Rubber Ducky Crash Course

  • Course Duration6 HRS
  • Course LanguageEnglish

What you'll learn

  • Understand how USB, HID, and keystroke-injection attacks work
  • Explain why computers trust USB keyboards by default
  • Set up and flash a USB Rubber Ducky (or compatible BadUSB device)
  • Master the DuckyScript language and its command set
  • Write payloads for Windows, macOS, and Linux targets
  • Build reconnaissance, credential-capture, and reverse-shell payloads
  • Use encoders, timing, and obfuscation for reliable execution
  • Exfiltrate data and stage payloads from external sources
  • Understand physical access in red team engagements
  • Defend against BadUSB and USB-based threats

The USB Rubber Ducky looks like an ordinary flash drive, but to a computer it is a trusted keyboard — and that trust is exactly what makes keystroke-injection attacks so powerful. This fast-paced crash course takes you from zero to writing and deploying your own BadUSB payloads, teaching you how a few seconds of physical access can be turned into a full compromise, and how defenders can stop it.

Across focused, hands-on modules you will learn how Human Interface Device (HID) attacks work, master the DuckyScript language, and build payloads for Windows, macOS, and Linux. You will explore reconnaissance, credential capture, reverse shells, and exfiltration payloads, learn evasion and timing techniques, and see how the same ideas apply to other BadUSB devices. Every attack is paired with the defensive controls that mitigate it.

By the end of this crash course, you will be able to write reliable DuckyScript payloads from scratch, adapt them to real target environments, understand the role of physical access in red team engagements, and advise organisations on how to defend against USB-based threats.

Disclaimer: This course is intended strictly for educational and authorised security testing purposes. All payloads are deployed only on devices you own or are explicitly authorised to test, within isolated lab environments. Unauthorised use of any technique taught in this course is illegal and strictly prohibited.

Course content

01Welcome to the Course2 lectures
  • Important Before You Start
  • Course Roadmap & Objectives
02Understanding Keystroke Injection5 lectures
  • What Is the USB Rubber Ducky?
  • How USB & HID Devices Work
  • Why Computers Trust Keyboards
  • The BadUSB Threat Landscape
  • Rubber Ducky vs Other BadUSB Devices
03Hardware & Setup5 lectures
  • Anatomy of the Rubber Ducky
  • Setting Up Your Lab Safely
  • Installing the Toolkit
  • Flashing Firmware & the microSD Card
  • Your First Payload: Hello World
04DuckyScript Fundamentals6 lectures
  • Introduction to DuckyScript
  • Core Commands (STRING, DELAY, ENTER)
  • Modifier & Special Keys
  • Comments & Payload Structure
  • Timing & Reliable Execution
  • Encoding & Deploying a Payload
05DuckyScript 3.0 Advanced Features5 lectures
  • Variables & Arithmetic
  • Conditionals & Loops
  • Functions & Reusable Code
  • Using Keyboard LEDs & Feedback
  • OS Detection & Adaptive Payloads
06Building Attack Payloads6 lectures
  • Reconnaissance & Info-Gathering Payloads
  • Windows Attack Payloads
  • macOS & Linux Payloads
  • Credential Capture Techniques
  • Reverse Shell Payloads
  • Data Exfiltration & Payload Staging
07Evasion & Real-World Deployment4 lectures
  • Avoiding On-Screen Detection
  • Obfuscation & Anti-Detection Tricks
  • Physical Access & Social Engineering
  • Payloads in Red Team Engagements
08Defense & Countermeasures4 lectures
  • Detecting Malicious USB Devices
  • USB Port & Device Control
  • Endpoint & Group Policy Defenses
  • Physical Security Best Practices
09Wrap-Up & Next Steps3 lectures
  • Capstone: Build Your Own Payload
  • Ethics, Legality & Responsible Use
  • Continuing Your Learning Journey

Requirements

  • A USB Rubber Ducky or a compatible BadUSB device (e.g. a Digispark/ATtiny board)
  • A computer running Windows, macOS, or Linux for testing in a lab
  • Basic familiarity with using a computer (no programming experience required)
  • A stable internet connection to download the toolkit and payloads

Who this course is for

  • Beginners curious about physical security and hardware hacking
  • Penetration testers and red teamers adding BadUSB to their toolkit
  • IT and security staff who want to understand and defend against USB attacks
  • Students and enthusiasts who learn best through hands-on projects
$120ENROLL NOW