Skip to content

ZeroTrace HID & Dongle

Safety & Legal

Authorized-use posture for ZeroTrace HID keystroke-automation devices.

A ZeroTrace HID device does on a host exactly what a person at the keyboard could do, at machine speed and with no confirmation prompts. That power is the point of the product, and it is also why it must be used carefully.

Use only on systems you own or are authorized to test

Plugging a HID device into a computer and running a payload is an active action on that computer. Do it only on machines you own, or where you have explicit written authorization to test. Running payloads against systems you do not control can be unlawful.

Understand a payload before running it

There is no sandbox. A payload can type commands, open a terminal, drive the mouse and, if you allow the destructive effect, wipe the device's own stored payloads. Read and understand any payload, including ones you import, before you run it.

Irreversible actions are opt-in

Commands that erase data (formatStorage, selfDestruct) and commands that change the USB presentation (attackMode, enableHID, storageMode) require you to explicitly opt in to their effect before the payload will build. This is a deliberate guardrail, see Gated effects. Treat the destructive ones with particular care: they cannot be undone.

Keystroke flooding and credential guessing

jamKeys (keystroke flooding) and bruteForce (credential guessing) are stress and testing tools that require the unbounded opt-in. They are for authorized testing of systems you control, not for use against third parties.

Built for authorized labs

ZeroTrace HID devices are sold for security labs, IT training and demonstrations. Used within these limits, they are a controlled instrument for authorized work.

Command Palette

Search for a command to run...