Skip to content

About

A Python-based USB Device Control & Monitoring Framework for Windows, designed to detect and audit USB device activity in real time. The project identifies USB devices, enforces allowlist/blocklist policies, and audits file movements on removable storage to enhance endpoint security.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

USB Device Control & Monitoring Framework

📌 Project Overview

The USB Device Control & Monitoring Framework is a cybersecurity project designed to monitor, control, and audit USB device activity on a Windows system.

The framework detects real USB device connection and disconnection events, identifies devices using hardware identifiers such as Vendor ID (VID) and Product ID (PID), enforces allowlist and blocklist policies, and audits file movement when removable USB storage is detected.

This project focuses on real device monitoring using operating system APIs and does not rely on simulations, Artificial Intelligence, or Machine Learning.


🎯 Objectives

  • Detect USB device plug and unplug events in real time
  • Identify USB devices using VID and PID
  • Enforce allowlist and blocklist security policies
  • Log unauthorized or suspicious USB activity
  • Audit file movement on removable USB storage
  • Generate detailed USB security logs

🛠️ Technologies Used

  • Programming Language: Python
  • Operating System: Windows

Python Libraries:

  • wmi – USB device monitoring via Windows Management Instrumentation
  • pywin32 (win32file) – Drive type detection
  • re – Vendor ID and Product ID extraction
  • os – File system operations
  • datetime – Timestamped logging

🧩 Project Structure


USB_Device_Control_Framework/
│
├── modules/
│   ├── usb_monitor.py
│   ├── device_manager.py
│   ├── policy_engine.py
│   ├── file_auditor.py
│   └── logger.py
│
├── data/
│   ├── allowlist.txt
│   └── blocklist.txt
│
├── logs/
│   └── usb_activity.log
│
├── main.py
└── README.md


⚙️ How the Framework Works

  1. The system continuously monitors USB ports for device changes
  2. When a USB device is detected, device information is extracted
  3. Vendor ID and Product ID are parsed from the device identifier
  4. The device is checked against allowlist and blocklist rules
  5. Allow or block decisions are logged
  6. If removable USB storage is detected, file movement auditing begins
  7. All events are logged for security auditing

🚨 Allowlist & Blocklist Policy

  • Allowlist: Contains approved USB device VID/PID values
  • Blocklist: Contains unauthorized or suspicious USB devices

Human Interface Devices (HID) such as keyboard and mouse are allowed by default to ensure system usability.


📂 File Movement Auditing

The file auditing module monitors:

  • File creation
  • File deletion
  • File modification

Auditing is automatically triggered only when removable USB storage is present.
If no removable storage is detected (for example, when only a USB mouse is connected), the system logs that no file activity was found.

This behavior matches real-world endpoint security tools.


▶️ How to Run the Project

Step 1: Install dependencies

pip install wmi pywin32

Step 2: Run the framework

python main.py

Step 3: Trigger USB activity

  • Plug or unplug a USB device (mouse, keyboard, or storage device)
  • Observe logs in logs/usb_activity.log

📄 Output Generated

  • USB device detection logs
  • Allow or block decision logs
  • File movement audit logs
  • Timestamped USB activity records

📸 Screenshots

Screenshots included in the project documentation show:

  • Framework running successfully
  • Detection of a real USB device (mouse)
  • File auditing output
  • Project directory structure

🎓 Learning Outcomes

  • Understanding USB device interaction with the OS
  • Endpoint security monitoring techniques
  • Device fingerprinting using VID and PID
  • File system auditing concepts
  • Blue-team defensive security practices

🔮 Future Enhancements

  • Centralized SIEM integration
  • Alerting and notifications
  • Advanced file integrity monitoring
  • Cross-platform USB monitoring

👨‍💻 Author

Mohit Kumar Singh Cyber Security Internship Project



---

## 🏁 FINAL STATUS (HONEST)
✔ Real USB monitoring  
✔ No simulation code  
✔ GitHub-safe  
✔ PDF ready  
✔ PPT ready  
✔ README done  

Boss, you’ve officially **completed TWO solid cybersecurity projects** end-to-end.  
Whenever you’re ready for the **next project or upgrade**, just call me 🔥👏

About

A Python-based USB Device Control & Monitoring Framework for Windows, designed to detect and audit USB device activity in real time. The project identifies USB devices, enforces allowlist/blocklist policies, and audits file movements on removable storage to enhance endpoint security.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages