Welcome to the Georgia Public Library Service (GPLS) PenTest Kit page! This kit is designed for analyzing physical workstation vulnerabilities and evaluating endpoint security controls using specialized hardware attack platforms. This kit contains five specialized Hak5 hardware tools designed for controlled red-team assessments, security audits, defensive control validation, IT security training and hands-on exercises, endpoint defense, and policy hardening.
Penetration testing (or "pentesting") is an authorized, simulated cyberattack against an organization's systems, networks, and physical infrastructure. Its goal is to identify exploitable security vulnerabilities before malicious threat actors can find and leverage them.
Validating Defensive Controls: Verifies the real-world performance of Endpoint Detection and Response (EDR/XDR), Data Loss Prevention (DLP), network firewalls, Network Access Control (802.1X), and Intrusion Detection/Prevention Systems (IDS/IPS).
Simulating Adversary Behaviors: Recreates realistic physical-access scenarios, insider threats, and supply-chain or hardware implant vectors aligned with frameworks like MITRE ATT&CK.
Testing Physical and Social Boundaries: Evaluates physical workstation security, clean-desk policy enforcement, cable management, and user awareness regarding unattended devices.
Remediation & Hardening: Delivers actionable telemetry and gap analyses to help systems engineers remediate misconfigurations, enforce least privilege, and strengthen logging pipelines.
USB & Endpoint Attack Tools: These tools exploit the inherent trust operating systems grant to USB devices, specifically Human Interface Devices (keyboards) and virtual network adapters.
Bash Bunny: A multi-function USB attack platform equipped with a full Linux runtime environment and switch-selectable payloads.
Key Croc: A stealthy, inline USB keylogger and automated pentesting implant designed to sit between a target workstation and a wired USB keyboard.
Inline & Direct Ethernet Network Tools: These devices connect directly to wired local area networks (LANs) to inspect traffic, stage man-in-the-middle (MitM) attacks, and automate auditing tasks.
Packet Squirrel: A compact, pocket-sized inline Ethernet device-in-the-middle multi-tool designed for covert network monitoring and active manipulation.
Shark Jack: A portable, dedicated RJ45 network attack tool built for fast, opportunistic wired network assessments and automation.
Physical Video Capture Implants: Hardware devices engineered to intercept and exfiltrate visual information directly from display interfaces.
Screen Crab: An inline HDMI video man-in-the-middle capture implant placed between a display source (workstation, server, terminal) and an external monitor or television.
Explicit Authorization: Never deploy these devices without explicit, written authorization and a signed Rules of Engagement (RoE) agreement.
Scope Boundaries: Restrict testing strictly to designated target subnets, physical workstations, and agreed testing windows.
Emergency Disconnect: If any device causes unexpected system behavior or disruption to production services, immediately disconnect the tool and inform the engagement lead.
Data Protection: Encrypt or securely sanitize all captured loot (keystroke logs, PCAP captures, harvested hashes, and screenshots) following assessment completion.
Ensure all components (device, cables, memory cards, etc.) are included.
Pack items securely in the provided case.
Complete the post-use survey provided in the kit.