It's Duck Season: Forensic Detection of BadUsb Attacks

Thu, 29 Jun 2023 @ 12:20:00

During this study we explore deep parts of Windows systems and tryo to “excavate” useful logs so that we can behaviorally detect rubber duckies post-mortem. This study focuses on upper filter drivers, ETW, detection engineering and forensic logic.