Skip to content

About

A Python-based defensive cybersecurity lab for controlled keyboard-event analysis, anomaly detection, process monitoring, file-integrity checking, and security reporting.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

Β 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ” Keyboard Security Lab

Detection & Analysis Platform for Keyboard Input Security

Keyboard Security Lab is a Python-based cybersecurity research and learning project designed to demonstrate how keyboard-input monitoring can be analyzed from a defensive security perspective.

Instead of implementing a covert or system-wide keylogger, this project provides a controlled testing environment where keyboard events are captured only inside the application's dedicated test area. The collected events can then be analyzed, simulated, monitored, exported, and included in security reports.

The project is intended for cybersecurity education, Python development practice, security analysis, and detection engineering.


🎯 Project Objectives

The main objectives of this project are to:

  • Understand keyboard-event collection in a controlled environment
  • Analyze keyboard-event patterns
  • Detect unusual event activity
  • Simulate high-volume keyboard activity
  • Monitor running processes
  • Perform SHA-256 file integrity checks
  • Export security-event data
  • Generate security analysis reports
  • Understand the security implications of keylogging
  • Demonstrate defensive security concepts related to MITRE ATT&CK T1056.001 – Input Capture: Keylogging

πŸ–₯️ Application Overview

The project provides a desktop-based security laboratory built with Python and Tkinter.

The application includes:

  • Controlled keyboard-event testing
  • Real-time event logging
  • Event statistics
  • Security analysis
  • Risk-level assessment
  • Normal event simulation
  • High-volume event simulation
  • Running-process inspection
  • File-integrity monitoring
  • JSON and CSV data export
  • Automated security reports
  • MITRE ATT&CK reference

✨ Features

⌨️ Controlled Keyboard Event Capture

Keyboard events are captured only from the application's dedicated test input area.

The application does not implement a hidden system-wide keyboard hook.

Captured information includes:

  • Timestamp
  • Key
  • Event type

Example:

2026-09-24 15:30:12 | a | character
2026-09-24 15:30:13 | Enter | special

πŸ“Š Event Analysis

The analysis module provides statistics about the captured events.

It can calculate:

  • Total events
  • Character events
  • Special-key events
  • Events per minute
  • Most frequently used keys

🚨 Security Detection

The detection engine analyzes controlled test activity and generates security findings when predefined thresholds are exceeded.

Example detection:

MEDIUM
High Event Volume

The controlled test session generated a high number
of keyboard events.

The application also calculates an overall risk level:

NORMAL
LOW
MEDIUM
HIGH

πŸ§ͺ Event Simulation

The project includes a safe event simulator for security testing.

Two simulation modes are available:

Normal Simulation

Generates a normal-sized set of keyboard events.

High-Volume Simulation

Generates a large number of synthetic events to demonstrate how the detection engine responds to abnormal event volume.

This allows the detection system to be tested without requiring actual suspicious activity.


πŸ–₯️ Process Monitoring

The process-monitoring module uses psutil to inspect currently running processes.

It can display:

  • Process ID
  • Process name
  • Process status

This provides a foundation for learning how security tools can inspect the runtime environment.


πŸ”’ File Integrity Monitoring

The project includes SHA-256 file hashing functionality.

The integrity module can calculate cryptographic hashes for selected files.

This can be used to demonstrate the basic concept of:

File β†’ SHA-256 Hash β†’ Compare β†’ Detect Modification

File integrity monitoring is a common defensive security technique for detecting unexpected changes to important files.


πŸ’Ύ Data Export

Security-event data can be exported into:

  • JSON
  • CSV

Example:

data/
β”œβ”€β”€ events.json
└── events.csv

This makes the generated data easier to analyze using other tools.


πŸ“„ Security Reports

The application can automatically generate security reports containing:

  • Session statistics
  • Event frequency
  • Security findings
  • Risk level
  • MITRE ATT&CK reference

Reports are stored locally in:

reports/

🧩 Project Architecture

Keyboard-Security-Lab/
β”‚
β”œβ”€β”€ app/
β”‚   β”œβ”€β”€ __init__.py
β”‚   β”œβ”€β”€ main.py
β”‚   β”‚
β”‚   β”œβ”€β”€ collectors/
β”‚   β”‚   β”œβ”€β”€ __init__.py
β”‚   β”‚   └── keyboard_events.py
β”‚   β”‚
β”‚   β”œβ”€β”€ analysis/
β”‚   β”‚   β”œβ”€β”€ __init__.py
β”‚   β”‚   └── analyzer.py
β”‚   β”‚
β”‚   β”œβ”€β”€ detection/
β”‚   β”‚   β”œβ”€β”€ __init__.py
β”‚   β”‚   └── detector.py
β”‚   β”‚
β”‚   β”œβ”€β”€ monitoring/
β”‚   β”‚   β”œβ”€β”€ __init__.py
β”‚   β”‚   β”œβ”€β”€ process_monitor.py
β”‚   β”‚   └── integrity.py
β”‚   β”‚
β”‚   β”œβ”€β”€ reporting/
β”‚   β”‚   β”œβ”€β”€ __init__.py
β”‚   β”‚   └── report.py
β”‚   β”‚
β”‚   └── utils/
β”‚       β”œβ”€β”€ __init__.py
β”‚       └── storage.py
β”‚
β”œβ”€β”€ simulator/
β”‚   β”œβ”€β”€ __init__.py
β”‚   └── simulator.py
β”‚
β”œβ”€β”€ data/
β”œβ”€β”€ logs/
β”œβ”€β”€ reports/
β”‚
β”œβ”€β”€ requirements.txt
β”œβ”€β”€ README.md
└── .gitignore

