A Windows-based C# cybersecurity assessment utility designed to monitor USB devices, analyze files for suspicious indicators, correlate USB-launched processes with network connections, inspect Windows security events, assess potential BadUSB/HID anomalies, control USB devices, and perform additional malware assessment using ML.NET and YARA.
Security assessment tool: This project provides indicators and observations for security analysis. It is not intended to replace Microsoft Defender, enterprise EDR/XDR platforms, endpoint security products, or professional malware-analysis environments.
USB devices are commonly used for data transfer, software installation, system maintenance, and offline file exchange. They can also introduce potentially unwanted or malicious files into a Windows environment.
Enhanced USB Threat Detection & Behavior Analysis Tool provides a collection of Windows security assessment functions from a single administrative console.
The tool combines:
- USB device enumeration
- Continuous USB monitoring
- Real-time USB connection monitoring
- USB file analysis
- File extension and filename heuristics
- File entropy analysis
- Suspicious file identification
- Optional file quarantine
- USB process monitoring
- Process/network correlation
- Windows Event Log analysis
- Security event monitoring
- BadUSB/HID assessment
- USB storage activity monitoring
- USB device disable/enable operations
- ML.NET-based file assessment
- YARA rule scanning
- Security findings collection
- Threat assessment reporting
- Security and diagnostic logging
Continuously queries Windows USB device information and tracks devices over time.
The monitoring system can display:
- Device name
- Manufacturer
- USB Vendor ID (VID)
- USB Product ID (PID)
- Device status
- First observed connection time
- Last observed time
- Internal risk/review level
The device scanner periodically refreshes the USB device inventory and maintains tracked device profiles.
USB Device Continuous Monitoring
[Device 1]
VID:PID: 0781:5581
Name: USB Mass Storage Device
Manufacturer: SanDisk
Status: OK
Monitors the current USB device inventory and reports changes.
The tool can identify when a USB device:
- Appears
- Is removed
- Remains connected
Example:
[21:30:15] USB device detected: USBSTOR\...
[21:30:18] USB devices present: 2
[21:31:02] USB device no longer detected: USB\...
Press:
S
to stop monitoring.
The file-analysis module recursively scans a selected USB storage drive.
The tool examines file characteristics including:
- Executable files
- Dynamic-link libraries
- Drivers
- Screensavers
- Control Panel extensions
- Scripts
- Installers
- Archives
- Suspicious filenames
- File entropy
- Large executable files
The current implementation reviews extensions such as:
.exe
.dll
.scr
.com
.cpl
.ocx
.sys
.vbs
.vbe
.bat
.cmd
.ps1
.psm1
.js
.jse
.wsf
.wsh
.msi
.msp
.zip
.rar
.7z
The tool checks filenames against a collection of suspicious keyword patterns.
Current examples include:
malware
trojan
virus
ransom
worm
backdoor
exploit
payload
keylog
stealer
A filename match is treated as a review indicator, not automatic proof that the file is malicious.
For example:
[REVIEW] Suspicious filename:
E:\Downloads\possible_payload.exe
The tool can calculate Shannon entropy for supported files.
Entropy can help identify files that contain highly compressed, encrypted, or packed data.
Example:
Entropy: 7.82
High entropy may be useful during malware triage, particularly for packed or encrypted executables.
However:
High entropy does not prove that a file is malware.
Legitimate software, installers, compressed files, and encrypted data can also have high entropy.
The implementation currently limits entropy processing to files up to:
100 MB
and applies a timeout to prevent excessively long analysis.
Files identified by the current heuristic review process can optionally be moved into an application quarantine directory.
The quarantine location is:
%LOCALAPPDATA%\EnhancedUSBThreatDetection\Quarantine
Files are renamed using a timestamp and GUID to reduce filename collisions.
Example:
20260924_213045123_8f1..._suspicious.exe
The tool asks for confirmation before moving files:
Quarantine these files? (Y/N):
Important: The quarantine feature is an application-level file move. It is not equivalent to Microsoft Defender quarantine or an enterprise endpoint security quarantine mechanism.
The tool identifies currently running processes whose executable paths originate from removable USB storage.
It uses Windows process information to examine:
Process Name
Process ID
Executable Path
It can then correlate those process IDs with established TCP connections.
Example output:
--- PROCESSES RUNNING FROM USB STORAGE ---
Name ProcessId ExecutablePath
---- --------- --------------
tool.exe 4216 E:\Tools\tool.exe
Network correlation can include:
Local Address
Local Port
Remote Address
Remote Port
Owning Process
This can help with basic incident-response investigation when an executable is launched directly from removable storage.
