# PoisonTap
PoisonTap is Samy Kamkar's Raspberry Pi Zero USB-network research project; it matters here as proof that USB can present a network identity rather than only storage.
## Historical and Technical Context
The page compares legitimate multiboot/storage devices with offensive USB research. IODD devices emulate optical disks or virtual drives from stored ISO/VHD images, allowing one physical unit to present many bootable environments across legacy BIOS and UEFI systems. RMPrepUSB is a boot-media preparation and testing utility. Hak5’s Rubber Ducky class uses USB HID behavior to inject keystrokes; PoisonTap used a Raspberry Pi Zero configured as a USB Ethernet gadget to manipulate a locked computer’s network behavior and siphon web credentials/cookies. [S14] The page’s conceptual insight is that **USB is not merely storage**: the same connector can impersonate disks, keyboards, serial devices, or network adapters.
## Role in Scanned_20260730-1802
The primary identifying evidence appears on PDF page 28. A landscape-oriented page with a rectangular copper/orange tape patch at upper right. The writing is divided into a boot-media block and a security-research block. Arrows and slashes connect ISO/VHD, legacy/UEFI, and named USB attack projects. Within that page, PoisonTap helps the notebook move from a visible name or artifact toward the underlying identity, protocol, ownership, or control structure.
## Notebook Evidence
- `Scanned_20260730-1802.pdf`, PDF page 28: "PoisonTap (Attack)"
**Evidentiary status:** Visible evidence: explicit “Attack” labels and boot-mode comparison. Verified fact: PoisonTap used Raspberry Pi Zero USB networking; IODD presents virtual media. Strong inference: laboratory/security research. No evidence on this page of deployment against a third party.
The canonical name **PoisonTap** is normalized outside the quotations. The quoted lines preserve the completed reconstruction's spelling, capitalization, and uncertainty markers.
## Relationships
On PDF page 28, PoisonTap appears in the same evidentiary cluster as [[Bootable Virtual Drive|Bootable Virtual Drive]], [[IODD|IODD]], [[ISO Image|ISO Image]], [[Virtual Hard Disk|Virtual Hard Disk]], [[BIOS|BIOS]], [[Unified Extensible Firmware Interface|Unified Extensible Firmware Interface]], [[USB Rubber Ducky|USB Rubber Ducky]], [[Raspberry Pi Zero W|Raspberry Pi Zero W]], [[RMPrepUSB|RMPrepUSB]]. These links record page-level proximity and the reconstruction's systems map; they do not by themselves prove corporate ownership or a direct technical dependency.
## Cross-Notebook Significance
Pages 28-30 extend the notebook’s recurring interest in boundary objects—hardware that changes identity according to protocol. This anticipates later concerns with programmable interfaces, hidden menus, and universal interaction.
## Missed Signals and Open Leads
Identify the exact IODD model, supported encryption implementation, and target hardware. Separate authorized penetration-testing equipment from ordinary recovery media in the device inventory.
## Sources
- [[Scanned_20260730-1802|Scanned_20260730-1802]], especially PDF page 28.
- `Scanned_20260730-1802.pdf`, cited as a plain archival filename; the PDF is not stored in `wiki-notes`.
- **[S14]** Samy Kamkar, “PoisonTap,” GitHub. https://github.com/samyk/poisontap
## Scanned_20260730-1314 overlay
[[Scanned_20260730-1314#Scanned_20260730-1314.pdf — PDF page 12|Pages 12]]: PoisonTap appears in a taxonomy of USB-mediated endpoint attacks and device impersonation.
**Relationship overlay:** [[USB Rubber Ducky]] · [[Raspberry Pi Zero W]].