Keyboard Security Lab is a Python-based cybersecurity research and learning project designed to demonstrate how keyboard-input monitoring can be analyzed from a defensive security perspective.
Instead of implementing a covert or system-wide keylogger, this project provides a controlled testing environment where keyboard events are captured only inside the application's dedicated test area. The collected events can then be analyzed, simulated, monitored, exported, and included in security reports.
The project is intended for cybersecurity education, Python development practice, security analysis, and detection engineering.
The main objectives of this project are to:
- Understand keyboard-event collection in a controlled environment
- Analyze keyboard-event patterns
- Detect unusual event activity
- Simulate high-volume keyboard activity
- Monitor running processes
- Perform SHA-256 file integrity checks
- Export security-event data
- Generate security analysis reports
- Understand the security implications of keylogging
- Demonstrate defensive security concepts related to MITRE ATT&CK T1056.001 β Input Capture: Keylogging
The project provides a desktop-based security laboratory built with Python and Tkinter.
The application includes:
- Controlled keyboard-event testing
- Real-time event logging
- Event statistics
- Security analysis
- Risk-level assessment
- Normal event simulation
- High-volume event simulation
- Running-process inspection
- File-integrity monitoring
- JSON and CSV data export
- Automated security reports
- MITRE ATT&CK reference
Keyboard events are captured only from the application's dedicated test input area.
The application does not implement a hidden system-wide keyboard hook.
Captured information includes:
- Timestamp
- Key
- Event type
Example:
2026-09-24 15:30:12 | a | character
2026-09-24 15:30:13 | Enter | special
The analysis module provides statistics about the captured events.
It can calculate:
- Total events
- Character events
- Special-key events
- Events per minute
- Most frequently used keys
The detection engine analyzes controlled test activity and generates security findings when predefined thresholds are exceeded.
Example detection:
MEDIUM
High Event Volume
The controlled test session generated a high number
of keyboard events.
The application also calculates an overall risk level:
NORMAL
LOW
MEDIUM
HIGH
The project includes a safe event simulator for security testing.
Two simulation modes are available:
Generates a normal-sized set of keyboard events.
Generates a large number of synthetic events to demonstrate how the detection engine responds to abnormal event volume.
This allows the detection system to be tested without requiring actual suspicious activity.
The process-monitoring module uses psutil to inspect currently running processes.
It can display:
- Process ID
- Process name
- Process status
This provides a foundation for learning how security tools can inspect the runtime environment.
The project includes SHA-256 file hashing functionality.
The integrity module can calculate cryptographic hashes for selected files.
This can be used to demonstrate the basic concept of:
File β SHA-256 Hash β Compare β Detect Modification
File integrity monitoring is a common defensive security technique for detecting unexpected changes to important files.
Security-event data can be exported into:
- JSON
- CSV
Example:
data/
βββ events.json
βββ events.csv
This makes the generated data easier to analyze using other tools.
The application can automatically generate security reports containing:
- Session statistics
- Event frequency
- Security findings
- Risk level
- MITRE ATT&CK reference
Reports are stored locally in:
reports/
Keyboard-Security-Lab/
β
βββ app/
β βββ __init__.py
β βββ main.py
β β
β βββ collectors/
β β βββ __init__.py
β β βββ keyboard_events.py
β β
β βββ analysis/
β β βββ __init__.py
β β βββ analyzer.py
β β
β βββ detection/
β β βββ __init__.py
β β βββ detector.py
β β
β βββ monitoring/
β β βββ __init__.py
β β βββ process_monitor.py
β β βββ integrity.py
β β
β βββ reporting/
β β βββ __init__.py
β β βββ report.py
β β
β βββ utils/
β βββ __init__.py
β βββ storage.py
β
βββ simulator/
β βββ __init__.py
β βββ simulator.py
β
βββ data/
βββ logs/
βββ reports/
β
βββ requirements.txt
βββ README.md
βββ .gitignore
| Technology | Purpose |
|---|---|
| Python | Core programming language |
| Tkinter | Desktop GUI |
| psutil | Process monitoring |
| hashlib | SHA-256 file integrity |
| JSON | Event-data storage |
| CSV | Event-data export |
| pathlib | File and directory management |
| datetime | Timestamp management |
| Git | Version control |
| GitHub | Source-code hosting |
git clone https://github.com/girishm03/Basic-Keylogger.gitcd Basic-KeyloggerWindows:
python -m venv venv.\venv\Scripts\Activate.ps1pip install -r requirements.txtRun the application from the project root directory:
python -m app.mainDo not run:
python app\main.pybecause the project uses Python packages and package-qualified imports.
