Hak5 Screen Crab Comprehensive Technical Manual
The Screen Crab is an essential tool in the Hak5 pentesting ecosystem, engineered for stealth, efficiency, and full operational reliability.
Table of Contents
- 1. Product Overview & Hardware Architecture
- 2. Configuration, Cloud C² & Operational Modes
- 3. Hardware Specifications, Safety & Troubleshooting
1. Product Overview & Hardware Architecture
Technical Specifications & Ground Truth Hardware Baseline
| Hardware Component | Official Specification Value |
|---|---|
| Video Interface | HDMI Passthrough (Input / Output up to 1080p @ 60 fps) |
| Wireless | 2.4 GHz 802.11 b/g/n for Out-of-Band Exfiltration |
| Storage | MicroSD Card Slot (FAT32 / exFAT up to 128 GB) |
| Power Interface | USB-C 5V DC Powered |
| Audio Capture | Inline HDMI PCM Audio Sniffing |
| Status Indicator | Multi-Color RGB Diagnostic LED |
1.1 The Screen Crab by Hak5
The Screen Crab by Hak5 is a stealthy video man-in-the-middle implant.
This covert inline screen grabber sits between HDMI devices - like a computer and monitor, or console and television - to quietly capture screenshots. Perfect for sysadmins, pentesters and anyone wanting to record what's on a screen.
WiFi enabled to stream screenshots via Hak5 Cloud C2.

[!WARNING] The e-book PDF generated by this document may not format correctly on all devices. For the most-to-date version, please see https://docs.hak5.org
1.2 Screen Crab Basics
Out of the box the Screen Crab will save screenshots at regular intervals to an inserted MicroSD card. Follow these steps for the most basic deployment to get started.
- Using two HDMI cables (not included) plug the Screen Crab inline between an input (e.g. a computer, chromecast, console, etc) and an output (e.g. monitor, television, projector).
- Insert a MicroSD card formatted in either FAT32 or ExFAT.
- Power the Screen Crab using a USB-C cable (not included) with a power adapter capable of providing 5 watts (5 Volts, 1 Amp).
After a brief 30-second boot time, the Screen Crab LED will light blue to indicate that the MicroSD card is being written to with screenshots. To stop recording and eject the MicroSD card - press the button, wait for the LED to light solid Green, then eject the card.

2. Configuration, Cloud C² & Operational Modes
2.1 Configuring the Screen Crab
By default the Screen Crab will save screenshots to a MicroSD card at regular intervals. With a blank MicroSD inserted, the Screen Crab will write a config.txt file to the root card.
DEFAULT CONFIGURATION:
LED ON
CAPTURE_MODE IMAGE
CAPTURE_INTERVAL 5
STORAGE FILL
BUTTON EJECT
CAPTURE CONFIGURATION:
LED [ON, OFF]
CAPTURE_MODE [IMAGE, VIDEO, OFF] (LED indication: Image=Blue, Video=Yellow, Off=Off)
DEDUPLICATE [ON, OFF] (Only for IMAGE CAPTURE_MODE)
CAPTURE_INTERVAL [N] (in N seconds)
STORAGE [ROTATE or FILL]
BUTTON [EJECT, OFF]
VIDEO_BITRATE [LOW, MEDIUM, HIGH]
(low 2Mbps, medium 4Mbps, high 16Mbps)
2.2 LED Status Indications

STARTUP STATUS
- LIGHT CYAN (SHORT)
- Device received power, starting boot
- BLINKING GREEN
- Waiting for capture to complete, ejecting SD card
[!CAUTION] Removing the MicroSD card before the LED lights solid green may damage the card's format.