πŸ› οΈ Technologies Used

Technology Purpose
Python Core programming language
Tkinter Desktop GUI
psutil Process monitoring
hashlib SHA-256 file integrity
JSON Event-data storage
CSV Event-data export
pathlib File and directory management
datetime Timestamp management
Git Version control
GitHub Source-code hosting

πŸ“¦ Installation

1. Clone the repository

git clone https://github.com/girishm03/Basic-Keylogger.git

2. Enter the project directory

cd Basic-Keylogger

3. Create a virtual environment

Windows:

python -m venv venv

4. Activate the virtual environment

.\venv\Scripts\Activate.ps1

5. Install dependencies

pip install -r requirements.txt

▢️ Running the Application

Run the application from the project root directory:

python -m app.main

Do not run:

python app\main.py

because the project uses Python packages and package-qualified imports.


πŸ§ͺ How to Use

Step 1 β€” Start the application

Run:

python -m app.main

Step 2 β€” Start a Test

Click:

Start Test

Step 3 β€” Enter Test Data

Type text inside the application's dedicated test input area.

The application records the keyboard events generated inside this controlled environment.

Step 4 β€” Stop the Test

Click:

Stop Test

Step 5 β€” Analyze Events

Click:

Analyze

The application calculates event statistics and checks for predefined security conditions.

Step 6 β€” Test Detection

Use:

Normal Simulation

or:

High Volume Simulation

to generate synthetic events.

Step 7 β€” Scan Processes

Click:

Process Scan

to inspect currently running processes.

Step 8 β€” Check File Integrity

Click:

Integrity Scan

to calculate SHA-256 hashes for selected project files.

Step 9 β€” Export Data

Click:

Save Data

to generate JSON and CSV event files.

Step 10 β€” Generate Report

Click:

Generate Report

to create a security analysis report.


πŸ” Security & Ethical Design

This project is intentionally designed as a controlled cybersecurity laboratory.

It does not implement:

  • ❌ Hidden keyboard monitoring
  • ❌ System-wide covert key capture
  • ❌ Credential harvesting
  • ❌ Password extraction
  • ❌ Remote key transmission
  • ❌ Data exfiltration
  • ❌ Persistence mechanisms
  • ❌ Startup execution
  • ❌ Antivirus/security-tool evasion
  • ❌ Stealth functionality

Keyboard events are collected only from the application's dedicated testing interface.

The purpose of the project is to understand security monitoring, detection, analysis, and defensive techniques.


πŸ›‘οΈ MITRE ATT&CK Reference

This project references:

T1056.001 β€” Input Capture: Keylogging

MITRE ATT&CK classifies keylogging under Input Capture.

In this project, the technique is discussed strictly from a security education and detection-analysis perspective.

The implementation itself is intentionally restricted to controlled application-level testing.


πŸ” Security Concepts Demonstrated

This project demonstrates several important cybersecurity concepts:

Input Capture
      ↓
Event Collection
      ↓
Event Analysis
      ↓
Anomaly Detection
      ↓
Risk Assessment
      ↓
Security Reporting

Additional defensive concepts include:

Process Monitoring
File Integrity Monitoring
SHA-256 Hashing
Security Event Logging
Synthetic Event Generation
Detection Engineering

πŸ“ˆ Future Improvements

Potential future versions may include:

  • πŸ“Š Interactive security dashboards
  • πŸ“ˆ Event-frequency graphs
  • 🧠 More advanced anomaly detection
  • πŸ”Ž Suspicious process correlation
  • πŸ›‘οΈ Rule-based detection engine
  • πŸ“‹ Improved security reports
  • πŸ—ƒοΈ SQLite event database
  • 🌐 Streamlit web dashboard
  • πŸ“Š Historical event analysis
  • πŸ”” Real-time security alerts
  • πŸ§ͺ Additional synthetic attack scenarios
  • πŸ” Configurable detection thresholds

πŸŽ“ Learning Outcomes

Through this project, you can practice:

  • Python application development
  • Object-oriented programming
  • Tkinter GUI development
  • Event-driven programming
  • Security event logging
  • Data analysis
  • File handling
  • JSON/CSV processing
  • Process monitoring
  • Cryptographic hashing
  • Detection engineering
  • Security reporting
  • Modular project architecture
  • Git and GitHub workflow

πŸ“‚ Example Output

The project can produce files such as:

data/
β”œβ”€β”€ events.json
└── events.csv

reports/
└── security_report_20260924_153000.txt

A generated report contains information such as:

KEYBOARD SECURITY LAB
Detection & Analysis Report

SESSION STATISTICS
------------------------------
Total events: 600
Character events: 600
Special events: 0
Events/minute: 1200

Risk level: MEDIUM

SECURITY FINDINGS
------------------------------
[MEDIUM] High Event Volume
The controlled test session generated a high number
of keyboard events.

πŸ‘¨β€πŸ’» Author

Girish M

Python Developer | Cybersecurity Researcher

Connect with me


⭐ Support

If you find this project useful for learning Python or cybersecurity concepts, consider giving the repository a ⭐ on GitHub.


⚠️ Disclaimer

This project is intended for educational, defensive-security, and authorized testing purposes only.

Use security-monitoring techniques only on systems, applications, and data that you own or have explicit permission to test.

The project intentionally avoids covert surveillance, credential collection, persistence, and unauthorized data collection.

About

A Python-based defensive cybersecurity lab for controlled keyboard-event analysis, anomaly detection, process monitoring, file-integrity checking, and security reporting.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages