{"repo":"cecio/USBvalve","free":true,"listed":false,"github":"https://github.com/cecio/USBvalve","clone":"git clone https://github.com/cecio/USBvalve.git","description":"Expose USB activity on the fly","language":"C","stars":1344,"topics":["badusb","malware","usb","usb-hid","forensics"],"license":"MIT","category":"api-integrations-sdks","readme_excerpt":"[!NOTE] USBvalve Version 1.0.0 A complete rewrite of the application has been done: - moved away from Arduino IDE environment, now the code is written for the Pi Pico SDK - dependencies on external libraries have been reduced a lot - USB host support for Low Speed devices is now more robust (ATTiny85, EvilCrow, etc) - hardware and functionalities are almost unchanged, see the notes below for details Expose USB activity on the fly I'm sure that, like me, you were asked to put your USB drive in an unknown device...and then the doubt: what happened to my poor dongle, behind the scene? Stealing my files? Encrypting them? Or just installing a malware? With USBvalve you can spot this out in seconds: built on super cheap off-the-shelf hardware you can quickly test any USB file system activity and understand what is going on before it's too late! With USBvalve you can have an immediate feedback about what happen to the drive; the screen will show you if the fake filesystem built on the device is accessed, read or written: and from version 0.8.0 you can also use it as USB Host to detect BADUSB devices: This is an example of the BADUSB debugger available on serial port: If you prefer videos, you can also have a look to my Insomni'hack Presentation USBvalve Watch Starting from version 0.15.0 a new Pi Pico Watch version is supported. To compile the new version you have to uncomment the #define PIWATCH line at the beginning of the code. The hardware is a RP2040-based 1.28-inch TFT display","default_branch":null,"files":null,"tree":[],"storefront":"/r/cecio","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cecio/USBvalve/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}