Would disabling HID keyboard driver installation on windows prevent Rubber Ducky/O.MG cable payloads?

What I know about these device is that they act as HID that can then do a bunch of stuff through acting as a keyboard, i.e. using powershell to get and execute a payload. Through windows’ group policy editor you can disable the installation of a class of devices, for example “HID keyboard” ClassGuid = {4d36e96b-e325-11ce-bfc1-08002be10318}. Would this effectively make them useless?

I’m unsure if other HID classes other than keyboard could also be used by them to execute a payload, if so you would need to also blacklist these as well.

Practically to use your keyboard you would add it using a whitelist, or if you do have to blacklist every HID class (assuming they can all be used maliciously) you would have to whitelist every HID you have.

submitted by /u/DiamondxCrafting
[link] [comments]

May 9, 2023
Read More >>