LOTHardware LOTHardware / Hak5 Rubber Ducky

The Rubber Ducky, crafted by Hak5, is a discreet and highly sophisticated keystroke injection tool. Designed for advanced penetration testers and security professionals, this pocket-sized device masquerades as a standard USB flash drive but operates with an entirely different purpose. Leveraging advanced scripting capabilities and preloaded payloads, the Rubber Ducky can execute complex and covert attacks on target systems with lightning speed. Its ability to inject keystrokes, mimic human typing patterns, and execute payloads in milliseconds makes it an invaluable asset for security assessments, uncovering vulnerabilities, and strengthening digital defenses. The Rubber Ducky is a must-have tool for professionals seeking to assess and fortify the security of computer systems with precision and efficiency.

image

Limitations

Take into consideration that VendorID and ProductID can be spoofed natively by the Rubber Ducky.
The following IDs are the default ones.

Device Instance Path

Using ATTACKMODE HID:

HID\VID_03EB&PID_2401&REV_0100

Using ATTACKMODE HID STORAGE:

HID\VID_03EB&PID_2422&REV_0100

VendorID

03EB

ProductID

Using ATTACKMODE HID:

2401

Using ATTACKMODE HID STORAGE:

2422

Class

HID

Author

@enesilhaydin
@_ezlucky_

Sigma/Yara Rules

Coming Soon…