USB Keystroke Injection Protection Logo

USB Keystroke Injection Protection

0
Free
Updated 11 March 2025
Visit Website

This tool is a daemon for blocking USB keystroke injection devices on Linux systems. It supports two different modes of operation: monitoring and hardening. In monitor mode, information about a potentially attacking USB device is collected and logged to syslog. In hardening mode, the attacking USB device is ejected from the operating system by unbinding the driver. Installation Prerequisites: The installation is mainly handled by setup.sh, however, there are some prerequisites that need to be adjusted before running the script: Install Python3.7 or later, python dev package, virtualenv (python3-venv) and PIP3 (python3-pip) if not already available on the system. Adjust the KEYSTROKE_WINDOW variable on top of the setup.sh file. This is the number of keystrokes the daemon looks at to determine whether its dealing with an attack or not. The lower the number, the higher the false positives will be (e.g., if the number is 2, the tool looks at only 1 interarrival time between those two keystrokes to determine whether it's an attack or not. Obviously, users sometimes hit two keys almost at the same time, which leads to the aforementioned false positives.

FEATURES

EXPLORE BY TAGS

SIMILAR TOOLS

A honeypot system designed to detect and analyze potential security threats

Object scanning system with scalable and flexible architecture for intrusion detection.

Impost is a powerful network security auditing tool with honey pot and packet sniffer capabilities.

pfSense is a leading open source firewall and network security solution, providing advanced protection and connectivity options.

A tool that reads IP packets from the network or a tcpdump save file and writes an ASCII summary of the packet data.

Tool used to scan a range of IP addresses to identify active hosts and gather information about them.

A fast and flexible HTTP enumerator for content discovery and credential bruteforcing

A repository of pre-defined detections for security threats and abnormal behaviors in Falco.

Passive sniffer tool for analyzing traffic patterns.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved