ICMP - Timing-Based Exfiltration

ICMP - Timing-Based Exfiltration
Download Copy
Title: ICMP - Timing-Based Exfiltration
Author: TW-D

This payload does covert timing-channel data exfiltration by running a local command, encoding each character’s ASCII value as a delay between network probes, and letting a receiver reconstruct the output from the probes’ timestamps.

🏆   Recognized with a Payload Award in September 2025

 

Exfiltration is an involuntary backup. It's a technique for obtaining data from a network. Once obtained, the data may be removed using a number of methods. These may include traversing the network to a command and control server, such as Cloud C². The content is typically encrypted or obfuscated. In the case of physical access, a bring-your-own-network element may be included to evade detection. See all exfiltration payloads.

This payload is for the USB Rubber Ducky — a "flash drive" that types keystroke injection payloads into unsuspecting computers at incredible speeds. It's no wonder this little quacker has made appearances on Mr. Robot, FBI, Blacklist, National Geography and more!

Submit your own payload, or browse more featured USB Rubber Ducky Payloads.

 

 

Related Payloads

Passpoint Scanner
Passpoint Scanner
Scanner for true Passpoint/Hotspot 2.0 networks. Detects Passpoint APs via IE 221 (HS2.0 Vendor Specific OUI 50:6f:9a:10
Read More
Nautilus
Nautilus
Web-based payload launcher with GitHub integration. Control your Pager from any device on the network. Run payloads dire
Read More
PlunderPIN
PlunderPIN
PlunderPIN is a mobile PIN phishing payload that replaces a user's Google Chrome browser homepage with a malicious imita
Read More