finds.dev← search

// the find

davidbombal/hak5

★ 523 · PowerShell · MIT · updated Aug 2022

hak5 YouTube videos

A flat folder of payload scripts for Hak5 USB Rubber Ducky and O.MG Cable devices, mostly PowerShell and plain text, that accompany David Bombal's YouTube videos. It is aimed at people following those videos or studying how keystroke-injection payloads are written.

- The O.MG scripts are short enough to read in one sitting. The notepad, open-browser and copy-Wi-Fi-details examples show the basic shape of a keystroke-injection payload without extra machinery.

- Each file is a single self-contained payload named after what it does, so you can match a video to its script without digging.

- It covers Windows, macOS, Linux, iOS and Android in separate files, which makes it a usable side-by-side reference for how the same idea gets adapted per OS.

- The last push was August 2022. Some names point to old hardware (an Android 9 Galaxy S8 payload, a separate S22 Ultra file), so expect parts to fall out of step with current OS builds.

- The visible listing has no README or setup notes. Nothing says which device each payload targets, what prerequisites it needs, or how to run it.

- Several payloads (disabling Defender, the backdoor, the Meterpreter payload) only do anything useful against machines the operator does not own. As a pick this is a teaching reference, not a tool to adopt.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →