About this tool
Score the residual risk of a USB situation against the controls you actually have in place, and see which ones only feel safe.
The USB Drive Hygiene Checklist scores the residual risk of a USB situation against the controls you say you have in place. Pick a scenario — a drive you found, a conference giveaway, a client handover, your own personal drive, moving files across an air gap, a print-shop kiosk, or charging a phone from a strange port — and tick the controls you actually use. Each control only reduces the specific threats it targets, so the tool can separate real coverage from controls that merely feel protective, and it names the false comfort out loud when a habit you rely on does not touch the biggest risk in that scenario.
Open USB Drive Hygiene Checklist on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Firmware attacks, hostile files, data loss, deleted-file recovery, exfiltration and electrical damage are scored separately, because a drive that is safe from one is not automatically safe from the rest.
If a control you rely on does not touch the largest threat in your scenario — antivirus against a keyboard-emulating device, for instance — the tool says so instead of letting the overall score hide it.
The three controls that would remove the most residual risk for your exact scenario are ranked first, so effort goes where it changes the score the most.
It covers hostile files, but nothing else. Antivirus inspects the files on a volume; it has no visibility into the device's own firmware. A drive reprogrammed to act as a keyboard — the BadUSB class of attack shown by Karsten Nohl and Jakob Lell at Black Hat 2014 — can type commands the moment it is plugged in, before any scan runs.
No. A university study by Tischer and colleagues dropped 297 drives around a campus; 98% were picked up and files were opened on at least 45% of them. A dropped drive is a deliberate delivery method with a track record of working, so the only safe move is not connecting it.
Not reliably. NIST Special Publication 800-88 notes that overwriting flash media is unreliable because wear levelling and over-provisioning leave storage cells the write never reaches, and recommends cryptographic erase instead — which is why encrypting a drive from the first file you put on it is also the most dependable way to make its contents unrecoverable later.
Only if the connection cannot carry data. Modern phones ask before allowing a cable to exchange data, and declining that prompt is enough, but a charge-only cable or a small USB data blocker removes the question entirely and is cheap insurance for airports, hotels and shared charging stations.