Utility Commands
Timing, flow control, variables, LED, storage, and system commands for ZeroTrace payloads
Utility commands cover everything that isn't keystrokes or pointer input — pauses, flow control, variables, the on‑board LED, mass storage, and device/system actions.
Timing
Pauses execution for ms milliseconds. Negative values are treated as 0; a single delay is capped at 1 hour (3,600,000 ms).
delay 1000Pauses for a random duration between minMs and maxMs, to make timing look less mechanical. Same 1‑hour cap as delay.
randomDelay 200 800Flow control
Ends the running script immediately. exit is an alias. Typically paired with an IF branch to bail out early.
_$VAR os = "_@detectedOS"
IF "${os}$" is not "windows"
stop
IF_ENDBlocks until the host toggles a lock‑key LED, polling every 20 ms. Because the host controls these LEDs, this is the primitive for host→device synchronization (e.g. a host script toggles Caps Lock to signal "ready"). The optional timeout (ms) unblocks anyway; 0 (or omitted) waits indefinitely.
Events: caps_on, caps_off, caps_change, num_on, num_off, num_change, scroll_on, scroll_off, scroll_change.
waitFor caps_change 10000Blocks until the selected lock key changes state. waitFor is the richer primitive (specific on/off target plus a timeout); stateChange is the simple "wait until this lock key toggles" form.
stateChange 'capslock'Keys: capslock, numlock, scrolllock.
Halts until the device's on‑board button is pressed. Optional timeout (ms) continues anyway if it isn't pressed in time. Only available on hardware with a button pin; a no‑op elsewhere.
waitForButton
waitForButton 15000Variables and math
Assigns a value to a variable. Reference it later as ${name}$.
set counter 0
set target 'Windows'Integer arithmetic (base‑10) on a variable, in place. add and sub adjust it, mul multiplies, mod takes the remainder. A mod by 0 leaves the variable unchanged.
add counter 1
sub counter 2
mul counter 4
mod counter 10LED
The device drives a single addressable pixel. Colors are 0–255 per channel.
Sets the LED to a solid RGB color.
ledColor 255 0 0
ledColor 0 255 100Blinks the LED in the given color count times, delayMs per phase. delayMs is clamped to 0–5000 and count to 0–100.
ledBlink 255 0 0 500 3Sets LED brightness, 0–255 (default 50). A value outside that range is a no‑op.
ledBrightness 128Turns the LED off.
ledOffStorage
Mounts the device to the host as a USB mass‑storage volume. Bringing the volume up self‑sequences a detach → configure → reattach and blocks about 650 ms — account for that pause in scripts.
storageMode "MYDISK" "1234" "5678"Arguments: <volumeName> <productId> <vendorId>.
Unmounts the emulated volume and returns storage access to the device (BLE file manager and scripts). The host's "Safely Remove" action triggers the same teardown.
ejectStorageFormats (erases) the device's filesystem.
formatStorageDevice and system
Restarts the device.
rebootBrings up USB HID at runtime. Only has an effect when HID start‑up was disabled at boot (disable_hid_startup=true); otherwise HID is already up.
enableHIDConnects or disconnects the USB device to the host. false detaches; true reattaches.
attackMode falseEnables or disables recon mode. See Recon Mode.
reconMode trueTriggers the host OS‑detection routine as a background task. Re‑entry is guarded, so a second call while one is running does nothing. See OS Detection.
osDetectionErases the entire flash chip, wiping firmware and stored data. See Self‑Destruct.
selfDestruct