- SOLID GREEN
- (After light cyan) Booting
- (After button push) SD is safe to eject
- SOLID RED
- SD card full or not detected
CONFIGURATION STATUS
- SOLID CYAN
- Wireless config unchanged on device/MicroSD
- BLINKING CYAN
- Updating device wireless to match MicroSD
config.txt - Updating device wireless state to match MicroSD config.txt
- Changing from wireless disabled -> wireless enabled
- Changing from wireless enabled -> wireless disabled
- Updating device wireless to match MicroSD
- SOLID MAGENTA
- Device button listening for capture override
- INVERSE BLINK MAGENTA
- Button pushed once during capture override mode at startup - config set to default image capture
- Button pushed twice during capture override mode at startup - config set to default video capture
CAPTURE STATUS:
-
SOLID BLUE
- Has video signal and capturing images to SD card
-
SOLID YELLOW
- Has video signal and capturing video to SD card
-
SOLID WHITE
- Has no video signal
UPGRADE STATUS:
- BLUE/RED POLICE PATTERN
- Screen Crab detected
upgrade.binon MicroSD card at boot - starting device upgrade
- Screen Crab detected
- BLUE/MAGENTA POLICE PATTERN
- Screen Crab starting framework upgrade
- FOREVER BLINKING RED - only during device upgrade (following police pattern)
- Software Upgrade Failed
[!CAUTION] Do not unplug power from the device or remove the MicroSD card during the upgrade process as doing so may render the device inoperable.
2.3 Configuring Cloud C²
[!CAUTION] April 2024: If your C2 server is configured with HTTPS, you will need to apply the SSL Update
Cloud C² Configuration
To get the most out of your Screen Crab, configure your device to connect to your Cloud C2 instance; This way you'll be able to to remotely view configure and manage the device - all through the web.
To configure your Screen Crab to connect to your Cloud C2 instance follow these simple steps:
- Download the
device.configfrom Cloud C2 - Copy the
device.configto the root of the MicroSD card - Configure
config.txton the MicroSD card for wireless
For the best performance using your Screen Crab connected to Cloud C2, use a config.txt that only contains the wireless options below
WiFi Configuration
The two WiFi parameters are:
WIFI_SSID– the network nameWIFI_PASS– the WPA-PSK password
Any characters after these variables will be used as the values. Special considerations must be made for WiFi network names and passwords containing special characters.
For example:
WIFI_SSID This is my network
WIFI_PASS The P@$$word is 1337!!
Should be escaped:
WIFI_SSID This is my network
WIFI_PASS The P\@\$\$word is 1337\!\!
[!CAUTION] To fully reset your Screen Crab's wireless configuration: remove the
WIFI_SSIDandWIFI_PASSparameters from yourconfig.txtand fully reboot your device before attempting to reconfigure.
2.4 2024 SSL Update
Let's Encrypt has been phasing out the X3 certificate chain. This change requires applying a one time update to your Screen Crab if you plan to use Cloud C2 with HTTPS.
This process from start to finish should only take a few minutes.
Download the update
The fix is a simple script available for download here: https://downloads.hak5.org/crab
[!CAUTION] This
autoexec.txtis meant only to be executed on your Screen Crab
Applying the update
- Power off the Screen Crab
- Eject the microSD card and attach to your host machine via card reader
- Copy the
autoexec.txtdownloaded from downloads.hak5.org to the root of the MicroSD card - Safely eject the MicroSD card from your host machine
- Insert the MicroSD card back into your Screen Crab
- Power the device on
- Done!
The script will automatically remove itself upon completion. If your Screen Crab is already registered to your Cloud C2 server, the device should now be online. Additionally anupgrade.logwill be created on the root of the MicroSD card to add an additional indication of success.
3. Hardware Specifications, Safety & Troubleshooting
3.1 Important Safety Information and Warnings
Your device may get hot to the touch; this is normal. Unplug the device and let it cool before removing it. This device complies with applicable surface temperature standards and limits defined by the International Standard for Safety (IEC 60950-1). Still, sustained contact with warm surfaces for long periods of time may cause discomfort or injury. Keep the device in a well-ventilated area when in use. Allow for adequate air circulation under and around the device. Do not expose the device to water or extreme conditions (moisture, heat, cold, dust), as the device may malfunction or cease to work when exposed to such elements. Do not attempt to disassemble or repair the device yourself. Doing so voids the limited warranty and could harm you or the device. This device is not designed, manufactured or intended for use in hazardous environments requiring fail-safe performance in which the failure of the device could lead directly to death, personal injury, or severe physical or environmental damage.
The Screen Crab is a network administration and pentesting tool for authorized auditing and security analysis purposes only where permitted subject local and international laws where applicable. Users are solely responsible for compliance with all laws of their locality. Hak5 LLC and affiliates claim no responsibility for unauthorized or unlawful use. © Hak5 LLC.
