HID device wiki.

Which dialect each device speaks, an example payload, the official documentation and where to buy it. Kept in step with what the editor exports.

DuckyScript 1.0, Wind, 2.x and 3.0 · official documentation per device · responsible-use guidelines at the end.

The USB Rubber Ducky is the original keystroke injection tool by Hak5. Recognized by computers as a keyboard, it can inject pre-programmed keystrokes at superhuman speeds. DuckyScript 1.0 payloads are backwards compatible with DuckyScript 3.0.

Key features

  • Keystroke injection at superhuman speeds
  • Cross-platform compatibility (Windows, Mac, Linux)
  • MicroSD storage for payloads
  • Plug-and-play operation
  • LED status indicators
  • Button for payload control
  • Variables, conditions, loops, functions (v3.0)
  • Attack modes (HID, Storage)

example payload · DuckyScript 3.0

REM Hello World Example Script
DELAY 1000
GUI r
DELAY 500
STRING notepad
ENTER
DELAY 1000
STRING Hello from USB Rubber Ducky!
REM DuckyScript 3.0 supports variables:
VAR $COUNT = 0
WHILE ($COUNT < 5)
    STRINGLN Iteration $COUNT
    $COUNT = ($COUNT + 1)
END_WHILE
Flipper Devices

Flipper Zero

DuckyScript 1.0 (with Flipper extensions)

Flipper Zero is a portable multi-tool for pentesters and geeks. It includes BadUSB functionality that allows it to act as a USB keyboard and execute pre-programmed scripts. The BadUSB feature uses DuckyScript 1.0 syntax with Flipper-specific extensions like ALT+Numpad and SysRq commands.

Key features

  • Built-in screen for payload selection
  • Bluetooth and IR capabilities
  • Sub-GHz radio for RF analysis
  • NFC and RFID support
  • GPIO pins for hardware hacking
  • MicroSD expandable storage
  • Firmware updates via qFlipper
  • Active community and payload library

example payload · DuckyScript 1.0 (with Flipper extensions)

REM Flipper Zero BadUSB Script
ID 1234:5678 Flipper Keyboard
DELAY 1000
GUI r
DELAY 500
STRING powershell
CTRL-SHIFT ENTER
DELAY 1500
ALT y
DELAY 1000
STRING Write-Host "Hello from Flipper Zero!"
ENTER
Joel Serna / April Brother

Evil Crow Cable Wind

Wind Syntax

Evil Crow Cable Wind is a BadUSB device based on ESP32-S3 disguised as a USB cable. It can be controlled via a web panel over WiFi. Uses Wind Syntax with commands like Print, PrintLine, Press KEY_ENTER, Delay, GuiR, and more.

Key features

  • Looks like a normal USB cable
  • ESP32-S3 based with WiFi control
  • Web panel at http://cable-wind.local/
  • Multiple keyboard layout support (18 layouts)
  • Payload editor with syntax checker
  • OS detection capability
  • AutoExec planning
  • Remote shell (Linux/iOS/Windows/Android)
  • WinPrint/WinPrintLine for unknown layouts
  • Wind Syntax scripting language

example payload · Wind Syntax

REM Evil Crow Cable Wind Payload
REM Wind Syntax Commands:
REM - Print <text> - types text
REM - PrintLine <text> - types text + Enter
REM - Press KEY_ENTER - press Enter key
REM - Press KEY_TAB - press Tab key
REM - Delay <ms> - wait in milliseconds
REM - GuiR - Windows+R (Run dialog)
REM - Gui - Windows key
REM - CtrlAltT - Ctrl+Alt+T (Linux terminal)
REM - Press KEY_LEFT_CTRL - Ctrl key
REM - Press KEY_LEFT_ALT - Alt key
REM - WinPrint/WinPrintLine - for unknown layouts
REM
REM === Windows Example ===
Delay 2000
GuiR
Delay 500
PrintLine cmd
Delay 1000
PrintLine echo Evil Crow Cable Wind Active!
Press KEY_ENTER
REM
REM === Linux Example ===
REM Delay 2000
REM CtrlAltT
REM Delay 500
REM PrintLine echo Hello from Evil Crow!
REM Press KEY_ENTER
REM
REM === WinPrint for unknown layouts (Windows only) ===
REM WinPrintLine Hello World!@#/()-:,;0123456789