The tool queries available Windows event logs for USB-related activity.
The current implementation can inspect events including:
2003
2004
2100
2102
20001
20003
Depending on Windows configuration, these events may provide information related to:
- USB driver activity
- Device activity
- Plug and Play activity
- Driver installation
- Device installation
Event availability varies by Windows version and configuration.
The security-event module queries existing Windows Security logs.
The current implementation examines:
Process creation.
Windows Filtering Platform allowed network connection.
Object access activity.
Registry value modification.
It also queries USB-related Driver Framework events.
The tool does not silently modify Windows audit policy.
If the required auditing is not enabled, the corresponding events may not exist.
The tool provides an observational assessment of USB and HID devices.
It examines information such as:
- USB device status
- Device class
- Friendly name
- Manufacturer
- Instance ID
- Vendor IDs
- HID-class devices
It can identify review indicators such as:
Duplicate Vendor ID groups
Unknown manufacturer information
USB/HID device observations
Example:
[REVIEW] 1 Vendor ID group(s) contain multiple devices.
The application intentionally does not treat these indicators as proof of malicious hardware.
A shared Vendor ID or missing manufacturer information alone is not sufficient to establish that a device is a BadUSB device.
The storage activity monitor measures changes in used storage space on a selected removable drive.
It records:
Initial used storage
Final used storage
Net storage change
Net size-change rate
Example:
Initial used storage: 1024.50 MB
Final used storage: 1100.20 MB
Net size change: 79,364,096 bytes
Net size-change rate: 2.52 MB/s
This feature measures net storage-size change.
It does not claim to measure:
- USB bus throughput
- Actual read bandwidth
- Actual write bandwidth
- USB controller throughput
- Network transfer rate
Administrators can disable supported USB devices using Windows Plug and Play management.
The tool uses:
pnputil.exe
The workflow requires confirmation before disabling the selected device.
Example:
Enter Device Instance ID to BLOCK:
The tool then attempts to verify that Windows reports the device as:
Disabled
This feature requires Administrator privileges.
Previously disabled USB devices can also be enabled through the tool.
The tool searches for USB devices reported as:
Error
Unknown
Disabled
After confirmation, it uses Windows Plug and Play management to attempt to enable the selected device.
The tool verifies whether the resulting status is reported as:
OK
The project includes an optional ML.NET assessment component.
The current model uses file-oriented features such as:
File Size
Entropy
Executable Count
The application creates or loads:
malware_model_v2.zip
The model uses binary classification through ML.NET.
The current training dataset is intentionally small and embedded in the application for demonstration and development purposes.
[ML.NET] Assessment Results
File: example.exe
Size: 245,760 bytes
Entropy: 7.31
Executable count: 1
Probability: 82.15%
Score: 1.5264
The included model should not be considered a production-grade malware detection model.
A real malware classification system requires a substantially larger and carefully validated dataset containing representative benign and malicious samples, appropriate feature engineering, evaluation, validation, and ongoing model maintenance.
The ML.NET component is intended primarily for:
- Research
- Experimentation
- Security assessment
- Demonstration
- Local malware-analysis workflows
The project supports external YARA rule scanning.
The application searches trusted locations for:
yara.exe
Supported locations include:
ApplicationDirectory\Tools\yara.exe
ApplicationDirectory\yara.exe
C:\YARA\yara.exe
C:\Program Files\YARA\yara.exe
C:\Program Files (x86)\YARA\yara.exe
YARA rules should be stored under:
YaraRules\
Supported rule extensions:
.yar
.yara
The tool can scan:
- Individual files
- Directories
- Recursive directory contents
The application interprets YARA results using the standard convention:
0 = Match
1 = No match
Other = Error
Example:
[YARA] ⚠ Match: malware_rules.yar
The application maintains a collection of security findings generated during analysis.
Findings can originate from:
- USB file scanning
- Quarantine operations
- BadUSB assessment
- USB storage monitoring
- USB device control
- Windows event monitoring
- ML.NET assessment
- YARA assessment
Each finding contains:
Timestamp
Category
Threat level
Details
The application maintains up to:
500
recent findings in memory.
The application defines the following assessment levels:
Safe
Low
Medium
High
Critical
These levels represent the application's assessment logic and should not be interpreted as definitive malware classifications.
For example, the USB file scoring system considers:
- Number of executables
- Number of scripts/installers
- Suspicious filename indicators
The resulting score is converted into a review level.
The tool can generate a text-based security report.
