Skip to main content
ExplainerWorkplace SurveillanceEnterprise Security· 7 min read· in Careers & Work

How IT Departments Detect Mouse Jigglers Using Windows APIs and USB Logs

While mouse jigglers are frequently marketed as undetectable, enterprise monitoring tools use operating system flags and hardware enumeration to identify them. Understanding the technical footprint of synthetic input reveals why automated activity is rarely invisible to IT.

By Isabella Vega

In short

  • Windows permanently tags software-generated cursor movement with the LLMHF_INJECTED flag, making software jigglers instantly visible to endpoint monitoring tools.
  • Hardware USB dongles bypass software flags but trigger permanent USB enumeration logs that alert IT administrators to unauthorized peripheral connections.
  • Mechanical movers evade input-layer detection but are caught by behavioral analytics that flag continuous cursor movement lacking clicks or keyboard activity.

When remote work surged in 2020, the market for devices that keep a computer awake exploded overnight. Employees seeking to maintain an active status on platforms like Microsoft Teams or Slack turned to mouse jigglers, a category of tools designed to simulate constant user input and prevent screens from locking.

Today, Amazon lists more than a hundred of these devices, often retailing for under $20, with many explicitly marketed to consumers as entirely undetectable. However, that bold marketing claim relies on a fundamental misunderstanding of how modern operating systems process, tag, and log peripheral input.[2]

According to 2026 data published by Kickidler, approximately 16 percent of employees intentionally use mouse jigglers or similar automation tools to circumvent corporate inactivity tracking. This widespread adoption has prompted enterprise IT departments to deploy increasingly sophisticated countermeasures to ensure their productivity data reflects genuine human work.

The reality is that no mouse jiggler is truly invisible to a properly managed corporate machine. The detection mechanism simply shifts depending on the specific type of tool being used, moving fluidly from software API flags to hardware connection logs, or ultimately to advanced behavioral correlation.

Understanding exactly how these detection layers function requires looking far past the green status dot on a chat application. It demands a technical examination of the Windows kernel, the Universal Serial Bus standard, and the behavioral analytics engines powering modern workforce monitoring software.

How enterprise monitoring tools detect different categories of simulated input.

The Software Layer and Windows APIs

The most accessible jigglers are software applications or simple scripts that run silently in the background of a workstation. Because they do not require the purchase of physical hardware, users often assume they leave no trace beyond the cursor movement itself, making them seem perfectly stealthy.

This assumption fails immediately at the operating system level, where input provenance is strictly tracked. When a Windows application wants to move the cursor, it must call a documented Application Programming Interface, typically utilizing the SendInput or mouse_event function to generate the synthetic action.[1]

The Windows kernel intercepts this synthetic command and inserts it directly into the system's input stream alongside genuine hardware signals. Crucially, the operating system permanently tags this event to distinguish it from a physical mouse movement, ensuring the source of the input remains transparent to the system.[1]

Microsoft's official documentation for the MSLLHOOKSTRUCT structure is unambiguous about this tagging process. Any monitoring software equipped with a low-level mouse hook can read the flags member of this specific structure to instantly determine the exact origin of the input event.[1]

Testing for the LLMHF_INJECTED flag, which occupies bit 0 and carries a value of 0x00000001, tells the system definitively whether the event was injected by software. If this specific bit is set, the movement absolutely did not come from a physical piece of hardware on the desk.[1]

Furthermore, testing bit 1, known technically as LLMHF_LOWER_IL_INJECTED, reveals whether the event was injected from a process running at a lower integrity level. Because user-space programs cannot suppress these kernel-level flags, software jigglers are trivial for endpoint agents to detect and log.[1]

The Windows kernel permanently tags synthetic cursor movement using the LLMHF_INJECTED flag.

Hardware Dongles and USB Enumeration

To completely bypass the LLMHF_INJECTED software flag, many remote workers turn to hardware USB jigglers. These small, inexpensive dongles plug directly into a computer's port and utilize microcontrollers, such as the ATtiny85, to send fake movement signals directly to the motherboard.[3]

Because they operate entirely outside the software layer, they present themselves to the operating system as a standard Human Interface Device. The OS accepts the input as genuine hardware motion, leaving the injected flag completely untriggered and bypassing software-only detection methods.[3]

However, hardware jigglers create a different, highly visible footprint that IT departments can easily track: the USB enumeration event. The exact moment a dongle is connected, the computer records that a brand new peripheral has joined the system, creating a permanent digital receipt.[2]

This physical connection generates a persistent registry record and a Plug and Play event in security tools like Microsoft Defender for Endpoint. The device proudly announces its Vendor ID and Product ID, which often stand out glaringly against a strictly managed corporate asset inventory.