The Bash Bunny is a multi-function USB attack platform by Hak5. It's a quad-core Linux computer that can emulate trusted USB devices like keyboards, serial ports, storage, and Ethernet adapters to deliver advanced payloads.

Key features

  • Quad-core Linux computer
  • Multi-vector USB attacks
  • HID keyboard emulation
  • Ethernet adapter emulation (RNDIS/ECM)
  • Mass storage emulation
  • Serial console access
  • RGB LED status indicators
  • Physical switch for payload selection (3 positions)
  • Extensions system for enhanced payloads

example payload · Bunny Script (DuckyScript + Bash)

#!/bin/bash
# Bash Bunny Payload
LED SETUP
ATTACKMODE HID STORAGE
DUCKY_LANG us

LED ATTACK
QUACK GUI r
QUACK DELAY 500
QUACK STRING powershell
QUACK ENTER
QUACK DELAY 1000
QUACK STRING "Write-Host 'Bash Bunny Active'"
QUACK ENTER

LED FINISH

USB Nova is a BadUSB device by Spacehuhn. It's compatible with DuckyScript 1.0 with some functions added or expanded. Features include mouse support, multiple modes with LED colors, and firmware update capability.

Key features

  • DuckyScript 1.0 compatible
  • Additional functions and keys
  • Mouse support
  • Multiple modes with LED colors
  • Firmware update capability
  • DIY tutorial available
  • Compact form factor
  • Cross-platform support

example payload · DuckyScript 1.0 (with extensions)

REM USB Nova Hello World Script
REM Compatible with DuckyScript 1.0
DEFAULTDELAY 200
DELAY 1000
GUI r
STRING notepad
ENTER
DELAY 1000
STRING Hello from USB Nova!
REM USB Nova supports mouse commands:
REM MOUSE MOVE 100 50
REM MOUSE CLICK LEFT
Maltronics

Malduino

DuckyScript (Maltronics variant)

Malduino is a BadUSB device by Maltronics. Writing scripts is based on DuckyScript syntax and can be learned in minutes. Supports multiple keyboard locales and features like REPEAT command and configurable key press delays.

Key features

  • DuckyScript-based syntax
  • Multiple keyboard locale support (DE, GB, US, ES, FR, DK, RU)
  • LOCALE command for keyboard language
  • DEFAULTDELAY and KEYPRESS_DELAY commands
  • REPEAT command for repeating commands
  • MalDuino 3 (current), MalDuino W (WiFi)
  • Open-source firmware
  • Affordable entry point

example payload · DuckyScript (Maltronics variant)

REM Malduino Payload
LOCALE US
DELAY 1000
GUI r
STRING notepad
ENTER
DELAY 500
STRING It's super easy to script for MalDuino!
REM Repeat previous command 3 times:
REM REPEAT 3
REM Set default delay:
REM DEFAULTDELAY 100
REM Set key press duration:
REM KEYPRESS_DELAY 10
Hak5

Key Croc

DuckyScript 2.X (with Key Croc extensions)

Key Croc is a keylogger armed with pentest tools. It captures keystrokes and can inject payloads based on pattern matching. Native commands (MATCH, SAVEKEYS, LED) don't need Q prefix; DuckyScript commands (STRING, DELAY, GUI) need QUACK prefix.