Reports are saved under:
%USERPROFILE%\Documents\EnhancedUSBThreatDetection\Reports
Example:
USBThreatReport_20260924_213045.txt
Reports can contain:
- Computer information
- Windows version
- USB devices
- Vendor/Product IDs
- Manufacturer information
- Connection timestamps
- USB drive scan results
- Executable counts
- Review levels
- Recent security findings
- Assessment notes
The application maintains application logs under:
%LOCALAPPDATA%\EnhancedUSBThreatDetection\Logs
USBSecurityLog.txt
Used for security-related administrative actions such as device enable/disable operations.
USBDebug.log
Used for application diagnostics and operational errors.
The application currently requires:
Windows 10 / Windows 11
Administrator privileges are required for functionality involving device management and certain system-level queries.
The project is designed for a modern .NET runtime supporting the APIs used by the application.
Recommended:
.NET 8 or later
depending on the project's .csproj configuration.
The project requires the appropriate ML.NET packages used by the source code.
For example:
Microsoft.ML
The project also uses Windows Management Instrumentation APIs through:
System.Management
Make sure the corresponding package/reference is included in the project configuration when required by the target framework.
YARA is optional.
If YARA is installed, place the executable in one of the supported locations.
Recommended application structure:
EnhancedUSBThreatDetection/
│
├── EnhancedUSBThreatDetection.exe
├── malware_model_v2.zip
│
├── Tools/
│ └── yara.exe
│
└── YaraRules/
├── rules.yar
├── malware.yar
└── custom_rules.yara
Only use YARA rules that you trust and understand.
For additional USB device history and monitoring information, users may also use USBDeview by NirSoft.
USBDeview is a Windows utility that displays information about USB devices currently connected to the computer and USB devices that were previously connected to the system.
- USB device name
- Description
- Device type
- Connected status
- Vendor ID (VID)
- Product ID (PID)
- Serial number
- Device instance ID
- USB device connection history
- First connection time
- Last connection time
- Device driver information
- USB hub information
- Additional USB device properties
This can be useful as a supplementary USB investigation and verification tool alongside the Enhanced USB Threat Detection & Behavior Analysis Tool.
Official NirSoft website:
https://www.nirsoft.net/utils/usb_devices_view.html
Important: USBDeview is developed and distributed by NirSoft and is not part of this project. The project does not modify, redistribute, or claim ownership of USBDeview.
Users should download USBDeview directly from the official NirSoft website and review the software documentation and licensing information before use.
USBDeview can be used as an additional source of USB device information:
Enhanced USB Threat Detection
│
├── USB Device Inventory
├── USB File Analysis
├── Process / Network Correlation
├── Windows Event Analysis
├── BadUSB / HID Assessment
└── Threat Reporting
│
▼
USB Investigation
│
└── USBDeview
│
├── Current USB Devices
├── Previously Connected Devices
├── VID / PID
├── Serial Information
└── Connection History
USBDeview results should be treated as supplementary evidence. Device presence, connection history, VID/PID information, or other USB metadata does not by itself establish that a device is malicious.
Use the following official NirSoft page to obtain USBDeview:
https://www.nirsoft.net/utils/usb_devices_view.html
EnhancedUSBThreatDetection/
│
├── Program.cs
├── EnhancedUSBThreatDetection.csproj
├── malware_model_v2.zip
│
├── Tools/
│ └── yara.exe
│
├── YaraRules/
│ ├── example.yar
│ └── custom.yara
│
└── README.md
Runtime-created data:
%LOCALAPPDATA%\EnhancedUSBThreatDetection\
│
├── Logs/
│ ├── USBSecurityLog.txt
│ └── USBDebug.log
│
└── Quarantine/
Reports:
%USERPROFILE%\Documents\EnhancedUSBThreatDetection\
└── Reports/
Run the application as Administrator.
The main menu provides:
================================================================
ENHANCED USB THREAT DETECTION & BEHAVIOR ANALYSIS TOOL
================================================================
1. List USB Devices with Continuous Monitoring
2. Start Real-time USB Monitoring
3. Analyze USB Files for Threat Indicators
4. Monitor USB Processes & Correlate Network Activity
5. Check USB Behavior & Windows Event Activity
6. Generate Threat Report
7. BadUSB / HID Anomaly Assessment
8. USB Storage Activity Monitoring
9. Block USB Device
10. Enable USB Device
11. Windows Security Event Monitoring
12. ML.NET & YARA File Analysis
0. Exit
A basic USB security assessment can be performed in the following order:
Run:
1. List USB Devices with Continuous Monitoring
Record:
- Device name
- Manufacturer
- VID
- PID
- Device status
Run:
3. Analyze USB Files for Threat Indicators
Review:
- Executables
- Scripts
- Installers
- Suspicious filenames
- Entropy indicators
Run:
4. Monitor USB Processes & Correlate Network Activity
Look for processes executing directly from removable storage.
