PHYSICAL-PENTEST
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Methodology, tools, and techniques for authorized physical security assessments. Always operate within legal scope.
LEGAL AND ETHICAL CONSIDERATIONS#
BEFORE ANY ENGAGEMENT: [ ] Written authorization (scope, dates, times, locations) [ ] Letter of authorization on company letterhead (carry at all times) [ ] Emergency contact for client security team [ ] NDA signed [ ] Insurance coverage verified [ ] Local law review (trespass, lock picking, recording laws) [ ] Rules of engagement clearly defined [ ] Safe word / abort procedure established [ ] Identification carried (in case of police contact) [ ] Scope limitations documented (no-go areas, off-limits systems) If confronted: 1. Remain calm and cooperative 2. Identify yourself immediately 3. Present letter of authorization 4. Contact client emergency POC 5. Do not resist security or law enforcement 6. Document the interaction for the report
PHASE 1: RECONNAISSANCE#
OSINT on the building and organization:
Google Maps / Street View:
- Building layout and entry points
- Parking areas and access roads
- Neighboring businesses
- Loading docks and service entrances
- Fence types and gate locations
- Camera placements visible from street
Public records:
- Building permits (floor plans may be public)
- Fire department records (evacuation plans)
- Zoning records
- Business registrations
Social media:
- Employee LinkedIn profiles (badge photos, office photos)
- Company Instagram/Facebook (office layout, events)
- Job postings (technology stack, security systems)
- Glassdoor (office culture, security practices)
Employee information:
- Organizational chart (who has authority)
- Employee names and roles (for pretexting)
- Dress code (for blending in)
- Working hours and shift changes
- Vendor and contractor relationships
Technical reconnaissance:
- Badge/access control system brand (look for logos)
- Camera types and coverage
- Alarm system provider (signs, stickers)
- WiFi SSIDs (wardriving)
- Phone system (for vishing)
Physical surveillance:
[ ] Observe entry/exit patterns at shift changes
[ ] Identify security guard schedules and rotation
[ ] Note smoker's entrance (often propped open)
[ ] Identify delivery schedules and procedures
[ ] Document camera blind spots
[ ] Note tailgating opportunities at busy times
[ ] Check dumpsters for sensitive documents (dumpster diving)
[ ] Identify badge type (proximity, smart card, magnetic stripe)
PHASE 2: SOCIAL ENGINEERING ENTRY#
Pretexting scenarios:
IT Support:
"Hi, I'm from [IT vendor]. We have a ticket to check on your servers."
Props: laptop bag, clipboard, vendor polo/lanyard
Delivery person:
"I have a package for [employee name]."
Props: package, clipboard, uniform
Fire/Safety inspector:
"We're doing annual fire safety compliance checks."
Props: clipboard, hard hat, safety vest
New employee:
"I'm starting today in [department]. HR told me to come here."
Props: appropriate business attire
Maintenance/HVAC:
"We got a call about an HVAC issue on the 3rd floor."
Props: tools, work uniform
Vendor/Consultant:
"I have a meeting with [executive name]."
Props: business attire, briefcase
Key social engineering principles:
- Authority: appear to have authorization
- Urgency: create time pressure
- Social proof: "everyone else let me through"
- Reciprocity: offer something (hold door, carry items)
- Liking: be friendly and approachable
PHASE 3: TAILGATING AND UNAUTHORIZED ACCESS#
Tailgating techniques:
- Follow closely behind authorized person through door
- Carry items with both hands (people hold doors open)
- Arrive with a group during busy entry times
- Use phone call as distraction ("can you hold the door?")
- Time entry with delivery or vendor arrivals
- Use smoking areas (often have propped doors)
Counter-tailgating note:
Document how many times tailgating succeeds vs fails.
Note which entrances are most/least secure.
PHASE 4: BADGE CLONING#
Proxmark3 (RFID/NFC tool):
Supported card types:
- HID iCLASS
- HID Prox (125kHz)
- MIFARE Classic (13.56MHz)
- EM4100 (125kHz)
- T5577 (writable, 125kHz)
Basic commands:
# Identify card type
lf search # low frequency (125kHz)
hf search # high frequency (13.56MHz)
# Read HID Prox card
lf hid reader # read card on reader
lf hid demod # decode last read
# Clone to T5577 blank
lf hid clone -r <raw_hex> # clone HID card
# Read MIFARE Classic
hf mf autopwn # auto-crack and dump
hf mf rdsc # read sector
# Simulate card
lf hid sim -r <raw_hex> # simulate HID card
hf mf sim --1k # simulate MIFARE 1K
Long-range reading:
- Standard readers: 1-5 cm range
- Custom antenna builds: up to 1 meter for 125kHz
- Commercial long-range readers available
Other tools:
- Flipper Zero (multi-protocol, portable)
- ChameleonMini/Ultra (card emulation)
- iCopy-X (portable cloner)
- ACR122U (USB NFC reader/writer)
PHASE 5: LOCK PICKING#
Note: Only pick locks you are authorized to test. See LOCKPICKING.txt for detailed techniques. Basic tools needed: - Tension wrench set (top and bottom of keyway) - Hook picks (short, medium, deep) - Rake picks (bogota, snake, city) - Diamond picks - Ball pick - Bypass tools (shims, traveler hooks) Quick entry methods (fastest to slowest): 1. Try the door (often unlocked) 2. Use a found/cloned badge 3. Bump key (fast, noisy) 4. Raking (5-30 seconds) 5. Single pin picking (30 seconds - 5 minutes) 6. Bypass tools (varies) Document: lock type, brand, time to open, technique used.
