Skip to content

Root Management

Root management covers everything you need to install, run and maintain root on your Android device: root managers for Magisk, KernelSU and APatch, temporary root solutions for locked-bootloader devices, module managers and metamodules, the LSPosed/Xposed and Zygisk frameworks, and the tools that keep root hidden from apps (Play Integrity, SUSFS). Apps and modules live together here because they solve the same problem - controlling root access.

TIP

New to rooting? Read the Complete Rooting Guide first, then come back for the tools.

Root Managers ​

  • ⭐ KernelSU - A Kernel based root solution for Android. FOSS
  • ⭐ Magisk - Manage Magisk modules and root permissions. FOSS
  • APatch - The patching of Android kernel and Android system. FOSS
  • FolkPatch - A Root management tool focused on interface optimization and feature extension, based on APatch. FOSS
  • KernelSU-next - An advanced Kernel based root solution for Android. FOSS
  • ReSukiSU - Fork of SukiSU-Ultra with additional features. FOSS
  • SukiSU-Ultra - A kernel-based root solution for Android devices, forked from KernelSU with some useful changes. FOSS

Temporary Root (Locked Bootloader) ​

What is temporary root (GhostLock)?

Exploits like GhostLock (CVE-2026-43499) - a 15-year-old Linux kernel bug - grant root in memory only, for the current boot. No bootloader unlock, no flashing, no Knox trip, no data wipe: reboot and the device is bone-stock again. The trade-offs: root doesn't survive reboots, you can't flash ROMs/recoveries, and it only works on specific devices running firmware up to ~the June 2026 patch level.


  • ⭐ Root My Galaxy - One-tap temporary root for Snapdragon Galaxy flagships (S24/S25 series, S24 FE, A56...) via GhostLock; bootloader stays locked, Knox isn't tripped. FOSS

Bootloop Protection ​

LSPosed & Xposed ​

NOTE

LSPosed allows you to use Xposed modules, that can modify or extend the functionality of your Android system and apps.

  • ⭐ Vector - Open Source Fork of original LSPosed with dynamic module loading, and other improvements. FOSS [M]
  • LSPosed - A Riru / Zygisk module that provides an ART hooking framework delivering consistent APIs with the OG Xposed, leveraging the LSPlant hooking framework. Proprietary

TIP

See our LSPosed installation guide ↗ for setup instructions.

Metamodules ​

NOTE

Metamodules provides the core mounting infrastructure for the module system. Unlike regular modules that modify system files, metamodules control how regular modules are installed and mounted.

  • ⭐ Meta-overlayfs - Official reference implementation using OverlayFS for most users and standard setup. FOSS [K]
  • ⭐ Mountify - OverlayFS with tmpfs/ext4 sparse support for reduced detection, works on APatch/Magisk too. FOSS [M] [K] [A]
  • Magic Mount Metamodule - An implementation of a metamodule using Magic Mount, based on MKSU. FOSS [M] [K] [A]
  • Meta-hybrid_mount - Three-engine mount orchestration (OverlayFS + Magic Mount + Kasumi LKM) with conflict monitor, SolidJS WebUI, auto-fallback, and EROFS storage backend support. FOSS [K] [A]
  • meta-mm - The official KernelSU Modules Repo's Magic Mount metamodule. Lighter alternative to meta-magic_mount for users who just want Magisk-compatible mounting without extra tooling. FOSS [K]
  • ZeroMount - Mountless module loading with Kernel-level VFS path redirection & SUSFS integration, WebUI, bootloop guard, and strategy fallback. FOSS [M] [K] [A]

Module Managers ​

  • ⭐ MMRL - An Android app that helps manage your own modules repository. FOSS [M] [K] [A]| |
  • KPatch Next Module - Standalone implementation of KPM (KernelSU Patch Module) support for Magisk/KernelSU with WebUI. FOSS [M] [K]
  • Magisk Manager for Recovery Mode - Easily manage your Magisk Modules from a terminal session in your custom recovery. FOSS [M]

