At first glance, the Shark Jack looks like a small, pocket-sized plastic dongle with an Ethernet plug on one end, or an ordinary network cable (in the Shark Jack Cable version). In reality, it is a tiny, battery-powered automated network auditing tool. While tools like the Bash Bunny plug into USB ports, the Shark Jack plugs directly into wired network jacks (RJ45 Ethernet ports) on walls, IP phones, printers, or desktop computers. The moment it connects to a live network, it automatically runs security scans and maps out connected devices without needing a computer attached to it.
Autonomous Network Reconnaissance:
Automatically starts scanning the local area network (LAN) as soon as it is plugged into an active Ethernet jack. It can identify connected devices, operating systems, and open network "doors" (ports).
Drop-and-Run Operation:
Equipped with an internal rechargeable battery (or continuous USB-C power on the cable version), allowing security auditors to plug it in, walk away, and return later to collect the gathered information.
Dual Form Factors:
Shark Jack (Pocket Tool): Battery-operated for quick 10–15 minute audit missions.
Shark Jack Cable: Looks like a standard network cable and receives continuous power via USB-C for extended testing.
Flip-of-a-Switch Modes:
Uses a simple 3-position physical switch to easily change between Arming Mode (for setup and viewing scan results) and Attack Mode (for running automated scans).
Cloud C2 Exfiltration:
If the local network has outbound internet access, the Shark Jack can silently upload its scan results directly to a remote security server (Hak5 Cloud C2) in real time.
Physical Port Security Audits:
Tests whether Ethernet ports in public areas—such as lobbies, conference rooms, hallway wall jacks, or behind unattended reception desks—are properly secured or exposed to unauthorized visitors.
Automated Network Mapping (Nmap Scans):
Quickly creates a digital map of all active servers, IP addresses, printers, and routers on an internal network segment without needing to unpack a laptop.
Rogue DHCP & Network Vulnerability Testing:
Evaluates whether an attacker plugging into a wall jack can receive an IP address, intercept unencrypted network traffic, or discover vulnerable network services.
Network Access Control (802.1X) Testing:
Validates whether corporate switches correctly block unrecognized physical devices from joining the internal corporate network.
Because the Shark Jack attacks networks from the physical wire level, traditional antivirus software on desktop PCs cannot block it. Defense requires strong physical and network infrastructure controls:
Network Access Control (802.1X Authentication):
Enforce 802.1X port authentication across all corporate Ethernet ports. Unrecognized physical devices (without valid digital certificates) will be blocked from accessing the network.
Disable Unused Physical Wall Jacks:
Deactivate unused network ports at the switch level in conference rooms, waiting areas, and hallways so an intruder cannot simply plug in and gain access.
VLAN Segmentation & Guest Isolation:
Place physical wall jacks in public areas onto an isolated "Guest" VLAN that cannot communicate with internal corporate servers, HR databases, or domain controllers.
MAC Address Filtering & Port Security:
Configure network switches to limit the number of MAC addresses allowed per port or lock ports strictly to approved corporate hardware IDs.
Network Intrusion Detection (IDS/NTA):
Monitor internal network traffic for rapid port-scanning activity (such as aggressive nmap sweeps) originating from newly connected network jacks.
Off Position: Device is powered off and charging internal battery.
Arming Mode (Safe Setup): Connects to your computer via Ethernet to let you edit settings, view scan logs, or update payloads via SSH/Serial.
Attack Mode: Runs configured payload scripts automatically as soon as Ethernet link is established.
Green (Blinking): Booting up
Blue (Blinking): Charging
Blue (Solid): Fully Charged
Yellow (Blinking): Arming mode
Red (Blinking): Error - no payload found