Windows utility for detecting and defeating rogue USB devices.
-
Updated
Jun 22, 2022 - C#
Windows utility for detecting and defeating rogue USB devices.
Educational security research notes documenting USB HID (BadUSB/Rubber Ducky) concepts from a defensive perspective. The repository preserves historical filenames while emphasizing detection, prevention, user awareness, and ethical lab use. No payloads, automation scripts, or actionable exploits are provided.
UShield - USB Guard Camera Edition tracks USB/hard drive plug events and file operations, with USB block and whitelist controls. It auto activates the camera to capture snapshots every 3 seconds upon device insertion for full data protection.
USB Drive Protection Software
Detect & stop BadUSB / Rubber Ducky keystroke-injection attacks — a beautiful, cross-platform (Windows/macOS/Linux) defense app. Local-only, no telemetry.
Adaptive BadUSB/HID attack emulation + behavioral endpoint detection with the Flipper Zero. Defensive-security research: build a labeled human-vs-injected keystroke dataset, train an EDR-style detector, and red-team it with an adaptive humanized attacker.
Rubber Ducky is an awareness initiative focused on educating individuals and organizations about potential cybersecurity threats that can be delivered through USB devices, particularly targeting issues like ransomware, backdoors, and keyloggers. Leveraging the concept of Bad USB and the functionality of Rubber Ducky USBs.
Flipper Zero USB safety scanner: tells a charge-only port from a data port, and catches a 'flash drive' that is really a keyboard. Reads the resistors USB uses to declare itself - no USB host needed.
tCrypt2Go – Lock-and-Unlock Utilities for TrueCrypt Portable
🔒 Block all USB devices by default — require password auth via polkit before any device is allowed. Protects against BadUSB, Rubber Ducky & HID injection attacks.
Offline security tool that vets removable media before it enters an air-gapped environment. Analyzes the device, partition table, filesystem, and files from a read-only snapshot, without mounting.
spyUSB: An integrated endpoint security solution utilizing Deep Neural Networks (DNN) to detect USB malware injection, coupled with Tokenization and CloudConceal for data exfiltration prevention.
Herramienta de seguridad para Windows que utiliza unidades USB como llaves físicas para bloquear automáticamente el sistema.
Local-only encrypted vault with post-quantum key protection.
USB-Security-Web
Advanced USB Malware Detection, File Recovery & Digital Forensics Suite built with PowerShell and WPF.
Defensive Windows 11 USB storage control with password access, Microsoft Defender scanning, auto-blocking, remediation, and secure formatting.
macOS USB storage classification and UUID allowlisting PoC with safe-by-default unmount handling.
USB endpoint security framework with real-time monitoring, VirusTotal integration, and SOC-style threat detection.
SentinelOne policy configuration enabling automatic scanning of USB and external storage devices on Windows and macOS endpoints.
To associate your repository with the usb-security topic, visit your repo's landing page and select "manage topics."