1. Introduction

Hi, this is Dutch here at Dutch CyberWorks.
Today we’re going to be talking about the USB Army Knife by i-am-shodan.
This was probably the second project I really got involved with when I started getting back into pen testing. I’ve always liked projects where you can pick up the hardware, put the firmware on it, and boom—you’re ready to start experimenting. That’s where I started, and honestly, that’s still where I recommend beginners start.
This Field Note is also going to follow a DIY or Buy approach.
If you like building your own gear, I’m going to show you the hardware I use, where to get the firmware, how I flashed it, what storage I use, how I access the interface, and some of the things I’ve learned from actually using the platform.
If you’d rather skip the setup and start with something already put together, I also offer a DCW version built around the LilyGO T-Dongle S3 with the firmware, storage, accessories, demo payload, and quick-start information already included.
Either way, the goal is the same: understand what the platform does and get a usable USB Army Knife in your hands.
When I first got the USB Army Knife running, I couldn’t believe how much functionality was packed into such a little device. It brings together several things that would normally be separate tools and puts them into one small platform.
I have to say, the part I’ve personally used the most is the DuckyScript / HID injection side. I’ve used it for simple demonstrations like Rickrolls, opening Notepad, and having it type out links or information automatically.
I also sell these through my website. The demo I put on the units simply opens Notepad on the computer, opens DutchCyberWorks.com in a browser, and types out a few useful USB Army Knife resources, including the i-am-shodan GitHub page and some YouTube links I think are worth watching.
One thing that really impressed me about the USB Army Knife is the community behind it. There are a lot of people experimenting with the platform, building scripts, testing different hardware, and finding new ways to use it.
The project also has Agent capabilities, although that is one area I haven’t spent enough time with yet to say I completely understand it. I’ve looked into it and seen some impressive demonstrations, but I’m still learning that side of the platform myself.
In this Field Note, we’ll go over the hardware, the main features, the boards I’ve used, what has worked for me, what I’ve had problems with, and how you can either build one yourself or go with the ready-to-use DCW option.
For the price range, I think this is a really good project. If you’re comfortable flashing firmware, it’s also an easy DIY build. I normally use the LilyGO T-Dongle S3. You flash the USB Army Knife firmware onto it, add a microSD card, and you’re pretty much off to the races.
I also like that it has a web-based GUI that works well from a phone and that it can use its HID capabilities to identify itself to a computer as a keyboard.
There are still a lot of parts of USB Army Knife that I haven’t personally explored in depth yet, but I’ve heard and seen good reports about many of them. We’ll go over those features as well, while keeping a clear line between what I’ve actually used myself and what comes from the project documentation and community demonstrations.
2. What Is the USB Army Knife?

The USB Army Knife, created by i-am-shodan, is an open-source penetration-testing platform designed to combine several functions that would normally require separate tools into one small device.
At its core, USB Army Knife can act as much more than a simple BadUSB device. On supported hardware, it can emulate a keyboard, present itself as USB storage or a CD-ROM, operate as a USB network adapter, perform Wi-Fi and Bluetooth testing, capture network traffic, and run scripts through a web-based management interface.
One of its main features is USB HID emulation, which allows the device to identify itself to a computer as a keyboard and execute DuckyScript-style scripts. This is the feature commonly associated with BadUSB-style demonstrations and automated keyboard input.
USB Army Knife also supports mass-storage and CD-ROM emulation, allowing compatible hardware to appear as a USB storage device. It can also emulate a USB network interface, opening up additional network-testing and traffic-capture possibilities.
On ESP32-based versions, USB Army Knife incorporates modified ESP32 Marauder functionality. This adds Wi-Fi and Bluetooth-related tools, including wireless scanning, packet capture, EvilAP functionality, and other wireless-testing features.
- Hands-on note: I have not personally used the ESP32 Marauder functions on either my LilyGO T-Dongle S3 or my Waveshare ESP32-S3-LCD-1.47. That said, I am a big fan of the Marauder platform in general, so this is an area I definitely plan to spend more time with. Those specific USB Army Knife Marauder capabilities are included here based on the project documentation rather than my own testing.
The platform also includes a web-based GUI that can be accessed from a phone, tablet, or computer over Wi-Fi. From there, users can manage scripts, launch functions, and interact with the device without needing to keep it connected to a separate control computer.
Depending on the hardware being used, USB Army Knife can store scripts, files, and results on either a microSD card or internal flash memory. Boards with displays and physical buttons can also use those features for status information, simple menus, progress displays, and triggering scripts.
