Home/ blog/ silentstrike-building

Building SilentStrike: Digispark HID lab with detections attached

How the lab was put together — payload fixtures, Windows observables, and mitigations next to every demo.

Scope

A controlled Windows path: Digispark as HID → scripted actions → what shows up in logs → what you’d block or alert on.

Build choices

  • Digispark for the physical layer (cheap, common in labs)
  • PowerShell-oriented fixtures for repeatable runs
  • Detection notes as first-class docs, not an afterthought README paragraph

What “done” meant

Someone can run the lab, see the behavior, and leave with mitigations — USB policy, process-chain alerts, user education — not just a payload.

Repo

https://github.com/r1tv1kx/digispark-hid-attack-lab