"

echo "[+] Inspecting USB Debugging restriction flags..."
adb shell settings get global adb_enabled

Responsible Research & Ethical Disclosure Notice

This repository is created exclusively for educational purposes, security research, and Android framework analysis. It does not contain commercial bypass software, copyrighted proprietary binaries, or tools designed to alter legal financing obligations. Security researchers must adhere to local telecommunication laws and ethical research principles.

Apache 2.0 Licensed Educational Use Only