Hak5 Plunder Bug Comprehensive Technical Manual
The Plunder Bug is an essential tool in the Hak5 pentesting ecosystem, engineered for stealth, efficiency, and full operational reliability.
Table of Contents
- 1. Product Overview & Hardware Architecture
- 2. Hardware Setup, Connectivity & Drivers
- 3. Active and Passive Operating Modes & Cross-Platform Switching
- 4. Advanced Network Usage, Packet Capture & Maintenance
1. Product Overview & Hardware Architecture
This chapter details the 1. product overview & hardware architecture specifications, procedures, and operational methodologies for the Plunder Bug.
Technical Specifications & Ground Truth Hardware Baseline
| Hardware Component | Official Specification Value |
|---|---|
| Architecture | Pocket-Sized Passive/Active USB LAN Tap |
| Ethernet Interfaces | Dual 10/100 Fast Ethernet Ports (Inline Tap RJ-45) |
| Tap Output Interface | 1x USB Type-C High-Speed Port |
| Power Requirements | 5V DC via USB Type-C Connection (< 250mA Draw) |
| Operating Modes | Passive Tap Mode, Active Emulated NIC Mode, Simple Switch Mode |
| Chipset | High-Performance Low-Power ASIX / Realtek Ethernet Controller |
| Cross-Platform Compatibility | Linux (Native), macOS (Native/Driver), Windows (ASIX Driver), Android |
1.1 Plunder Bug by Hak5
The Plunder Bug by Hak5 is pocket-sized LAN Tap that lets you "bug" Ethernet connections with USB-C convenience.

[!WARNING] The e-book PDF generated by this document may not format correctly on all devices. For the most-to-date version, please see https://docs.hak5.org
2. Hardware Setup, Connectivity & Drivers
This chapter details the 2. hardware setup, connectivity & drivers specifications, procedures, and operational methodologies for the Plunder Bug.
2.1 Tapping an Ethernet link
Getting Started
The Plunder Bug by Hak5 is pocket-sized LAN Tap that lets you "bug" Ethernet connections with USB-C convenience.
Using a USB-C cable, connect the Plunder Bug to a computer running a network analyzer such as Wireshark. The light on the Plunder Bug will illuminate green to indicate that it is powered, and you will notice on the computer a new network interface (ASIX AX88772C USB Ethernet).
You will most likely wish to switch the Plunder Bug into passive mode, which mutes the tap port, preventing the host computer from transmitting anything downstream on the tap port. See instructions for your operating system here.
Using two Ethernet cables, plug the Plunder Bug inline between any two devices, such as a PC and a LAN switch. Packets between the two ports will be mirrored on the USB-C tap port, which may be viewed using common open source packet analyzers such as Wireshark or tcpdump.

2.2 Drivers
While most systems will automatically recognize and install drivers for the Plunder Bug's USB Ethernet interface (ASIX AX88772C chipset), some Windows and Mac systems may not.
To manually download and install the driver, please visit the ASIX driver download page for the AX88772C.
3. Active and Passive Operating Modes & Cross-Platform Switching
This chapter details the 3. active and passive operating modes & cross-platform switching specifications, procedures, and operational methodologies for the Plunder Bug.
3.1 About Mode Switching
By default the Plunder Bug's USB-C tap port will act in an active, bidirectional manner. This means that in addition to receiving a mirror of the traffic flowing between the two RJ45 Ethernet ports, it will also act as an additional Ethernet port on the target LAN.
This is useful for simultaneously performing active network scans (such as with nmap) while passively sniffing packets. To switch between passive (muted) and the default active (unmuted) modes, use the Plunder Bug mute script specific to your operating system.
3.2 Windows Mode Switching
Using plunderbug.ps1
Download the plunderbug.ps1 PowerShell script for modern Windows platforms from the Hak5 Download Center.
Open PowerShell bypassing the default execution policy so that the script may run. For example, from the Run dialog (WIN+R) enter powershell -exec bypass

Change to the directory of the downloaded plunderbug.ps1 script and execute with the mute or unmute parameter (eg: .\plunderbug.ps1 mute)

If necessary, allow User Access Control to run the script as an administrator.

The script will execute muting or unmuting the port as directed. Press Enter to close the command prompt. The setting will stay in effect until the script is run again with the opposite directive.

Manually
If preferred, the Plunder Bug can be muted or unmuted by opening Network Connections (Start > Run > ncpa.cpl > [ENTER])

Then right-click the Plunder Bug interface and select Properties

Uncheck the boxes next to each of the protocols and click OK.

3.3 MacOS Mode Switching
USING PLUNDERBUG.SH
Download the plunderbug.sh script for *nix platforms from the Hak5 Download Center.
Open a terminal, change to the directory of the downloaded plunderbug.sh script, make it executable (chmod +x ./plunderbug.sh) and run it as root.
plunderbug.sh accepts the arguments --mute and --unmute to switch between active and passive modes

MANUALLY
If preferred, the Plunder Bug can be muted and unmuted by opening Network from System Preferences. Click Advanced, then select "Off" from the Configure IPv4 and IPv6 menus, then click OK and Apply.

3.4 Linux Mode Switching
USING PLUNDERBUG.SH
Download the plunderbug.sh script for *nix platforms from the Hak5 Download Center.
Open a terminal, change to the directory of the downloaded plunderbug.sh script, make it executable (chmod +x ./plunderbug.sh) and run it as root.
plunderbug.sh accepts the arguments --mute and --unmute to switch between active and passive modes

MANUALLY
If preferred, the Plunder Bug can be muted and unmuted by opening Network Manager, clicking the configure gear icon next to the Plunder Bug interface, then selecting the disable option from the IPv4 and IPv6 tabs and clicking Apply.

4. Advanced Network Usage, Packet Capture & Maintenance
This chapter details the 4. advanced network usage, packet capture & maintenance specifications, procedures, and operational methodologies for the Plunder Bug.
4.1 Using as a Simple Switch
In a way, the Plunder Bug can be used as a simple switch. In the following example, the Plunder Bug is used to provide the laptop (via USB-C) and the Shark Jack (or any ordinary Ethernet device) network access via the WAN/Uplink port (closest to the Plunder Bug's status LED).
