The USB Device Control & Monitoring Framework is a cybersecurity project designed to monitor, control, and audit USB device activity on a Windows system.
The framework detects real USB device connection and disconnection events, identifies devices using hardware identifiers such as Vendor ID (VID) and Product ID (PID), enforces allowlist and blocklist policies, and audits file movement when removable USB storage is detected.
This project focuses on real device monitoring using operating system APIs and does not rely on simulations, Artificial Intelligence, or Machine Learning.
- Detect USB device plug and unplug events in real time
- Identify USB devices using VID and PID
- Enforce allowlist and blocklist security policies
- Log unauthorized or suspicious USB activity
- Audit file movement on removable USB storage
- Generate detailed USB security logs
- Programming Language: Python
- Operating System: Windows
wmi– USB device monitoring via Windows Management Instrumentationpywin32 (win32file)– Drive type detectionre– Vendor ID and Product ID extractionos– File system operationsdatetime– Timestamped logging
USB_Device_Control_Framework/
│
├── modules/
│ ├── usb_monitor.py
│ ├── device_manager.py
│ ├── policy_engine.py
│ ├── file_auditor.py
│ └── logger.py
│
├── data/
│ ├── allowlist.txt
│ └── blocklist.txt
│
├── logs/
│ └── usb_activity.log
│
├── main.py
└── README.md
- The system continuously monitors USB ports for device changes
- When a USB device is detected, device information is extracted
- Vendor ID and Product ID are parsed from the device identifier
- The device is checked against allowlist and blocklist rules
- Allow or block decisions are logged
- If removable USB storage is detected, file movement auditing begins
- All events are logged for security auditing
- Allowlist: Contains approved USB device VID/PID values
- Blocklist: Contains unauthorized or suspicious USB devices
Human Interface Devices (HID) such as keyboard and mouse are allowed by default to ensure system usability.
The file auditing module monitors:
- File creation
- File deletion
- File modification
Auditing is automatically triggered only when removable USB storage is present.
If no removable storage is detected (for example, when only a USB mouse is connected), the system logs that no file activity was found.
This behavior matches real-world endpoint security tools.
pip install wmi pywin32python main.py- Plug or unplug a USB device (mouse, keyboard, or storage device)
- Observe logs in
logs/usb_activity.log
- USB device detection logs
- Allow or block decision logs
- File movement audit logs
- Timestamped USB activity records
Screenshots included in the project documentation show:
- Framework running successfully
- Detection of a real USB device (mouse)
- File auditing output
- Project directory structure
- Understanding USB device interaction with the OS
- Endpoint security monitoring techniques
- Device fingerprinting using VID and PID
- File system auditing concepts
- Blue-team defensive security practices
- Centralized SIEM integration
- Alerting and notifications
- Advanced file integrity monitoring
- Cross-platform USB monitoring
Mohit Kumar Singh Cyber Security Internship Project
---
## 🏁 FINAL STATUS (HONEST)
✔ Real USB monitoring
✔ No simulation code
✔ GitHub-safe
✔ PDF ready
✔ PPT ready
✔ README done
Boss, you’ve officially **completed TWO solid cybersecurity projects** end-to-end.
Whenever you’re ready for the **next project or upgrade**, just call me 🔥👏