Hardware security vendors like Sepio specialize in identifying these unauthorized devices before they can cause harm. Because they monitor the hardware layer directly, they can instantly flag a generic or unknown USB mouse appearing alongside the employee's primary, company-issued pointing device.[3]

In a modern Zero Trust enterprise environment, IT administrators receive automated alerts whenever unapproved peripherals connect to a managed laptop. The physical dongle successfully bypasses the software flag only to trigger a much louder hardware security alarm at the network level.[3]

Illustration: Connecting an unauthorized USB device creates a permanent registry record on a managed corporate machine.

Mechanical Movers and Behavioral Analytics

The third category of jiggler attempts to bypass both the software flags and the USB enumeration logs entirely. Mechanical movers are physical platforms that cradle a real mouse, using a motorized spinning disc to physically move the optical sensor back and forth.[2]

Because the input comes directly from the employee's actual, approved mouse, there is no injected software flag and absolutely no suspicious USB enumeration event. At the raw input layer, the activity is entirely indistinguishable from genuine human work, making it the hardest to catch technically.[2]

To catch mechanical movers, enterprise monitoring tools must shift their focus from the input layer to advanced behavioral correlation. Platforms like ActivTrak, Teramind, and CurrentWare analyze the broader context of the cursor's movement to determine if a human is actually driving the machine.

A mechanical jiggler produces continuous activity without any corresponding productive output. The cursor moves steadily for hours, but the active window never changes, no application receives a targeted click, and the keyboard remains completely silent throughout the entire duration of the movement.[2]

Furthermore, the movement pattern itself is highly mechanical and mathematically predictable. A jiggler typically moves the pointer a few pixels on a fixed, repeating timer, whereas a human moves the cursor by hundreds of pixels at uneven, goal-directed intervals to click specific targets.

A simple 30-line Python script can easily flag pointer moves of four pixels or less that repeat on a steady, unvarying timer. When periodic screenshots show the exact same screen state for hours despite continuous mouse movement, the behavioral signature of a mechanical mover becomes undeniable.

Behavioral analytics flag continuous cursor movement that lacks corresponding keyboard input or application clicks.

Security Risks and the Productivity Debate

For enterprise IT departments, the concern over mouse jigglers extends far beyond inflated productivity metrics and idle time. Unauthorized USB devices represent a genuine security vulnerability, as malicious payloads can easily be disguised as harmless mouse movers to bypass perimeter defenses.[3]

Security platforms view any unvetted hardware connection as a potential vector for data breaches or unauthorized network access. When a workstation remains unlocked and unattended because a jiggler is keeping it awake, it actively bypasses essential inactivity-based security controls designed to protect sensitive data.[3]

The corporate response to simulated activity has been severe and highly publicized in recent years. In 2024, Wells Fargo dismissed more than a dozen employees after an internal review uncovered the widespread use of simulated keyboard and mouse activity to fake active working hours.[2]

Yet, the proliferation of these devices highlights a much deeper flaw in how some organizations measure modern knowledge work. When employers rely heavily on idle timers and green status dots rather than actual output, they inadvertently incentivize employees to optimize for the surveillance metric.[2]

Approximately 16 percent of employees utilize automation tools to bypass corporate inactivity tracking.

The technical arms race between mouse jigglers and endpoint monitoring software is a symptom of misaligned management philosophies. When companies shift their focus to measuring tangible deliverables and actual business impact, the need to fake a moving cursor disappears entirely.[4]

How we did this

Method
Cross-referencing Windows operating system API documentation with hardware security vendor specifications to map the exact detection layer for each category of simulated input.
What we found
Every category of mouse jiggler leaves a definitive technical footprint; the detection mechanism simply shifts from the software API layer to the USB hardware layer or behavioral correlation, rendering the 'undetectable' marketing claim technically false across all device types.
What we worked from
  • Windows MSLLHOOKSTRUCT API behavior: LLMHF_INJECTED flag (bit 0) — Microsoft
  • Hardware HID enumeration logs: USB device connection events — Sepio
Limits of this analysis
This analysis relies on what operating systems and monitoring tools are capable of logging, which does not guarantee that a specific employer is actively reviewing those logs.