Key features

  • Keylogger with cloud sync
  • Pattern matching with MATCH command
  • SAVEKEYS for capturing credentials
  • WiFi connectivity for remote access
  • Payload injection on trigger
  • USB passthrough mode
  • LED status indicators
  • MicroSD storage

example payload · DuckyScript 2.X (with Key Croc extensions)

# Key Croc Payload - Capture passwords after keyword
MATCH password
SAVEKEYS /root/loot/creds.txt NEXT 20
LED ATTACK
WAIT_FOR_LOOT /root/loot/creds.txt
LED FINISH

# Inject keystrokes on trigger
MATCH admin
QUACK GUI r
QUACK DELAY 500
QUACK STRING cmd
QUACK ENTER

O.MG Cable looks like a regular USB cable but contains a hidden implant for keystroke injection and WiFi-based remote access. Supports 191 keyboard layouts via DUCKY_LANG, mouse emulation, geofencing, and randomization commands. Connect to WiFi (SSID: O.MG, Pass: 12345678) and browse to 192.168.4.1.

Key features

  • Looks like genuine USB cable
  • WiFi-based remote control (192.168.4.1)
  • 191 keyboard layouts (DUCKY_LANG)
  • Mouse emulation (MOUSE MOVE/CLICK)
  • Randomization commands (RANDOM_CHAR, etc.)
  • Geofencing (IF_PRESENT, WAIT_FOR_PRESENT)
  • Self-destruct feature
  • Jiggler mode to prevent screen lock

example payload · DuckyScript (O.MG Extensions)

REM O.MG Cable Payload with Extensions
DUCKY_LANG US
DEFAULT_DELAY 100

REM Move mouse to corner and click
MOUSE MOVE -10000 -10000
MOUSE CLICK 1

DELAY 1000
GUI r
DELAY 500
STRING powershell -w hidden
ENTER
DELAY 1000

REM Generate random password
STRING $pass = "
REPEAT 16 RANDOM_CHAR
STRINGLN "

REM Jiggler to prevent screen lock
JIGGLER ON
Hak5

Packet Squirrel

DuckyScript (Packet Squirrel)

Packet Squirrel is a stealthy pocket-sized man-in-the-middle device. It can capture network traffic, perform DNS spoofing, and execute payloads. Uses DuckyScript with NETMODE, LED, and BUTTON commands.

Key features

  • Man-in-the-middle attacks
  • Packet capture to USB storage
  • DNS spoofing
  • VPN tunneling
  • Payload switching via button
  • LED status indicators
  • Ethernet passthrough
  • Remote access via reverse SSH

example payload · DuckyScript (Packet Squirrel)

#!/bin/bash
# Packet Squirrel Payload - Traffic Capture
LED SETUP
NETMODE TRANSPARENT

# Start packet capture
LED ATTACK
tcpdump -i br-lan -w /mnt/loot/capture.pcap &

# Wait for button press to stop
BUTTON
killall tcpdump
LED FINISH

LAN Turtle is a covert Systems Administration and Penetration Testing tool providing stealth remote access, network intelligence gathering, and man-in-the-middle monitoring capabilities. Uses a modular system with start/stop/configure functions.

Key features

  • Stealth USB Ethernet adapter
  • Remote access via autossh
  • Man-in-the-middle capabilities
  • Modular payload system
  • DNS spoofing
  • Responder integration
  • Meterpreter support
  • Cloud C2 compatible

example payload · Turtle Module (Bash)

#!/bin/bash /usr/lib/turtle/turtle_module
# LAN Turtle Module - Responder
VERSION="1.0"
DESCRIPTION="Capture NTLM hashes with Responder"
CONF=/tmp/responder.form

function start {
  responder -I eth0 -wrf &
  PID=$!
  echo $PID > /var/run/responder.pid
}

function stop {
  kill $(cat /var/run/responder.pid)
}

function status {
  if pgrep responder > /dev/null; then
    echo "1"
  else
    echo "0"
  fi
}

Shark Jack is a portable network attack tool by Hak5. It's designed for quick network reconnaissance and payload delivery. Uses NETMODE for network configuration and LED commands for status indication. Payloads are stored in /root/payload/ folder.

