ControlPuc v0: A HID Injection Framework with RP2350

Authors

  • Anindya Das Department of Computer Science and Engineering, JIS College of Engineering, Kalyani, India
  • Uttalak Mitra Department of Computer Science and Engineering, JIS College of Engineering, Kalyani, India

DOI:

https://doi.org/10.65138/ijresm.v9i7.3481

Abstract

Modern endpoint security systems can easily detect and block non-standard USB Human Interface Devices (HIDs), limiting the effectiveness of hardware-based penetration testing tools. This paper presents ControlPuc v0, a stealth-oriented hardware-software framework designed to evaluate endpoint resilience against advanced HID emulation attacks. Built on the RP2350 microcontroller with a custom micro-runtime [7], the system uses a physical pin-voltage interlock to switch between maintenance and stealth modes. To evade forensic detection, low-level firmware modifications disable Mass Storage Class descriptors, preventing automatic drive enumeration by Data Loss Prevention (DLP) systems. An anthropomorphic input engine introduces deterministic 5 ms delays between USB transactions to mimic human interaction and evade behavioral analysis. Additionally, an asynchronous outbound HTTP pull-based communication model enables reliable remote orchestration while bypassing stateful network restrictions. The framework highlights critical weaknesses in current heuristic endpoint defense mechanisms.

138 81

Downloads

Download data is not yet available.

Downloads

Published

15-07-2026

Issue

Section

Articles

How to Cite

[1]
A. Das and U. Mitra, “ControlPuc v0: A HID Injection Framework with RP2350”, IJRESM, vol. 9, no. 7, pp. 31–34, Jul. 2026, doi: 10.65138/ijresm.v9i7.3481.