USB Army Knife also has an optional Agent mode. The agent runs on the connected computer and communicates with the USB Army Knife over its serial connection, allowing additional interaction between the device and the host. This is one of the more advanced parts of the platform and something I have not personally explored in depth yet. Some supported hardware also adds features such as microphone streaming, IR, and external module support.
What makes USB Army Knife interesting is that all of these different capabilities are brought together under one platform. Instead of having one device for HID injection, another for wireless testing, another for storage emulation, and another for network functions, USB Army Knife attempts to combine many of those roles into one compact piece of hardware.
Looking Ahead: USB Army Knife Version 2
The developer is also working on USB Army Knife Version 2. At the time of this Field Note, Version 2 has not been released yet, so these should be considered planned features rather than current capabilities.
Some of the features being discussed for Version 2 include:
- A redesigned and multilingual web interface
- Browser-integrated VNC viewing
- A new USB Army Knife scripting engine
- Expanded DuckyScript-style scripting capabilities
- Additional networking and file-handling functions
- Expanded captive-portal and Bluetooth functionality
- Improved USB storage performance
- Additional multi-device and automation capabilities
- An MCP server and script-validation system designed to work with AI tools for generating and checking USB Army Knife scripts
Version 2 looks like it could be a significant expansion of the platform, especially with the planned scripting and AI integration. This pen tester, for one, is definitely looking forward to messing around with that. I’ll be keeping an eye on it as development continues.
Next, we’ll look at the two hardware platforms I’ve personally used with USB Army Knife: the LilyGO T-Dongle S3 and the Waveshare ESP32-S3-LCD-1.47.
3. Hardware Options and What I’ve Used
When I first got into the USB Army Knife, it was from watching a YouTube video that was using the Waveshare ESP32-S3-LCD-1.47.
That was the first board I bought for it. It worked fine, but I have to admit, I’m a little old school when it comes to hardware and I’ve never really liked exposed boards. There’s nothing wrong with it functionally, but I just prefer something that feels more self-contained.
Then I heard about the LilyGO T-Dongle S3, so I picked up a couple of those. That ended up being the version I really liked.
The LilyGO feels much more like a finished device. The board is enclosed, the screen is built in, and the microSD card is tucked away inside the unit. Everything is compact and self-contained, which makes it a much better fit for the way I actually carry and use equipment.


I’ve also been happy with LilyGO as a company. Their return policies and customer service have been good in my experience. Sometimes it can take a little while for the boards to arrive, but everything I’ve received from them has been well packed and shipped properly. Overall, I’ve been very happy with the LilyGO hardware I’ve bought.
What really surprised me, though, was the quality of the USB Army Knife firmware running on such a tiny computer.
Out of all the different projects I’ve gotten involved with since getting back into pen testing, the USB Army Knife is still one that stands out to me. I keep one in my go pack because it’s the kind of tool that could be useful at almost any time, especially if you already have a good library of scripts loaded and ready to go.
For my own use, the LilyGO T-Dongle S3 is my preferred platform, with the Waveshare 1.47 being the other version I’ve personally used successfully.
Even though I’m not a big fan of the exposed-board design of this particular Waveshare model, I am a big fan of Waveshare in general. I’ve had especially good experiences with their Ethernet HATs and their displays, so my preference for the LilyGO here is really about the form factor of this specific board, not the company.
I’ve also tried some of the cheaper alternatives.
The U-Disk version did not work for me.
The Pocket Dongle was more of a mixed experience. From what I’ve found, those can vary depending on the manufacturer and exact hardware revision, so I wouldn’t completely write them off.
There are also a lot of inexpensive ESP32-S3 dongles on the market that look very similar to the LilyGO. I’ve ended up with a handful of them myself. Some may work fine, but once you start dealing with different manufacturers and board revisions, compatibility can become less predictable.
That is one reason I keep coming back to the LilyGO. If the price is close, I would rather buy the known platform that I already know works well.
4. Flashing, Setup, and Using the Interface

Flashing the USB Army Knife is fairly straightforward once you have the correct firmware for your hardware.
For this Field Note, I updated my LilyGO T-Dongle S3 to the current USB Army Knife release and used the Spacehuhn ESP Web Tool to flash it directly from the browser.
The current firmware can be downloaded from the official USB Army Knife GitHub release page:

USB Army Knife Releases:https://github.com/i-am-shodan/USBArmyKnife/releases
For the LilyGO T-Dongle S3 build I used, the ZIP contained three .bin files along with a .elf file.
The three firmware files were flashed at the following addresses:
bootloader.bin—0x0partitions.bin—0x8000firmware.bin—0x10000
The included .elf file is not flashed. It is mainly used for debugging and symbol information.