PHASE 6: USB DROP ATTACKS#
Concept: Leave USB devices in parking lots, lobbies, or common areas.
Goal: test if employees plug in unknown devices.
Tools:
Rubber Ducky (Hak5):
- Looks like USB flash drive
- Emulates keyboard
- Executes pre-programmed keystrokes
- Payload examples: reverse shell, credential harvest
Bash Bunny (Hak5):
- Multi-function USB attack platform
- Emulates keyboard, storage, ethernet
- More sophisticated payloads
O.MG Cable:
- Looks like normal charging cable
- Contains WiFi-enabled implant
- Remote command execution
- Keystroke injection
Custom USB (less aggressive):
- Regular USB with tracking beacon
- HTML file that phones home when opened
- Measures: how many found, how many plugged in, how many reported
Placement locations:
- Parking lot (near entrance)
- Lobby / reception area
- Break room / kitchen
- Restrooms
- Conference rooms
PHASE 7: ROGUE DEVICE DEPLOYMENT#
LAN Turtle (Hak5): - USB Ethernet adapter form factor - Plugs inline between computer and network - Provides reverse shell, MitM, recon - Auto-SSH tunnel back to attacker - Small and easily hidden WiFi Pineapple (Hak5): - Rogue access point - Evil twin attacks - Captive portal credential capture - Probe request sniffing - Can be concealed in ceiling tiles or behind equipment Packet Squirrel (Hak5): - Inline network implant - Packet capture and exfiltration - VPN tunnel - Logging mode Raspberry Pi implant: - Cheap, versatile - Can run: responder, ntlmrelayx, nmap - WiFi + ethernet for bridging - Powered by USB or PoE hat - Small enough to hide under desks Placement strategy: - Behind monitors (USB + network) - Under desks near network drops - In server rooms (if accessed) - Near printers (often on flat networks) - In wiring closets Documentation: - Photograph placement location - Record time of deployment - Note how long before discovery (if ever) - Track what data/access was obtained
PHASE 8: INTERNAL ASSESSMENT#
Once inside the facility: [ ] How far can you move without being challenged? [ ] Are server rooms and wiring closets locked? [ ] Are sensitive documents left on desks (clean desk policy)? [ ] Are screens locked when unattended? [ ] Are passwords written down (sticky notes, under keyboards)? [ ] Can you access network ports in common areas? [ ] Are printers in secure areas? Any print jobs with sensitive data? [ ] Can you shoulder surf credentials? [ ] Are visitor badges collected when leaving? [ ] Are there unsecured WiFi access points? [ ] Are cameras functional and monitored? [ ] Can you access loading dock or roof?
PHASE 9: REPORTING#
Report structure:
1. Executive Summary
- Overall physical security posture rating
- Critical findings summary
- Positive observations (what worked well)
2. Methodology
- Scope and rules of engagement
- Dates and times of testing
- Techniques attempted
3. Findings (for each):
- Description of vulnerability
- Location and time
- Evidence (photos, logs, artifacts)
- Risk rating (Critical/High/Medium/Low)
- Affected security controls
- Remediation recommendation
4. Timeline of Events
- Chronological account of the assessment
5. Recommendations
- Prioritized remediation steps
- Quick wins vs long-term improvements
- Policy and procedure updates
- Training recommendations
6. Appendices
- Photos and evidence
- Rules of engagement document
- Tool list
PHYSICAL SECURITY CONTROLS TO EVALUATE#
[ ] Perimeter fencing and barriers [ ] Gate access controls [ ] Security guard presence and alertness [ ] Visitor management procedures [ ] Badge/access card systems [ ] Tailgating prevention (mantraps, turnstiles) [ ] Camera coverage and monitoring [ ] Alarm systems [ ] Lock quality and maintenance [ ] Server room physical security [ ] Clean desk policy enforcement [ ] Screen lock policy enforcement [ ] Dumpster security (shredding, locked bins) [ ] USB port controls [ ] Network jack security [ ] Signage (restricted areas clearly marked) [ ] Emergency exit security (alarmed?) [ ] Loading dock procedures [ ] Mail/package screening
REFERENCES#
- The Art of Intrusion (Kevin Mitnick) - Unauthorized Access: Physical Penetration Testing (Wil Allsopp) - ASIS Physical Security Professional (PSP) - Hak5 Tools: https://shop.hak5.org/ - Proxmark: https://proxmark.com/ - TOOOL (The Open Organisation Of Lockpickers): https://toool.us/