Jargon, explained

LLMHF_INJECTED
A specific flag set by the Windows operating system to permanently mark mouse input that was generated by software rather than physical hardware.
Human Interface Device (HID)
A standard USB device class for peripherals like mice and keyboards that allows them to operate without custom drivers.
USB Enumeration
The process where a computer detects a newly connected USB device, identifies its specifications, and logs its presence in the system registry.
Zero Trust
A security framework requiring all users and devices to be continuously authenticated and authorized before accessing corporate network resources.

Common questions

Can Microsoft Teams or Slack detect a mouse jiggler?

No. Chat applications simply read the operating system's idle timer. Because a jiggler resets this timer, the status remains active, which is why endpoint monitoring tools are required for actual detection.

Does unplugging a USB jiggler erase the evidence?

No. The moment a USB device connects, Windows creates a persistent registry record and a Plug and Play event log that remains on the machine long after the dongle is removed.

Are mechanical mouse movers completely undetectable?

They bypass software and USB logs, but they are easily caught by behavioral analytics. Monitoring tools flag them because the cursor moves continuously without any corresponding clicks, keyboard input, or screen changes.

Competing readings

Endpoint Security Vendors

Hardware-level security providers view jigglers primarily as unauthorized peripherals that bypass zero-trust policies.

For hardware security firms, the productivity debate is secondary to the physical risk. A USB port that accepts an unvetted microcontroller is a port that can accept a malicious payload. They argue that behavior-based software tools inherently trust what they see on the screen, whereas hardware-based solutions verify what is physically connected to the motherboard. In their view, any device that masks its true nature—even just to keep a screen awake—violates the core principle of a zero-trust architecture.

Employee Monitoring Providers

Monitoring platforms emphasize behavioral correlation to ensure productivity data reflects genuine human effort.

Vendors building workforce analytics tools argue that measuring raw input is a flawed baseline. Because software and hardware jigglers can spoof the operating system's idle timer, these platforms focus on the context of the movement. They track whether a moving cursor ever clicks a valid application target, whether the keyboard is used concurrently, and whether the active window changes over time. Their perspective is that transparency and accurate data collection protect both the employer's bottom line and the honest employee's record.

Technical Analysts

Systems engineers focus on the immutable technical footprints left by synthetic input at the OS level.

From a purely technical standpoint, analysts point out that the 'undetectable' marketing claim sold to consumers is fundamentally false. The Windows kernel is explicitly designed to tag synthetic input via the LLMHF_INJECTED flag, meaning the operating system always knows when software is driving the cursor. They note that while users can shift the detection burden by switching to hardware or mechanical movers, they cannot erase the digital footprint entirely; they merely move the evidence to the USB enumeration log or the behavioral analytics engine.

Endpoint Security Vendors 35%Employee Monitoring Providers 35%Technical Analysts 30%
Endpoint Security Vendors
Hardware-level security providers view jigglers primarily as unauthorized peripherals that bypass zero-trust policies.
Employee Monitoring Providers
Monitoring platforms emphasize behavioral correlation to ensure productivity data reflects genuine human effort.
Technical Analysts
Systems engineers focus on the immutable technical footprints left by synthetic input at the OS level.

Perspectives this story doesn't cover

  • Hardware Manufacturers
  • Labor Union Representatives

Sources

Source coverage

4 outlets

3 viewpoints surfaced

Endpoint Security Vendors 35%Employee Monitoring Providers 35%Technical Analysts 30%
  1. [1]MicrosoftTechnical Analysts

    MSLLHOOKSTRUCT structure (winuser.h)

    Read on Microsoft →
  2. [2]Employee Monitoring NetEmployee Monitoring Providers

    Can employers detect mouse jigglers?

    Read on Employee Monitoring Net →
  3. [3]SepioEndpoint Security Vendors

    Mouse Jigglers Detection and Remediation

    Read on Sepio →
  4. [4]Factlen Editorial Team

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team →

Comments

Stay informed

Every angle. Every day.

Get Careers & Work stories with full source coverage and perspective breakdowns, free every day.