Key features

  • Portable network attack tool
  • Nmap scanning capabilities
  • Payload switching via modes
  • LED status indicators
  • Internal storage for loot
  • Battery powered
  • Quick network recon
  • Cloud C2 compatible

example payload · DuckyScript (Shark Jack)

#!/bin/bash
# Shark Jack Payload - Network Scan
# NETMODE: DHCP_CLIENT, DHCP_SERVER, or TRANSPARENT
NETMODE DHCP_CLIENT

LED SETUP
# Wait for network connection
while ! ip addr show eth0 | grep -q "inet "; do
  sleep 1
done

LED ATTACK
# Run nmap scan
nmap -sP 192.168.1.0/24 -oN /root/loot/scan.txt

LED CLEANUP
sync

LED FINISH

Digispark is a tiny, Arduino-compatible development board based on the ATtiny85 microcontroller. It can be programmed to act as a USB keyboard for keystroke injection attacks. Duckify by Spacehuhn provides a web converter to translate DuckyScript to Arduino code.

Key features

  • Ultra-compact size (smaller than a quarter)
  • ATtiny85 microcontroller
  • Low cost entry point
  • Arduino IDE compatible
  • 6 I/O pins
  • Built-in USB connector
  • No bootloader button needed
  • Duckify converter for DuckyScript

example payload · Arduino (DigiKeyboard library)

#include "DigiKeyboard.h"

void setup() {
  DigiKeyboard.sendKeyStroke(0);
  DigiKeyboard.delay(2000);
  
  // Open Run dialog (Windows)
  DigiKeyboard.sendKeyStroke(KEY_R, MOD_GUI_LEFT);
  DigiKeyboard.delay(500);
  
  DigiKeyboard.print("notepad");
  DigiKeyboard.sendKeyStroke(KEY_ENTER);
  DigiKeyboard.delay(1000);
  
  DigiKeyboard.print("Hello from Digispark!");
}

void loop() {
  // Stop execution
}

The WiFi Pineapple Pager is a portable WiFi pentesting tool celebrating 20 years of WiFi exploits. It features a retro pager form factor with a vibrant display, battery power, and tri-band wireless radios. The device runs payloads written in Bash and DuckyScript, perfect for hands-free, event-driven WiFi attacks.

Key features

  • Standalone portable pentest device
  • Tri-band WiFi radios
  • Real-time WiFi alerts with ringtones
  • Battery powered operation
  • Menu-driven interface
  • GPS support for wardriving
  • PineAP attack suite
  • Recon and handshake capture
  • SSID impersonation pool
  • Cloud C2 compatible

example payload · Bash Script + DuckyScript

#!/bin/bash
# WiFi Pineapple Pager User Payload
# Scan for nearby networks and display results

PROMPT "Starting WiFi Recon"
START_SPINNER "Scanning..."

# Start a new recon session
PINEAPPLE_RECON_NEW

# Wait for scan
sleep 10

STOP_SPINNER
LOG "Scan complete!"

# Prompt for target selection
TEXT_PICKER "Enter target SSID" TARGET_SSID

# Add to SSID pool for impersonation
PINEAPPLE_SSID_POOL_ADD "$TARGET_SSID"
PINEAPPLE_SSID_POOL_START

ALERT "Evil Twin Active" "Now impersonating: $TARGET_SSID"

DuckyScript versions.

DuckyScript officially licensed devices are backwards compatible with previous versions. Payloads written for v1.0 run on v3.0 devices without modification.

