Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Honeypots
  3. Ghost-usb

Ghost-usb

GPL-3.0C

A honeypot that emulates USB storage devices to detect and capture malware that spreads via USB propagation.

GitHubGitHub
104 stars25 forks0 contributors

What is Ghost-usb?

Ghost USB honeypot is a security tool that emulates USB storage devices to detect malware that spreads via USB propagation. It tricks infected machines into attempting to infect the emulated device, revealing the presence of such malware without needing prior threat intelligence. Originally developed for a bachelor thesis, it is now maintained within the Honeynet Project.

Target Audience

Security researchers, IT administrators, and organizations monitoring for USB-based malware threats in Windows environments, particularly those concerned with physical device attack vectors.

Value Proposition

It provides a specialized, low-overhead method for detecting USB-propagating malware without relying on signatures, offering unique visibility into threats that exploit physical media in Windows systems.

Overview

A honeypot for malware that propagates via USB storage devices

Use Cases

Best For

  • Detecting malware that spreads via USB storage devices in Windows environments
  • Security research on USB-based attack vectors and propagation methods
  • Monitoring for physical device-based threats in controlled networks
  • Educational purposes in cybersecurity and honeypot deployment
  • Incident response investigations involving USB malware infections
  • Complementing traditional antivirus with behavioral detection techniques

Not Ideal For

  • Environments running modern Windows versions (e.g., Windows 10, 11) or 64-bit systems
  • Organizations requiring real-time malware prevention rather than just detection
  • Teams without experience in Windows driver development or kernel-mode programming
  • Projects needing broad-spectrum malware detection beyond USB-based threats

Pros & Cons

Pros

Specialized USB Threat Detection

Emulates USB storage devices to lure and detect malware that spreads via USB, providing unique insights without signature dependencies, as described in its behavioral approach.

No Prior Intelligence Needed

Detects unknown threats by tricking infected machines into attacking the emulated device, offering early warning without reliance on known malware samples, aligning with its no-signature philosophy.

Academic and Community Backing

Originally developed for a bachelor thesis and now maintained by the Honeynet Project, ensuring credibility and ongoing development within the security community.

Low-Resource Operation

Designed for practical, low-overhead detection, making it suitable for monitoring in resource-constrained environments vulnerable to physical device attacks.

Cons

Outdated Platform Support

Only supports Windows XP 32-bit and Windows 7 32-bit, making it obsolete for current operating systems and severely limiting its practical use in modern environments.

Complex Setup Requirements

Building from source requires the Windows Driver Kit, involving a steep learning curve and technical hurdles, as noted in the build and install guides.

Limited Maintenance and Documentation

Binaries are hosted on an old Google Code site, and the wiki may not be updated, posing challenges for installation, troubleshooting, and long-term support.

Narrow Detection Scope

Focuses solely on USB-based malware propagation, missing other attack vectors like network or email, thus not suitable for comprehensive security monitoring.

Frequently Asked Questions

Quick Stats

Stars104
Forks25
Contributors0
Open Issues3
Last commit11 years ago
CreatedSince 2015

Tags

#honeypot#windows-security#malware-detection#emulation#security-tool#forensics#incident-response#threat-detection

Built With

W
Windows Driver Kit

Included in

Honeypots10.2k
Auto-fetched 20 hours ago

Related Projects

T-PotT-Pot

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Stars9,360
Forks1,379
Last commit1 month ago
EndlesshEndlessh

SSH tarpit that slowly sends an endless banner

Stars8,496
Forks300
Last commit2 years ago
CowrieCowrie

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Stars6,480
Forks1,041
Last commit1 day ago
AndroguardAndroguard

Reverse engineering and pentesting for Android applications

Stars6,161
Forks1,139
Last commit1 month ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub