← All cheat sheets

PHYSICAL-PENTEST

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Methodology, tools, and techniques for authorized physical
security assessments. Always operate within legal scope.
BEFORE ANY ENGAGEMENT:
  [ ] Written authorization (scope, dates, times, locations)
  [ ] Letter of authorization on company letterhead (carry at all times)
  [ ] Emergency contact for client security team
  [ ] NDA signed
  [ ] Insurance coverage verified
  [ ] Local law review (trespass, lock picking, recording laws)
  [ ] Rules of engagement clearly defined
  [ ] Safe word / abort procedure established
  [ ] Identification carried (in case of police contact)
  [ ] Scope limitations documented (no-go areas, off-limits systems)

If confronted:
  1. Remain calm and cooperative
  2. Identify yourself immediately
  3. Present letter of authorization
  4. Contact client emergency POC
  5. Do not resist security or law enforcement
  6. Document the interaction for the report

PHASE 1: RECONNAISSANCE#

OSINT on the building and organization:
  Google Maps / Street View:
    - Building layout and entry points
    - Parking areas and access roads
    - Neighboring businesses
    - Loading docks and service entrances
    - Fence types and gate locations
    - Camera placements visible from street

  Public records:
    - Building permits (floor plans may be public)
    - Fire department records (evacuation plans)
    - Zoning records
    - Business registrations

  Social media:
    - Employee LinkedIn profiles (badge photos, office photos)
    - Company Instagram/Facebook (office layout, events)
    - Job postings (technology stack, security systems)
    - Glassdoor (office culture, security practices)

  Employee information:
    - Organizational chart (who has authority)
    - Employee names and roles (for pretexting)
    - Dress code (for blending in)
    - Working hours and shift changes
    - Vendor and contractor relationships

  Technical reconnaissance:
    - Badge/access control system brand (look for logos)
    - Camera types and coverage
    - Alarm system provider (signs, stickers)
    - WiFi SSIDs (wardriving)
    - Phone system (for vishing)

Physical surveillance:
  [ ] Observe entry/exit patterns at shift changes
  [ ] Identify security guard schedules and rotation
  [ ] Note smoker's entrance (often propped open)
  [ ] Identify delivery schedules and procedures
  [ ] Document camera blind spots
  [ ] Note tailgating opportunities at busy times
  [ ] Check dumpsters for sensitive documents (dumpster diving)
  [ ] Identify badge type (proximity, smart card, magnetic stripe)

PHASE 2: SOCIAL ENGINEERING ENTRY#

Pretexting scenarios:
  IT Support:
    "Hi, I'm from [IT vendor]. We have a ticket to check on your servers."
    Props: laptop bag, clipboard, vendor polo/lanyard

  Delivery person:
    "I have a package for [employee name]."
    Props: package, clipboard, uniform

  Fire/Safety inspector:
    "We're doing annual fire safety compliance checks."
    Props: clipboard, hard hat, safety vest

  New employee:
    "I'm starting today in [department]. HR told me to come here."
    Props: appropriate business attire

  Maintenance/HVAC:
    "We got a call about an HVAC issue on the 3rd floor."
    Props: tools, work uniform

  Vendor/Consultant:
    "I have a meeting with [executive name]."
    Props: business attire, briefcase

Key social engineering principles:
  - Authority: appear to have authorization
  - Urgency: create time pressure
  - Social proof: "everyone else let me through"
  - Reciprocity: offer something (hold door, carry items)
  - Liking: be friendly and approachable

PHASE 3: TAILGATING AND UNAUTHORIZED ACCESS#

Tailgating techniques:
  - Follow closely behind authorized person through door
  - Carry items with both hands (people hold doors open)
  - Arrive with a group during busy entry times
  - Use phone call as distraction ("can you hold the door?")
  - Time entry with delivery or vendor arrivals
  - Use smoking areas (often have propped doors)

Counter-tailgating note:
  Document how many times tailgating succeeds vs fails.
  Note which entrances are most/least secure.

PHASE 4: BADGE CLONING#

Proxmark3 (RFID/NFC tool):
  Supported card types:
    - HID iCLASS
    - HID Prox (125kHz)
    - MIFARE Classic (13.56MHz)
    - EM4100 (125kHz)
    - T5577 (writable, 125kHz)

  Basic commands:
    # Identify card type
    lf search                    # low frequency (125kHz)
    hf search                    # high frequency (13.56MHz)

    # Read HID Prox card
    lf hid reader                # read card on reader
    lf hid demod                 # decode last read

    # Clone to T5577 blank
    lf hid clone -r <raw_hex>   # clone HID card

    # Read MIFARE Classic
    hf mf autopwn               # auto-crack and dump
    hf mf rdsc                  # read sector

    # Simulate card
    lf hid sim -r <raw_hex>     # simulate HID card
    hf mf sim --1k              # simulate MIFARE 1K

  Long-range reading:
    - Standard readers: 1-5 cm range
    - Custom antenna builds: up to 1 meter for 125kHz
    - Commercial long-range readers available

  Other tools:
    - Flipper Zero (multi-protocol, portable)
    - ChameleonMini/Ultra (card emulation)
    - iCopy-X (portable cloner)
    - ACR122U (USB NFC reader/writer)

PHASE 5: LOCK PICKING#

Note: Only pick locks you are authorized to test.
See LOCKPICKING.txt for detailed techniques.

