logo

How to Get USB_Exfiltration Payload Using the Bash Bunny

ID: 92406a32-4ea8-5fcf-b3fc-c4a162e654f0

STIX ID: report--92406a32-4ea8-5fcf-b3fc-c4a162e654f0

Feed Name: Black Hills Infosec Blog

Date Published: 2017-03-16

Date Updated: 2026-04-27

Author: BHIS

...
...

A brief write-up demonstrating the Bash Bunny USB_Exfiltrator payload: tested as reliable on Windows (XP-SP3+ with PowerShell), modified to pull subdirectories from the user Documents folder, with a warning about the device's roughly 2GB storage limit and the requirement that the target system be unlocked.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.