Run:
python -m app.mainClick:
Start Test
Type text inside the application's dedicated test input area.
The application records the keyboard events generated inside this controlled environment.
Click:
Stop Test
Click:
Analyze
The application calculates event statistics and checks for predefined security conditions.
Use:
Normal Simulation
or:
High Volume Simulation
to generate synthetic events.
Click:
Process Scan
to inspect currently running processes.
Click:
Integrity Scan
to calculate SHA-256 hashes for selected project files.
Click:
Save Data
to generate JSON and CSV event files.
Click:
Generate Report
to create a security analysis report.
This project is intentionally designed as a controlled cybersecurity laboratory.
It does not implement:
- β Hidden keyboard monitoring
- β System-wide covert key capture
- β Credential harvesting
- β Password extraction
- β Remote key transmission
- β Data exfiltration
- β Persistence mechanisms
- β Startup execution
- β Antivirus/security-tool evasion
- β Stealth functionality
Keyboard events are collected only from the application's dedicated testing interface.
The purpose of the project is to understand security monitoring, detection, analysis, and defensive techniques.
This project references:
MITRE ATT&CK classifies keylogging under Input Capture.
In this project, the technique is discussed strictly from a security education and detection-analysis perspective.
The implementation itself is intentionally restricted to controlled application-level testing.
This project demonstrates several important cybersecurity concepts:
Input Capture
β
Event Collection
β
Event Analysis
β
Anomaly Detection
β
Risk Assessment
β
Security Reporting
Additional defensive concepts include:
Process Monitoring
File Integrity Monitoring
SHA-256 Hashing
Security Event Logging
Synthetic Event Generation
Detection Engineering
Potential future versions may include:
- π Interactive security dashboards
- π Event-frequency graphs
- π§ More advanced anomaly detection
- π Suspicious process correlation
- π‘οΈ Rule-based detection engine
- π Improved security reports
- ποΈ SQLite event database
- π Streamlit web dashboard
- π Historical event analysis
- π Real-time security alerts
- π§ͺ Additional synthetic attack scenarios
- π Configurable detection thresholds
Through this project, you can practice:
- Python application development
- Object-oriented programming
- Tkinter GUI development
- Event-driven programming
- Security event logging
- Data analysis
- File handling
- JSON/CSV processing
- Process monitoring
- Cryptographic hashing
- Detection engineering
- Security reporting
- Modular project architecture
- Git and GitHub workflow
The project can produce files such as:
data/
βββ events.json
βββ events.csv
reports/
βββ security_report_20260924_153000.txt
A generated report contains information such as:
KEYBOARD SECURITY LAB
Detection & Analysis Report
SESSION STATISTICS
------------------------------
Total events: 600
Character events: 600
Special events: 0
Events/minute: 1200
Risk level: MEDIUM
SECURITY FINDINGS
------------------------------
[MEDIUM] High Event Volume
The controlled test session generated a high number
of keyboard events.
Girish M
Python Developer | Cybersecurity Researcher
- GitHub: https://github.com/girishm03
- LinkedIn: https://www.linkedin.com/in/girish-m-0b626727b
- Portfolio: https://girishm-portfolio.vercel.app/
If you find this project useful for learning Python or cybersecurity concepts, consider giving the repository a β on GitHub.
This project is intended for educational, defensive-security, and authorized testing purposes only.
Use security-monitoring techniques only on systems, applications, and data that you own or have explicit permission to test.
The project intentionally avoids covert surveillance, credential collection, persistence, and unauthorized data collection.