BadUSB Protection

This guide explains how to turn on BadUSB protection in My OPSWAT Central Management and how to read the results.

This features applies to Windows Endpoints and Windows Kiosks that are managed by My OPSWAT Central Management and have Peripheral Media Protection enabled.

What BadUSB Protection Does

Most USB security checks look at the files on a drive. BadUSB attacks work differently: the danger is the device itself.

A USB stick can carry firmware that makes Windows see it as a keyboard and type commands the moment it is plugged in. A charging cable can hide a radio. A memory stick can register itself as a network adapter and quietly reroute traffic. Nothing on the device has to look like malware for any of this to work.

BadUSB protection inspects the peripheral itself, including how it identifies to the operating system, what it claims to be, and how it behaves on connection. It reports anything suspicious as a device threat, separately from file scanning results.

Please Note BadUSB protection does not replace file scanning. A single session can produce both file findings (malware, data loss, sanitization) and device findings (BadUSB). My OPSWAT Central Management keeps the two on separate tabs so you can tell them apart.

BadUSB Category and Status

Every device finding has a Category (what kind of threat it is) and a Status (how certain the detection is).


Category

What It Means

Example Attacks

Deceptive Device

The peripheral presents itself as something it is not

Network adapter spoofing; combined keyboard and storage attack; malicious charging cable

Physical Attack

The peripheral tries to act directly on the machine it is plugged into

Malicious keyboard impersonation; keystroke injection; BadUSB firmware replacement

Unapproved Device

The peripheral is not on the list of devices you allow

Unapproved peripheral device

Status

What It Means

What To Do

DETECTED

The attack pattern was confirmed

Treat as an incident: identify the device from Session Details and the person who used it

SUSPECTED

Indicators were found but the evidence is not conclusive

Review the risk description and the hardware details before deciding

NOT DETECTED

The check ran and found nothing

No action

Turn On BadUSB Protection

BadUSB protection is configured per policy, so it applies to every device group that policy is assigned to.

  1. Go to Peripheral Media Protection > Policies. Open the policy that is assigned to the group you want to protect, or select Create New Policy

  2. Open the Peripheral Device Control tab, then the Windows sub-tab

  3. Switch the tab toggle from Inactive to Active

  4. Select Enable BadUSB protection

    1. Optionally select Enable unapproved device to detect and isolate peripherals that impersonate trusted devices such as keyboards, and Show Certified badge for matched vendors and product IDs to mark devices you have already approved

  5. Select Save. The change reaches the endpoints at their next sync


Please Note Peripheral Device Control is available for Windows only. The macOS sub-tab under Peripheral Media Protection is unaffected by these settings.

BadUSB Reports

The Reports module is designed as a drill-down experience, letting you move from high-level aggregates down to the exact attack on a specific device:

Drill Down Path

What You See

Go to Peripheral Media Protection > Reports

  1. At the top of the Reports page, two summary cards provide aggregate statistics across all sessions (files processed, threats detected, device threats)


  1. The table lists individual Session ID with status, content blocked, device threats, peripheral name, user, and timestamp


Click any Session ID to open the full report

  1. The top summary provides breakdown of one session: file results, device findings, and metric chips


  1. Switch between the Files tab and Device tab to isolate file-level vs. hardware-level threats

  • Files tab lists file-level scan results for the session, including details about each malicious or suspicious file detected


  • Device tab lists device-level (BadUSB) findings. This is where you investigate peripheral hardware threats. Read the risk description to understand what the peripheral attempted.


Select the Session Details button at the top-right

Identify the exact hardware, including vendor, model, serial number, firmware version, USB version, along with the endpoint that ran the scan and when. This is what you need in order to physically locate the device.


Check Affected Devices

Go to Inventory > Devices, open the Kiosk Windows or Endpoint tab, then select a device name.

  • The cards at the top show Peripheral Content Blocked and Peripheral Media Threats for the last 24 hours.

  • Reports lists every session for that device (7D or 30D) and links to the same report details.

  • Peripheral Inventory shows the peripherals seen on the device, with an Events tab for their activity.