# PoisonTap PoisonTap is Samy Kamkar's Raspberry Pi Zero USB-network research project; it matters here as proof that USB can present a network identity rather than only storage. ## Historical and Technical Context The page compares legitimate multiboot/storage devices with offensive USB research. IODD devices emulate optical disks or virtual drives from stored ISO/VHD images, allowing one physical unit to present many bootable environments across legacy BIOS and UEFI systems. RMPrepUSB is a boot-media preparation and testing utility. Hak5’s Rubber Ducky class uses USB HID behavior to inject keystrokes; PoisonTap used a Raspberry Pi Zero configured as a USB Ethernet gadget to manipulate a locked computer’s network behavior and siphon web credentials/cookies. [S14] The page’s conceptual insight is that **USB is not merely storage**: the same connector can impersonate disks, keyboards, serial devices, or network adapters. ## Role in Scanned_20260730-1802 The primary identifying evidence appears on PDF page 28. A landscape-oriented page with a rectangular copper/orange tape patch at upper right. The writing is divided into a boot-media block and a security-research block. Arrows and slashes connect ISO/VHD, legacy/UEFI, and named USB attack projects. Within that page, PoisonTap helps the notebook move from a visible name or artifact toward the underlying identity, protocol, ownership, or control structure. ## Notebook Evidence - `Scanned_20260730-1802.pdf`, PDF page 28: "PoisonTap (Attack)" **Evidentiary status:** Visible evidence: explicit “Attack” labels and boot-mode comparison. Verified fact: PoisonTap used Raspberry Pi Zero USB networking; IODD presents virtual media. Strong inference: laboratory/security research. No evidence on this page of deployment against a third party. The canonical name **PoisonTap** is normalized outside the quotations. The quoted lines preserve the completed reconstruction's spelling, capitalization, and uncertainty markers. ## Relationships On PDF page 28, PoisonTap appears in the same evidentiary cluster as [[Bootable Virtual Drive|Bootable Virtual Drive]], [[IODD|IODD]], [[ISO Image|ISO Image]], [[Virtual Hard Disk|Virtual Hard Disk]], [[BIOS|BIOS]], [[Unified Extensible Firmware Interface|Unified Extensible Firmware Interface]], [[USB Rubber Ducky|USB Rubber Ducky]], [[Raspberry Pi Zero W|Raspberry Pi Zero W]], [[RMPrepUSB|RMPrepUSB]]. These links record page-level proximity and the reconstruction's systems map; they do not by themselves prove corporate ownership or a direct technical dependency. ## Cross-Notebook Significance Pages 28-30 extend the notebook’s recurring interest in boundary objects—hardware that changes identity according to protocol. This anticipates later concerns with programmable interfaces, hidden menus, and universal interaction. ## Missed Signals and Open Leads Identify the exact IODD model, supported encryption implementation, and target hardware. Separate authorized penetration-testing equipment from ordinary recovery media in the device inventory. ## Sources - [[Scanned_20260730-1802|Scanned_20260730-1802]], especially PDF page 28. - `Scanned_20260730-1802.pdf`, cited as a plain archival filename; the PDF is not stored in `wiki-notes`. - **[S14]** Samy Kamkar, “PoisonTap,” GitHub. https://github.com/samyk/poisontap ## Scanned_20260730-1314 overlay [[Scanned_20260730-1314#Scanned_20260730-1314.pdf — PDF page 12|Pages 12]]: PoisonTap appears in a taxonomy of USB-mediated endpoint attacks and device impersonation. **Relationship overlay:** [[USB Rubber Ducky]] · [[Raspberry Pi Zero W]].