WS8 - Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices
Description
Instructed by: “wasabi”
Level of Difficulty: Beginner, Intermediate
Abstract:
"Don't plug in devices you don't trust." It's one of the most repeated pieces of security advice in the industry. What actually happens when a malicious USB device is plugged in? How does it work? This hands-on, four-hour workshop answers those questions by putting the tools directly in attendees' hands. Using O.MG Devices and the DuckyScript v3 scripting language, participants will learn the fundamentals of Human Interface Device (HID) attacks from the ground up. Starting from USB protocol basics all the way through real payload design, delivery strategy, and advanced techniques including wireless triggering, C2 integration, and air-gapped exfiltration (using HIDX StealthLink).
The class is beginner-friendly and builds progressively: no prior red teaming experience is required. Only a DuckyScript v3 device is required. Attendees will leave with working scripts, a framework for payload design, and an understanding of what attackers and defenders need to look for. We will cover OpSec, detection (and evasion), and how accessibility-first design thinking can make both attackers and defenders more effective.
Pre-Requisites:
· Basic familiarity with an operating system (Windows or Linux).
· Basic networking concepts (IP address, WiFi).
· No scripting or red team experience required.
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


