Bash Bunny Mark II
The multi-vector USB attack platform — emulate keyboard, Ethernet, serial and storage at once; switch between payloads, exfiltrate data.
The multi-vector USB attack platform — emulate keyboard, Ethernet, serial and storage at once; switch between payloads, exfiltrate data.
Frequently asked questions about Hak5 devices — which tool to buy, DuckyScript versions, legality, WiFi Pineapple vs Pager, O.MG differences and more.
Official Hak5 firmware, PayloadStudio, and payload repositories — one table to find everything, plus how to update firmware from SSH or the web UI.
Hak5 pentesting tools — WiFi Pineapple, USB Rubber Ducky, Bash Bunny, Shark Jack, Key Croc, O.MG and more. Specs, quickstarts, DuckyScript payloads and troubleshooting.
Hardware keylogger disguised as a keyboard adapter that attacks when you type keywords — DuckyScript 2.0, remote access, Cloud C².
The defensive tool that detects all known malicious USB cables — including O.MG's own — via side-channel power analysis. Also a safe-charging data blocker.
The O.MG wireless implant inside a USB-A-to-C adapter — covert keystroke injection on computers, phones and tablets.
A malicious USB cable with a hidden WiFi implant — covert keystroke injection, DuckyScript over WiFi, self-destruct and geofencing.
The O.MG wireless implant inside a keychain USB plug — covert keystroke injection and DuckyScript payloads you carry on your keys.
The universal programmer for all O.MG devices — activate, upgrade firmware, recover from self-destruct, and make forensic backups.
An O.MG wireless implant hidden inside a USB data blocker — the defender's tool, weaponised. Covert keystroke injection while passing power.
Inline Ethernet man-in-the-middle — sniff, proxy, redirect DNS, jail devices, or bridge transparently, all at the flip of a switch.
A pocket-sized USB-C Ethernet tap for passive or active capture — sniff traffic into Wireshark on Windows, Mac, Linux or Android.
First 15 minutes with any Hak5 device — arming mode, your first payload, your first scan. Step-by-step with commands and expected output.
A covert HDMI man-in-the-middle implant that silently captures screenshots or video — lag-free, MicroSD storage, WiFi + Cloud C² streaming.
Pocket-sized network recon box — plug into any Ethernet jack, run nmap scans in seconds, exfiltrate loot over SSH.
The Shark Jack powered by USB-C with a dedicated serial console — network recon that runs as long as power flows, with a live shell.
Hak5 troubleshooting hub — diagnostic decision tree, LED colour meanings per device, SSH/arming-mode fixes, payload execution problems, and what to report when you contact support.
The king of keystroke injection — DuckyScript payloads, arming mode, Hello World, keyboard layouts and advanced HID attacks.
The rack-mount WiFi Pineapple with five dual-band radios for serious airspace audits — specs, WPA2-Enterprise rogue AP, deployment and lab use.
The classic dual-band rogue access point — PineAP suite, evil twin attacks, modules, 5 GHz upgrade path and step-by-step first setup.
The tri-band, DuckyScript-powered WiFi Pineapple in a pocket-sized handheld with a 2.4-inch screen — fully standalone pentesting.