How to uninstall KnockKnock on Mac
Save wanted KnockKnock scan results before removing the app. The vendor’s instructions describe a self-contained scanner that lists persistent software. Its findings are not all malware and are not files owned by KnockKnock.
Quit and remove the app
Finish or stop the scan and quit KnockKnock, then move KnockKnock.app to the Trash as the vendor describes. Do not remove every application, launch item or extension shown in a scan just to uninstall the scanner.
Data to keep or review
~/Library/Preferences/com.objective-see.KnockKnock.plistheld app preferences in the test. Keep a copy if you want the settings.- An attributable temporary cache was observed. The cask also names
~/Library/Caches/com.objective-see.KnockKnockand~/Library/Saved Application State/com.objective-see.KnockKnock.savedState. - Exported reports and the third-party software shown in them are separate from scanner preferences. Full Disk Access is managed by macOS, not by deleting its permission database.
After copying wanted settings, open Finder and press Shift + Command + G. Paste each full path above separately, inspect the item, then move the confirmed app-owned data to the Trash.
Check the result
pgrep -ifl KnockKnock
ls -ld /Applications/KnockKnock.app "$HOME/Library/Preferences/com.objective-see.KnockKnock.plist"
No process output means this name was not found, not that every helper has gone. Check any match against the app’s actual executable path. A missing-path error from ls means only that location is absent; permission errors leave its state unknown. A surviving folder can be intentional data to keep.
If you installed it with Homebrew
The cask has no separate uninstall helper. Zap names exact caches, preferences and saved state; it does not remove the software found by a scan.
To uninstall without zap, use:
brew uninstall --cask knockknock
Mole checks Homebrew's full removal list and skips --zap when it reaches unchecked data, shared files or anything it cannot verify. It still removes the leftovers you selected. A direct brew uninstall --cask --zap knockknock runs Homebrew’s full zap list without consulting Mole’s checkboxes.
What Mole lists
Mole selects the app, exact preferences and attributable cache rows by default. Keep wanted preferences by unchecking that row. Software reported by KnockKnock is not included merely because it appears in the report.
These are the defaults with “Remove data and settings with apps” turned off. Enabling that preference can also select eligible reviewed app data; shared stores, protected profiles and agent archives keep their individual review or remain locked. Check the final list before confirming.
What this test covered
On September 25, 2026, KnockKnock 4.1.0 was copied from the official archive and uninstalled with a development build of Mole. The app, preference and temporary-cache rows were removed. This uninstall record does not verify malware detection, VirusTotal submissions or cleanup of findings.