VersionDevicesWhat it adds
v1.0Original USB Rubber Ducky (USB-A Only), USB Nova, Flipper Zero (BadUSB), MalduinoBasic keystroke injection with simple commands. Flipper Zero uses v1.0 with custom extensions (ID, SYSRQ, ALT+Numpad).
REM · DELAY · STRING · ENTER · GUI · ALT · CTRL · SHIFT · REPEAT
vWindEvil Crow Cable WindEvil Crow Cable Wind uses Wind Syntax with commands like Print, PrintLine, Press KEY_ENTER, Delay, GuiR, CtrlAltT, and special WinPrint for unknown keyboard layouts.
REM · Delay · Print · PrintLine · Press KEY_* · GuiR · Gui · CtrlAltT · WinPrint · WinPrintLine
v2.XBash Bunny, Key Croc, O.MG DevicesExtended syntax with device-specific commands. Key Croc adds MATCH and SAVEKEYS for keylogging.
All v1.0 commands · ATTACKMODE · QUACK · LED · MATCH (Key Croc) · SAVEKEYS (Key Croc)
v3.0New USB Rubber Ducky (USB-A & USB-C)Full programming language with variables, conditions, loops, and functions. Backwards compatible with v1.0.
All v1.0 commands · VAR · IF/ELSE/END_IF · WHILE/END_WHILE · FUNCTION · RETURN · DEFINE

Note: some commands are device-specific. MATCH and SAVEKEYS are Key Croc only, ATTACKMODE is Bash Bunny, and Flipper Zero adds ID, SYSRQ and ALT+numpad input.

Quick reference.

DuckyScript is the scripting language used by the Rubber Ducky and many other HID devices. It is designed to be simple and human-readable.

Basic commands

CommandDescriptionExampleVersion
REMComment - ignored during executionREM This is a commentAll
DELAYPause execution for specified millisecondsDELAY 1000All
DEFAULTDELAYSet default delay between all commandsDEFAULTDELAY 100All
STRINGType the following textSTRING Hello WorldAll
STRINGLNType text and press EnterSTRINGLN echo hello2.X+
ENTERPress Enter keyENTERAll
GUI / WINDOWSPress Windows/Command keyGUI rAll
ALTPress Alt keyALT F4All
CTRL / CONTROLPress Control keyCTRL cAll
SHIFTPress Shift keySHIFT INSERTAll
TABPress Tab keyTABAll
ESCAPE / ESCPress Escape keyESCAll

Advanced commands

CommandDescriptionExampleVersion
REPEATRepeat previous command N timesREPEAT 5All
VARDefine a variableVAR $COUNT = 03.0
IF/ELSE/END_IFConditional executionIF ($X > 5)3.0
WHILE/END_WHILELoop while condition is trueWHILE ($COUNT < 10)3.0
FUNCTION/END_FUNCTIONDefine reusable functionFUNCTION myFunc()3.0
ATTACKMODESet USB device modeATTACKMODE HID STORAGEBash Bunny
QUACKInject keystrokes from BashQUACK STRING helloBash Bunny
MATCHTrigger on keylogger pattern matchMATCH passwordKey Croc
SAVEKEYSSave captured keystrokesSAVEKEYS ONKey Croc
LOCALESet keyboard layoutLOCALE USMalduino

Special keys

F1-F12UPDOWNLEFTRIGHTSPACEBACKSPACEDELETEHOMEENDINSERTPAGEUPPAGEDOWNCAPSLOCKNUMLOCKSCROLLLOCKPRINTSCREENPAUSEBREAKMENU

Responsible use.

Ethical guidelines

  • Authorisation: obtain written permission before testing any system.
  • Scope: stay within the agreed scope of the engagement.
  • Documentation: record all activities and findings.
  • Disclosure: report vulnerabilities responsibly to the system owner.
  • Education: use these tools to learn and to improve security posture.

Best practices

  • Test payloads in isolated environments before deployment.
  • Include cleanup routines in your payloads to remove traces.
  • Use delays that account for the target system's response times.
  • Consider keyboard layout differences across target systems.
  • Keep tools and firmware updated to the latest versions.