Run:
5. Check USB Behavior & Windows Event Activity
and:
11. Windows Security Event Monitoring
Run:
12. ML.NET & YARA File Analysis
Use both ML.NET and YARA results as additional assessment indicators.
Run:
6. Generate Threat Report
to preserve the application's collected findings.
This project is designed for defensive security assessment.
The tool should be used only on:
- Computers you own
- Systems you are authorized to administer
- USB devices you are authorized to inspect
Do not use the device-control functionality on systems where you do not have administrative authorization.
Before quarantining or disabling a device, verify that it is not required for:
- System operation
- Authentication
- Backup
- Data recovery
- Business-critical hardware
- Accessibility equipment
- Security controls
This project should not be described as a replacement for a commercial antivirus or EDR solution.
Several assessment methods are heuristic or observational.
For example:
A .exe file is not automatically malicious.
A filename containing trojan or payload does not prove malicious behavior.
High entropy can occur in legitimate compressed or encrypted files.
Multiple devices can legitimately share a Vendor ID.
Missing manufacturer information does not establish that hardware is malicious.
The included demonstration model is trained on a very small dataset and should not be used as a production malware classifier.
YARA results depend on the quality and coverage of the installed rules.
Event availability depends on Windows configuration, audit policies, logging state, and operating-system version.
| Component | Technology |
|---|---|
| Language | C# |
| Runtime | .NET |
| Machine Learning | ML.NET |
| Malware Rules | YARA |
| USB Discovery | Windows Management Instrumentation |
| Device Management | Windows Plug and Play / PnPUtil |
| Process Analysis | Windows Management / PowerShell |
| Network Correlation | Windows TCP connection information |
| Event Analysis | Windows Event Log |
| Reporting | Text files |
| Logging | Local application logs |
| Interface | Windows Console |
The application follows a layered assessment approach.
Instead of relying on one indicator, it can combine multiple observations:
USB Device
│
├── Device Information
│
├── File Inventory
│ ├── File Type
│ ├── Filename
│ ├── Entropy
│ └── Size
│
├── Process Activity
│ └── Network Correlation
│
├── Windows Events
│
├── HID / BadUSB Assessment
│
└── ML.NET + YARA
│
▼
Security Assessment
│
▼
Findings / Report
The purpose is to provide multiple sources of evidence that can assist with security investigation.
Computer Security Latest Proprietary License Copyright © 2026 VALOR. All Rights Reserved.
This project is proprietary software and is not open source.
Use, copying, modification, redistribution, publication, sublicensing, commercial use, and creation of derivative works are prohibited unless explicitly authorized in writing by the copyright holder.
See the LICENSE file for the complete license terms.
If you would like to modify the source code, develop new features, create an extension, integrate this project into another application, or work on further development, please contact me first.
I am open to discussing authorized development, collaboration, feature development, and licensing opportunities.
Please obtain written permission before modifying, redistributing, publishing, or commercially using the source code.
🔒 This project is proprietary software and is not open source. Public access to the GitHub repository does not grant permission to modify or redistribute the source code.
Contributions are welcome.
Potential contribution areas include:
- Detection improvements
- Windows compatibility improvements
- USB device analysis
- Malware-analysis features
- YARA rule integration
- ML.NET model improvements
- Reporting
- Performance optimization
- Documentation
- Bug fixes
When contributing security-related detection logic, include information explaining:
- What is being detected
- Why the indicator is relevant
- Known false positives
- Windows versions tested
- How the feature was validated
This software is provided for defensive cybersecurity research, system administration, security assessment, and educational purposes.
Detection results are indicators and observations generated by the application. A Safe, Low, Medium, High, or Critical result does not constitute a definitive determination that a system or file is clean or malicious.
The authors are not responsible for data loss, system interruption, hardware disruption, or other consequences resulting from the use of this software.
Always verify security findings using additional trusted security controls before taking destructive or disruptive action.
Enhanced USB Threat Detection & Behavior Analysis Tool
A defensive Windows security utility combining:
USB Monitoring
+
File Threat Assessment
+
Process Analysis
+
Network Correlation
+
Windows Event Monitoring
+
BadUSB/HID Assessment
+
Device Control
+
ML.NET
+
YARA
+
Threat Reporting
Built with C# and .NET for Windows security assessment and research.