hacktricks/forensics/basic-forensic-methodology/pcap-inspection/usb-keyboard-pcap-analysis.md
carlospolop f0e09e3f54 social
2023-03-06 00:16:20 +01:00

3.7 KiB

HackTricks in 🐦 Twitter 🐦 - 🎙️ Twitch Wed - 18.30(UTC) 🎙️ - 🎥 Youtube 🎥

If you have a pcap of a USB connection with a lot of Interruptions probably it is a USB Keyboard connection.

A wireshark filter like this could be useful: usb.transfer_type == 0x01 and frame.len == 35 and !(usb.capdata == 00:00:00:00:00:00:00:00)

It could be important to know that the data that starts with "02" is pressed using shift.

You can read more information and find some scripts about how to analyse this in:

HackTricks in 🐦 Twitter 🐦 - 🎙️ Twitch Wed - 18.30(UTC) 🎙️ - 🎥 Youtube 🎥