Root Detection & Testing ​

  • ⭐ Android-Native-Root-Detector - A tool for detecting root on android. FOSS
  • ⭐ Duck Detector Fork - Duck Detector fork with additional features and improvements. FOSS
  • Android-Device-Trust - Android device attestation and fingerprinting tool. FOSS
  • Chunqiu Detector - Solutions, scripts, and modules for bypassing and troubleshooting Chunqiu Detector checks on rooted Android devices. FOSS
  • Duck Detector - Android environment integrity inspection tool for root, hook, bootloader, SELinux, virtualization, and attestation signals. FOSS
  • Key Attestation - Generates, saves, parses and verifies Android key and ID attestation certificate chains for self-testing and diagnostics. FOSS
  • Kknd Root Detector - Deep root, hook framework, SELinux and system integrity detection combining native C++ and Kotlin checks. FOSS
  • MagiskDetection - Collection of Some publicly Available POC Apps to Detect Root/Magisk presence. Proprietary
  • PIF Detector - Native app designed to detect modifications, bypasses, or "fixes" applied to the Google Play Integrity API. FOSS [M] [K]
  • Play Integrity Alert - Get notified when an app calls the Play Integrity API. FOSS [LSP]
  • Play Integrity API Checker - This app shows info about your device integrity as reported by Google Play Services. If any of this fails could mean your device is rooted or tampered in a way. FOSS|
  • Securify - Yet Another Root Checker and Play Integrity API Application. FOSS
  • ZygoteNextProbe - Research probe that checks whether Android 17's zygote_next native isolated services leak a global mount view - potentially exposing Magisk/Zygisk/LSPosed mounts to apps. FOSS

Root Hiding & Play Integrity ​

What is Play Integrity?

A Google API that lets apps verify a device is "genuine" - unmodified, Play-certified, and bootloader-locked. Apps use it to block rooted/modified devices. Verdicts: MEETS_BASIC_INTEGRITY < MEETS_DEVICE_INTEGRITY < MEETS_STRONG_INTEGRITY.

Why hide root?

Banking, payment, and some streaming/game apps detect root and refuse to run. Hiding root lets them work on a rooted device.

What's realistic in 2026?

Since Google's mid-2025 changes, DEVICE_INTEGRITY requires a locked bootloader on Android 13+, and STRONG_INTEGRITY needs an unrevoked hardware keybox (increasingly scarce). For most rooted users, passing BASIC + DEVICE integrity (via PIF + TrickyStore) is the practical ceiling - chasing STRONG is a deep, often futile rabbit hole.

  • ⭐ HMA-OSS - FOSS rewrite of Hide My Applist; hides your app list, settings, and package installers. FOSS [LSP]
  • ⭐ Shamiko - Hides Magisk root from detection. Proprietary [M]
  • ⭐ TEESimulator - Create a complete, software-based simulation of a hardware-backed Trusted Execution Environment (TEE) for Key Attestation. FOSS [M] [K]
  • Always Strong - Bundles TEESimulator-RS and PlayIntegrityFork into a single module for strong integrity on rooted devices. FOSS [M] [K]
  • AuditPatch - Hooks logd to replace sensitive SELinux contexts in the audit log, fixing AVC log leak detection without SUSFS or ZygiskNext. Proprietary [M] [K]
  • DirtySepolicy Bypass - Bypasses new DirtySepolicy on rooted Android devices to keep apps working. FOSS [M] [K] [A]
  • Komodo Build Props - Spoofs your device as a Pixel 9 Pro XL (komodo). FOSS [M]
  • NoHello - Lightweight Zygisk module to hide root. FOSS [M]
  • OhMyKeymint - Custom keystore implementation for Android Keystore Spoofer. FOSS [M] [K]
  • Play Integrity Fix (inject) - Actively maintained fork using injected GMS/Play Store spoofing with a WebUI. FOSS [M]
  • Play Integrity Fork (PIF) - The most actively maintained PIF. Fixes DEVICE_INTEGRITY verdicts with custom fields/props. Recommended starting point after chiteroman's original was discontinued. FOSS [M]
  • PlaycurlNEXT - Fixes Play Integrity (and SafetyNet) verdicts with custom fields and props. FOSS [M] [K]
  • ReZygisk's Treat Wheel - Hides Magisk/root traces exclusively for ReZygisk, acting as the best userspace root hiding tool. FOSS [M] [K]
  • Sensitive Props - Modifies system properties and applies device-specific fixes to bypass SafetyNet/Play Integrity. FOSS [M]
  • Specter - Unified Play Integrity and root hiding stack for Android. Successor of Yurikey. FOSS [M] [K]
  • TEESimulator-RS - Fork of TEESimulator with native Rust certificate generation, key persistence, and AOSP-compliant attestation behavior. FOSS [M] [K]
  • Tricky Addon – Update Target List - KSU WebUI to configure TrickyStore's target.txt. FOSS [K]
  • TrickyStore - Modifies the certificate chain for Android key attestation (keybox-based). The original/reference module. Proprietary [M] [K]
  • TrickyStore OSS - Open-source alternative to TrickyStore. FOSS [M] [K]
  • YuriKey - Systemless module to obtain strong integrity easily. FOSS [M] [K]
  • Zygisk Assistant - Zygisk module to hide root on KernelSU, Magisk, and APatch. FOSS [M]

