Skip to content
Open access

ControlPuc v0: A HID Injection Framework with RP2350

Jul 2026 · International Journal of Research in Engineering, Science and Management · 0 citations

Abstract

Modern endpoint security systems can easily detect and block non-standard USB Human Interface Devices (HIDs), limiting the effectiveness of hardware-based penetration testing tools. This paper presents ControlPuc v0, a stealth-oriented hardware-software framework designed to evaluate endpoint resilience against advanced HID emulation attacks. Built on the RP2350 microcontroller with a custom micro-runtime [7], the system uses a physical pin-voltage interlock to switch between maintenance and stealth modes. To evade forensic detection, low-level firmware modifications disable Mass Storage Class descriptors, preventing automatic drive enumeration by Data Loss Prevention (DLP) systems. An anthropomorphic input engine introduces deterministic 5 ms delays between USB transactions to mimic human interaction and evade behavioral analysis. Additionally, an asynchronous outbound HTTP pull-based communication model enables reliable remote orchestration while bypassing stateful network restrictions. The framework highlights critical weaknesses in current heuristic endpoint defense mechanisms.

Read PDF