Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
USBArmyKnife — USB Army Knife – the ultimate close access tool for penetration testers and red teamers. | Kitploit
Tools/GitHubGitHub/i-am-shodan/usbarmyknife
Packet Sniffing & AnalysisWi-Fi AuditingBluetooth SecurityImpersonation ToolsData ExfiltrationPost-ExploitationHardware HackingPenetration TestingRed TeamingRemote Access ToolPayload Development
2.8k2743724 days agoReviewed by Kitploit
GitHub
i-am-shodan/usbarmyknife

USBArmyKnife

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

License PlatformIO CI .NET Twitter ko-fi Buy Me A Coffee

🚀 USB Army Knife v2 is steeping — and its going to be a beast

After two years of active development on v1, v2 is planned to turn the USB Army Knife into a full red-team platform in your pocket. A big announcement is coming this autumn but I still wanted to tease:

  • Brand-new web UI — smaller, faster, sleeker & multilingual, with a built-in VNC viewer to watch and drive the target straight from your browser. This won't be tied to any web tools like today so anyone can change it.
  • New UAK Scripting engine — DuckyScript v3-compatible, but goes way beyond what DuckyScript 3 can do with full string and return code support. This makes writing neater and more robust payloads much easier.
  • New cross-platform Agent for Windows, Linux and macOS — live VNC, microphone capture and maybe even network access over the USB serial link.
  • Many new capabilities — Brand new functionality across networking, files, captive portal, bluetooth and many more! USB 2.0 for faster throughput with read-only and read-write containers!
  • AI-ready — an MCP server with a real UAK script validator so your AIs can write and check payloads before they hit the device.

A ton of this work has now been completed and I've been busy working with hardware that will be powerful enough to run this new platform. What's clear is that the dongle that started this project won't be able to handle the newer V2 features. But I for one love its form factor. What I'm sure of is that v2 will take UAK make one tiny stick that scripts itself, picks its target, controls the device, hears the room, and maybe can even talk to its siblings...

USB Army Knife

Introducing the USB Army Knife – the ultimate tool for penetration testers and red teamers.

Compact and versatile, this device packs a punch with its extensive capabilities, including USB HID attacks, mass storage emulation, network device impersonation and WiFi/Bluetooth exploits (thanks to our forked version of ESP32 Marauder).

Complete control over how and when your payloads are run. Plug in and execute, leave behind and trigger over WiFi, run on a timer or build a Hollywood-esq UI. Manage and deploy your attacks effortlessly using just a phone using a user-friendly Bootstrap web interface.

Want more? Deploy the agent and execute commands even when the machine is locked. Working over the serial interface egress is incredibly hard to detect. You can even view the victims screen over the devices' dedicated WiFi connection.

Equip yourself with the USB Army Knife and elevate your local access toolkit to the next level.

Testimonials

"Your device is evil. You are doing evil." - Mr. Peoples via X

Intro

There is a problem with physical access/USB attacks today. On their own, each attack doesn't provide enough of a solution to meet most objectives.

  • USB keyboard attacks (Ducky, HID&Run) require a logged on machine and even the best tools don’t provide a solution to this.
  • Networking attacks (poison tap and alike) might get you a password hash but often require something complex hanging out of an Ethernet port to get this back for offline cracking.
  • When you get on a box, what options do you still have for exfiltrating data when anything that opens a socket is getting sent to VT.

What was needed is a physical access platform that enables a suitable rogue to take the best bits of each attack and workaround their respective problems with another attack. Ideally this platform would be so cheap and covert that losing one wouldn't be an issue.

This is why I decided to create the USB Army Knife.

  • Want to become a USB Ethernet adapter PCAP the interface and egress it over WiFI? USB Army Knife.
  • Want to wrap your attacks in custom UI or just show a Hollywood interface when your attack has worked? USB Army Knife
  • Want a covert storage device? USB Army Knife
  • Want to deauth everyone on the WiFi, PCAP the renegotiation and email this to yourself when the machine has been left unlocked for offline cracking? USB Army Knife
  • Want your attack to destroy itself when it’s been found? USB Army Knife
  • What to connect to other bits of hardware, motion sensors and alike? USB Army Knife.
  • Want to view what’s on the victim's screen over WiFi? USB Army Knife.
  • Want to record what your victim is saying? USB Army Knife.

Video

This video shows how the ultimate rick roll works

https://github.com/user-attachments/assets/f373e18e-5cad-4871-9f2a-17523fa33398

This video shows how the USB PCAP functionality and has a brief peak at the web interface

https://github.com/user-attachments/assets/0d5b1485-b808-46c6-aaf7-7cf016088b8f

This video shows how to pull the victims machine once the agent has been installed

https://github.com/user-attachments/assets/3c866d29-ef26-4eaf-943b-1206b8c40101

Features

This project implements a variety of attacks based around an easily concealable USB/WiFi/BT dongle. The attacks include sending BadUSB (USB HID commands using DuckyScript), appearing as mass storage devices, appearing as USB network devices, and performing WiFi and Bluetooth attacks with ESP32 Marauder. Attacks are deployed using a Ducky-like language you probably already know and love. This language has been agumented with a raft of custom commands and even the entire ESP32 Marauder capability (improved). Attacks include:

  • USB HID Attacks: Send custom HID commands using DuckyScript, supports BadUSB & USB HID and run style attacks. Supports multiple keyboard layouts/languages.
  • Mass Storage Device: Emulate a USB mass storage device (USB drive and CDROM).
  • USB Network Device: Appear as a USB network device.
  • WiFi and Bluetooth Attacks: Utilize ESP32 Marauder for WiFi and Bluetooth attacks. Include EvilAP, Deauth and pcap.
  • Hot Mic: Plug in a USB device and stream audio over WiFi

Examples

NameDescription
Covert StorageExample showing how to masquerade as two different USB mass storage devices. The first time the device is plugged in the devices appears with the full contents of the micro SD card. In all subsequence attempts a different 'benign' drive appears.
Download Tool