I used the Spacehuhn ESP Web Tool for the actual flashing:
Spacehuhn ESP Web Tool:https://esp.huhn.me/
I’ve included a screenshot showing the three firmware files loaded into the web flasher with their corresponding addresses.
Once the firmware finished flashing, I rebooted the LilyGO and confirmed that USB Army Knife was running on the display.
Connecting to the Web Interface
USB Army Knife creates a Wi-Fi access point that can be used to manage the device from a phone, tablet, or computer.
The current project documentation lists the default connection information as:
- Wi-Fi network:
iPhone14 - Password:
password - Web interface:
http://4.3.2.1:8080
In my case, the Wi-Fi connection appeared under a previously saved network rather than exactly the way I expected from the documentation, but once connected, the web interface worked normally.
From the web interface, you can create and manage USB Army Knife scripts, launch payloads, and monitor the device.
After updating the firmware, I tested one of my existing HID payloads, and the demo worked perfectly. It opens a web browser and goes to Dutch CyberWorks, then opens Notepad and types out several useful USB Army Knife links and resources without automatically opening those additional links.
It’s also easy to find some starter scripts on the official USB Army Knife GitHub page. Using the link included in this Field Note, go to the Scripts section and look through the examples. One of the first ones I’d recommend trying is the Rickroll script. It’s basically a simple demo payload, but it’s a good way to get familiar with the USB Army Knife interface and how scripts are loaded and run.
microSD Card
The LilyGO T-Dongle S3 has a microSD card slot hidden inside the USB-A end of the device.
You do not need the microSD card installed just to flash the firmware, but it is useful for storing scripts, files, and other USB Army Knife content.
In my experience, 4 GB and 8 GB microSD cards are plenty large enough for this platform, and they have seemed to work better for me than larger 16 GB or 32 GB cards.
I don’t have a confirmed technical explanation for that. It may have something to do with filesystem behavior, indexing, card controllers, or something else entirely. I simply know that the smaller cards have felt quicker and more reliable in the USB Army Knife units I’ve used.
That should be treated as my personal experience rather than an official USB Army Knife requirement.
The problem is that good-quality 4 GB and 8 GB cards are getting harder to find. Because of that, I may end up including 16 GB microSD cards with the DCW units simply because they are easier to source reliably.
One useful thing I confirmed while updating this unit is that reflashing the firmware did not erase the contents of my microSD card. After flashing the new firmware, my existing payload was still there and worked normally.
Where Are the ESP32 Marauder Functions?
One thing that can be confusing is that you may not see a separate ESP32 Marauder application or menu inside USB Army Knife.
The Marauder functionality is integrated into the USB Army Knife scripting system.
USB Army Knife uses a DuckyScript-style language that has been expanded with additional USB Army Knife commands, including ESP32 Marauder functionality. That means wireless functions can be incorporated directly into scripts alongside HID, USB, storage, networking, and other actions.
So rather than launching a separate Marauder firmware, you create or edit a USB Army Knife script and call the supported Marauder functions from within that script.
I have not personally spent much time experimenting with the Marauder commands inside USB Army Knife yet, even though I am a big fan of the ESP32 Marauder platform itself. That is another part of USB Army Knife I plan to explore further.
5. My Hands-On Use With DuckyScript and HID
Hi, Dutch again from Dutch CyberWorks.
I hope you’ve enjoyed the Field Note so far. In this section, I’m going to get into my own hands-on experience with DuckyScript and USB HID on the USB Army Knife.
Most of what I’ve personally done with USB Army Knife has been on the HID side. I had my AI help me write a simple DuckyScript-style demo that would open Notepad, open a website, and type out a few useful links just to see how the platform behaved.
It worked well, and the version I’m using now is basically an expanded version of that original test.
When you select the demo and hit Execute, it opens Notepad, then opens a web browser and goes to:
DutchCyberWorks.com
The demo also types out several USB Army Knife-related links and resources that I’ve found useful, so you have a few good places to start exploring the platform.
That has honestly been the bulk of my hands-on use with DuckyScript so far.
I’m more of a Wi-Fi person myself, which is one of the reasons the integrated Marauder capabilities interest me so much. Between that and what is being planned for USB Army Knife Version 2, I’m really looking forward to seeing where the project goes next.
At this point, I’d probably describe myself as more of a hacker emeritus than somebody trying to spend every night building complicated payloads. Most of my use has been experimenting with demos, testing the hardware, and getting familiar with what the platform can do.
