The spark
USB devices that pretend to be keyboards still work. Most training stops at “don’t plug unknown USBs in.” That advice is true — and incomplete.
What I wanted to understand
Not how to weaponize a Digispark in the wild. How the path looks from insert → HID → process → logs, so detections and mitigations have somewhere to land.
Constraints I set early
- Owned lab hardware only
- Every demo paired with a defensive note
- No “cool exploit” framing without the close-out
The question that shaped the project
If an analyst only sees a keyboard, what should the endpoint story look like anyway?