TIP

Combine these with a proper Zygisk implementation for best results.


Susfs ​

What is SUSFS? SUSFS (Systemless User Space File System) is a kernel-level module that allows root-hiding and system modifications without altering the system partition. It provides a stealthy environment for modules to operate, making it harder for apps to detect root or modifications.

  • ⭐ SUSFS for KernelSU - Add-on root-hiding service for SUSFS-patched kernels (KernelSU/Next). The core of modern KSU hiding setups. FOSS [M] [K]
  • BRENE - SUSFS/KernelSU module for patched kernels with enhanced root hiding & spoofing. FOSS [M] [K]
  • ReSuSFS: Removed on author's request

Zygisk ​

What is Zygisk?

A feature that lets modules inject code into Android's Zygote process for system-level modifications like root hiding and app patching.


  • ⭐ Zygisk Next The "Gold Standard" for detection evasion. It is a standalone Zygisk implementation that offers the most advanced stealth features, including a dedicated Zygote Monitor and dashboard. Proprietary [M] [K] [A]
  • NeoZygisk A minimalist, high-stealth implementation using ptrace injection. It focuses on "trace cleaning," aiming to remove all injection artifacts from memory once modules are loaded. FOSS [M] [K] [A]
  • OnyxZygisk - A ptrace-powered Zygisk implementation with a built-in WebUI, hot-swappable FN modules, and an advanced DenyList. FOSS [M] [K] [A]
  • ReZygisk A high-performance implementation entirely rewritten in C. It introduces custom linkers to bypass modern linker-based detections, offering a WebUI for status monitoring and compatibility with Android 15 and 16. FOSS [M] [K] [A]
  • VexZygisk - Standalone implementation of Zygisk for KernelSU and APatch. FOSS [M] [K] [A]
Comparison table
Magisk Built-inZygisk NextNeoZygiskReZygisk
Key AdvantageOfficial & simpleDetection evasionStealth / cleaningSpeed / open source
LicenseGPL-3.0ProprietaryGPL-3.0GPL-3.0 / AGPL-3.0
Root SupportMagisk onlyMagisk, KSU, APatchMagisk, KSU, KSU Next, APatchMagisk, KSU, APatch
Hiding ApproachBasic DenyListZN Linker + anon memory + ShamikoPtrace injection + unmountingCustom linker + maps hiding
Strengths✅ Stable, well-documented
✅ Widest arch (incl. x86)
✅ Most feature-rich
✅ Largest community
✅ Hard to trace in memory
✅ Minimal & open
✅ Fastest (native C)
✅ Fully open & auditable
Trade-offs❌ Magisk-only
❌ Easily detected
❌ Closed source
❌ ZN Linker experimental
❌ 64-bit only
❌ Smaller community
❌ RC phase
❌ Some compat issues