This device complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions: (1) this device may not cause harmful interference, and (2) this device must accept any interference received, including interference that may cause undesired operation. Warning (Part 15.21) Changes or modifications not expressly approved by the party responsible for compliance could void the user’s authority to operate the equipment. RF Exposure (OET Bulletin 65) To comply with FCC RF exposure requirements for mobile transmitting devices, this transmitter should only be used or installed at locations where there is at least 20cm separation distance between the antenna and all persons. Information to the User - Part 15.105 (b) Note: This equipment has been tested and found to comply with the limits for a Class B digital device, pursuant to part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference in a residential installation. This equipment generates, uses and can radiate radio frequency energy and, if not installed and used in accordance with the instructions, may cause harmful interference to radio communications. However, there is no guarantee that interference will not occur in a particular installation. If this equipment does cause harmful interference to radio or television reception, which can be determined by turning the equipment off and on, the user is encouraged to try to correct the interference by one or more of the following measures: * Reorient or relocate the receiving antenna. * Increase the separation between the equipment and receiver. * Connect the equipment into an outlet on a circuit different from that to which the receiver is connected. * Consult the dealer or an experienced radio/TV technician for help.
Screen Crab is a trademark of Hak5 LLC. This product is packaged with a limited warranty, the acceptance of which is a condition of sale. See Hak5.org for additional warranty details and limitations. Availability and performance of certain features, services and applications are device and network dependent and may not be available in all areas; additional terms, conditions and/or charges may apply. All features, functionality and other product specifications are subject to change without notice or obligation. Hak5 LLC reserves the right to make changes to the products description in this document without notice. Hak5 LLC does not assume any liability that may occur due to the use or application of the product(s) described herein. Made in China. Designed in San Francisco by Hak5 LLC, 548 Market Street, #39371, San Francisco, CA, 94104.
3.2 Hardware Specifications
INTERFACE: HDMI, USB, MICROSD
STANDARDS: HDMI 1.4/DVI 1.0, 802.11b/g/n
FREQUENCY RANGE: 2.412 ~ 2.4835 GHz
SIZE: 105 x 51 x 21 mm
POWER: 5W (USB 5V 1A)
OPERATING TEMPERATURE: 35ºC ~ 45ºC
STORAGE TEMPERATURE: -20ºC ~ 50ºC
RELATIVE HUMIDITY: 0% to 90% (noncondensing)
Supported WiFi: 2.4Ghz
Supported Resolutions: Most resolutions below 1920x1080 in 16:9 format;
3.3 Troubleshooting Guide
WiFi
[!CAUTION] Be sure to carefully read WiFi Configuration before continuing.
[!WARNING] The Screen Crab only supports dedicated 2.4Ghz APs. Access points with band steering enabled will not work.
Advanced WiFi Diagnostics
Please follow the below guide to generate a WiFi diagnostics file.
- Create a file named
autoexec.txton the root of the SD card containing:
source /system/bin/crab && do_gpio_setup && locate_sd && wifi_config > $SD_LOCATION/wifiinfo.txt && ping -c 5 8.8.8.8 >> $SD_LOCATION/wifiinfo.txt; ping -c 5 google.com >> $SD_LOCATION/wifiinfo.txt; disable_wifi && sleep 5 && enable_wifi; ping -c 5 8.8.8.8 >> $SD_LOCATION/wifiinfo.txt; ping -c 5 google.com >> $SD_LOCATION/wifiinfo.txt && cycle_colors
2. Insert the MircoSD card into the Screen Crab and apply power.
3. After boot and diagnostics, the LED colors will change rapidly.
4. Check if the device has connected to the WiFi network.
5. Press the button and safely eject the MicroSD card.
6. Check the MicroSD card for troubleshooting assistance in the newly created wifiinfo.txt file.
Wont Connect to Cloud C2
[!NOTE] If your Cloud C2 instance uses HTTPS, you will need to apply the SSL Update
If you have already confirmed your Screen Crab has a successful connection to the access point configured using the config.txt, be sure to confirm your Cloud C2 server configuration is valid and functional; See Cloud C2 setup for more information
Additionally confirm that the device.config used to register the Screen Crab is correct.
No Video Signal
Be sure to confirm the following:
- functional HDMI cables are fully seated in all ports
- fully functional USB-C cable, with appropriate power delivery
- target device uses a supported or down-scalable resolution. non-16:9 aspect ratios may not work. Non standard codecs may not work.