ZeroTrace BLELogger
BLELogger vs. classic keyloggers
How BLELogger compares to inline PS/2 loggers, USB pass-through loggers, and software keyloggers
BLELogger straddles three product categories. This page maps the differences honestly.
Feature matrix
| Feature | Inline USB logger | Software keylogger | BLELogger |
|---|---|---|---|
| Hardware-level capture | Yes | No | Yes |
| Survives OS reinstall | Yes | No | Yes |
| Works on locked / signed-in machines | Yes | Depends on install access | Yes |
| BLE HID output | No | No | Yes |
| USB-to-wireless bridge | No | No | Yes |
| Auto-spoof source keyboard identity | No | N/A | Yes |
| Live remote view | Off-device flash | Network exfil | Web UI on AP |
| Layout calibration | Limited | OS-aware | Per-keyboard |
| Keyword / regex detection | No | Varies | Live |
| Trigger actions on match | No | Varies | Replace, key, media |
| Firmware updates | Vendor tooling | N/A | Browser Web Flasher |
Calibration is the differentiator
Inline USB loggers store raw scancodes. Reading them back later requires you to know which layout was on the host. Get it wrong and password! becomes password§ or worse.
BLELogger's Calibration workflow handshakes with the keyboard once: you type a guided sequence, the device builds a per-keyboard scancode-to-character map, every subsequent log entry is correct text the first time. AZERTY, QWERTZ, Dvorak, custom keymaps — all work.
Use cases
Test what an attacker could capture from the host's USB keyboard. The unit is fully visible, no install required, and produces structured logs you can attach to a report.
Where BLELogger isn't the answer
- Stealth at the cable layer — BLELogger is a visible device the size of a USB stick. It's not a hidden inline tap.
- Network keyloggers — wireless protocols other than BLE (e.g. Logitech Unifying RF) need a different tool.
- Mobile-only environments — BLELogger needs a USB-A keyboard. Phone keyboards aren't intercepted.
Hardware keylogging on systems you don't own is illegal in most jurisdictions. BLELogger is for authorized engagements and your own hardware. Keep authorization documentation.