Duck Blind: Remote Host-Based Forensics of Universal Serial Bus Attack Platforms
Open Access DepositedSignificant attacks have been conducted against governments and the private sector from Insider Threats (InTs) using Universal Serial Bus (USB) devices, such as the STUXNET worm that attacked Iran’s Natanz nuclear enrichment lab. Due to their ubiquitousness and small size, these USB devices can be easily concealed, transported, and readily used within most network environments. To compound the matter, USB attack platforms, where the USB device appears to be a keyboard or other Human Interface Device (HID) to circumvent cybersecurity controls, are in use by cyber threat actors. These USB attack platforms are available commercially for under $100. This praxis provides a remote forensic technique, Duck Blind, that can identify the use of commercially available USB attack platforms in a forensically sound manner, enhancing incident response capabilities against InTs. The Duck Blind Forensic Technique (DBFT) is designed to be used in a Windows Enterprise, where a remote Velociraptor server can monitor for known Indicators of Compromise (IOCs) to identify when an InT uses a USB attack platform. This praxis uses a clean copy of Win11_22H2_English_x64v2 in a VMware Workstation Pro 17.0.2 environment as a victim machine to attack and gather IOCs from the Windows registry and volatile memory. It uses Hak5 Rubber Ducky 2.0 (2022) and Bash Bunny Mark 2 as examples of USB attack platforms to attack the Windows system. It then uses a Velociraptor version 0.7.0-2 sever running on Ubuntu for remote digital forensics and incident response to detect the discovered IOCs. The DBFT is 100% accurate in this testing environment, with no Type I or Type II errors.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.
| Thumbnail | Title | Date Uploaded | Visibility | Actions |
|---|---|---|---|---|
|
|
Alexander_gwu_0075A_16958.pdf | 2025-04-09 | Open Access |
|