I also know people who have had success using the USB Army Knife Agent functionality, including being able to view what is happening on a target computer screen. I haven’t personally spent enough time with that side of the platform to claim much hands-on experience with it, so I’d rather be clear about that than pretend otherwise.
For me, the real value has been how easy USB Army Knife makes it to start small. You can begin with a simple HID demo, learn how the scripting works, and then move into the more advanced USB, wireless, and Agent capabilities as you get more comfortable with the platform.
6. Recommended Resources: Hakista and Valley Tech Customs
Oh man, Hakista. He is the man on YouTube when it comes to this stuff.
I love his videos. A lot of what he covers is still beyond where I’m at right now, especially since I’m getting back into pen testing after being away from it for about 20 years. I’m still working through the Junior Penetration Tester material on TryHackMe myself.
That said, Hakista is one of the best resources I’ve found for the USB Army Knife. He goes much deeper into the platform than I do, especially when it comes to things like the Agent functionality and some of the more advanced workflows.
I’ve included three of Hakista’s USB Army Knife videos below, including a beginner-oriented video, a more complete guide, and a Waveshare hardware walkthrough.
Hakista USB Army Knife Ultimate Guide:https://www.youtube.com/watch?v=hvovjyw2IYM&t=884s
Hakista Waveshare USB Army Knife Video:https://www.youtube.com/watch?v=roNRKHlf9f0
Hakista Beginner USB Army Knife Video:https://www.youtube.com/watch?v=e1oLkWlMVdE&t=16s
Hakista Website:https://hakista.com/
If you’re interested in digging deeper into the USB Army Knife, Hakista is definitely a resource worth keeping bookmarked.
Valley Tech Customs
Cal from Valley Tech Customs is another one of the first creators I started watching when I was getting back into this arena.
Valley Tech Customs is a really good YouTube channel to follow. If something new is coming out in the cyber-gadget and hardware world, Cal usually seems to have his hands on it early, if not one of the first.
I’ve included one of his USB Army Knife videos here as another good look at the platform:
Valley Tech Customs — USB Army Knife:https://www.youtube.com/watch?v=_E7mgh94wxk&t=425s
Valley Tech Solutions / Valley Tech Customs Website:https://valleytechsolutions.tech/
It’s also worth simply searching “USB Army Knife” on YouTube. There are a lot of useful demonstrations, setup guides, build videos, and different takes on the platform, and new material continues to appear as USB Army Knife evolves.
7. DIY or Buy: The DCW Option
If you want to build your own USB Army Knife, this Field Note should give you a good starting point. You can buy the hardware yourself, download the firmware, flash it, add a microSD card, and build the setup exactly the way you want.
If you’d rather skip that part, the Dutch CyberWorks version is built around the LilyGO T-Dongle S3 and comes ready to go.
The DCW package includes:
- LilyGO T-Dongle S3
- USB Army Knife firmware pre-flashed
- microSD card included
- USB-A / USB-C adapter set
- Custom DCW printed case
- Original LilyGO hard shipping case with foam insert
- DCW demo payload already loaded
- Printed quick-start / cheat sheet
The quick-start sheet is basically the condensed version of what you’ve learned in this Field Note. It covers the basic connection information, where to get the firmware, where to find scripts, and the key USB Army Knife resources you’ll probably want right away.
It’s there for people who buy the product and just want to get started without having to sit down and read through the whole blog post first.
The idea is not to hide how any of this works. In fact, this Field Note shows you how to build one yourself.
The DCW option is simply there for people who would rather skip the flashing, sourcing, and setup and start with a complete package.
I also like including the original LilyGO case because it gives you a second storage option. The custom DCW case is meant to be the finished everyday setup, while the original LilyGO case is compact and useful if you want something smaller for storage or travel.
For me, that is really what DIY or Buy means: if you want to build it yourself, go for it. If you want to save some time and start with the hardware already put together, that option is there too.
8. Final Thoughts
The USB Army Knife is still one of those projects that stands out to me.
It takes a bunch of things that would normally feel like separate tools and puts them into one small piece of hardware. HID injection, storage, networking, wireless functions, scripting, and a web interface all living on something the size of a USB dongle is still pretty impressive.
For me, the LilyGO T-Dongle S3 is the version that makes the most sense. I’ve used the Waveshare board and it works, but I prefer having everything enclosed and self-contained. If I’m going to carry something in my go pack, I want it protected and ready to use.
I also think this is a good project for somebody getting started.
You don’t have to understand every part of USB Army Knife on day one. You can start with something simple like a Rickroll or a harmless HID demo, learn how the scripting and interface work, and then move into more advanced features as you get comfortable.
That is pretty much how I approached it myself.