Scope
A controlled Windows path: Digispark as HID → scripted actions → what shows up in logs → what you’d block or alert on.
Build choices
- Digispark for the physical layer (cheap, common in labs)
- PowerShell-oriented fixtures for repeatable runs
- Detection notes as first-class docs, not an afterthought README paragraph
What “done” meant
Someone can run the lab, see the behavior, and leave with mitigations — USB policy, process-chain alerts, user education — not just a payload.