// the find
davidbombal/hak5
hak5 YouTube videos
A flat folder of payload scripts for Hak5 USB Rubber Ducky and O.MG Cable devices, mostly PowerShell and plain text, that accompany David Bombal's YouTube videos. It is aimed at people following those videos or studying how keystroke-injection payloads are written.
- The O.MG scripts are short enough to read in one sitting. The notepad, open-browser and copy-Wi-Fi-details examples show the basic shape of a keystroke-injection payload without extra machinery.
- Each file is a single self-contained payload named after what it does, so you can match a video to its script without digging.
- It covers Windows, macOS, Linux, iOS and Android in separate files, which makes it a usable side-by-side reference for how the same idea gets adapted per OS.
- The last push was August 2022. Some names point to old hardware (an Android 9 Galaxy S8 payload, a separate S22 Ultra file), so expect parts to fall out of step with current OS builds.
- The visible listing has no README or setup notes. Nothing says which device each payload targets, what prerequisites it needs, or how to run it.
- Several payloads (disabling Defender, the backdoor, the Meterpreter payload) only do anything useful against machines the operator does not own. As a pick this is a teaching reference, not a tool to adopt.