Basic tools needed:
  - Tension wrench set (top and bottom of keyway)
  - Hook picks (short, medium, deep)
  - Rake picks (bogota, snake, city)
  - Diamond picks
  - Ball pick
  - Bypass tools (shims, traveler hooks)

Quick entry methods (fastest to slowest):
  1. Try the door (often unlocked)
  2. Use a found/cloned badge
  3. Bump key (fast, noisy)
  4. Raking (5-30 seconds)
  5. Single pin picking (30 seconds - 5 minutes)
  6. Bypass tools (varies)

Document: lock type, brand, time to open, technique used.

PHASE 6: USB DROP ATTACKS#

Concept: Leave USB devices in parking lots, lobbies, or common areas.
Goal: test if employees plug in unknown devices.

Tools:
  Rubber Ducky (Hak5):
    - Looks like USB flash drive
    - Emulates keyboard
    - Executes pre-programmed keystrokes
    - Payload examples: reverse shell, credential harvest

  Bash Bunny (Hak5):
    - Multi-function USB attack platform
    - Emulates keyboard, storage, ethernet
    - More sophisticated payloads

  O.MG Cable:
    - Looks like normal charging cable
    - Contains WiFi-enabled implant
    - Remote command execution
    - Keystroke injection

  Custom USB (less aggressive):
    - Regular USB with tracking beacon
    - HTML file that phones home when opened
    - Measures: how many found, how many plugged in, how many reported

  Placement locations:
    - Parking lot (near entrance)
    - Lobby / reception area
    - Break room / kitchen
    - Restrooms
    - Conference rooms

PHASE 7: ROGUE DEVICE DEPLOYMENT#

LAN Turtle (Hak5):
  - USB Ethernet adapter form factor
  - Plugs inline between computer and network
  - Provides reverse shell, MitM, recon
  - Auto-SSH tunnel back to attacker
  - Small and easily hidden

WiFi Pineapple (Hak5):
  - Rogue access point
  - Evil twin attacks
  - Captive portal credential capture
  - Probe request sniffing
  - Can be concealed in ceiling tiles or behind equipment

Packet Squirrel (Hak5):
  - Inline network implant
  - Packet capture and exfiltration
  - VPN tunnel
  - Logging mode

Raspberry Pi implant:
  - Cheap, versatile
  - Can run: responder, ntlmrelayx, nmap
  - WiFi + ethernet for bridging
  - Powered by USB or PoE hat
  - Small enough to hide under desks

Placement strategy:
  - Behind monitors (USB + network)
  - Under desks near network drops
  - In server rooms (if accessed)
  - Near printers (often on flat networks)
  - In wiring closets

Documentation:
  - Photograph placement location
  - Record time of deployment
  - Note how long before discovery (if ever)
  - Track what data/access was obtained

PHASE 8: INTERNAL ASSESSMENT#

Once inside the facility:
  [ ] How far can you move without being challenged?
  [ ] Are server rooms and wiring closets locked?
  [ ] Are sensitive documents left on desks (clean desk policy)?
  [ ] Are screens locked when unattended?
  [ ] Are passwords written down (sticky notes, under keyboards)?
  [ ] Can you access network ports in common areas?
  [ ] Are printers in secure areas? Any print jobs with sensitive data?
  [ ] Can you shoulder surf credentials?
  [ ] Are visitor badges collected when leaving?
  [ ] Are there unsecured WiFi access points?
  [ ] Are cameras functional and monitored?
  [ ] Can you access loading dock or roof?

PHASE 9: REPORTING#

Report structure:
  1. Executive Summary
     - Overall physical security posture rating
     - Critical findings summary
     - Positive observations (what worked well)

  2. Methodology
     - Scope and rules of engagement
     - Dates and times of testing
     - Techniques attempted

  3. Findings (for each):
     - Description of vulnerability
     - Location and time
     - Evidence (photos, logs, artifacts)
     - Risk rating (Critical/High/Medium/Low)
     - Affected security controls
     - Remediation recommendation

  4. Timeline of Events
     - Chronological account of the assessment

  5. Recommendations
     - Prioritized remediation steps
     - Quick wins vs long-term improvements
     - Policy and procedure updates
     - Training recommendations

  6. Appendices
     - Photos and evidence
     - Rules of engagement document
     - Tool list

PHYSICAL SECURITY CONTROLS TO EVALUATE#

[ ] Perimeter fencing and barriers
[ ] Gate access controls
[ ] Security guard presence and alertness
[ ] Visitor management procedures
[ ] Badge/access card systems
[ ] Tailgating prevention (mantraps, turnstiles)
[ ] Camera coverage and monitoring
[ ] Alarm systems
[ ] Lock quality and maintenance
[ ] Server room physical security
[ ] Clean desk policy enforcement
[ ] Screen lock policy enforcement
[ ] Dumpster security (shredding, locked bins)
[ ] USB port controls
[ ] Network jack security
[ ] Signage (restricted areas clearly marked)
[ ] Emergency exit security (alarmed?)
[ ] Loading dock procedures
[ ] Mail/package screening

REFERENCES#

- The Art of Intrusion (Kevin Mitnick)
- Unauthorized Access: Physical Penetration Testing (Wil Allsopp)
- ASIS Physical Security Professional (PSP)
- Hak5 Tools: https://shop.hak5.org/
- Proxmark: https://proxmark.com/
- TOOOL (The Open Organisation Of Lockpickers): https://toool.us/