Physical pentest tradecraft

Physical pentest tradecraft

TL;DR: Physical pentests test whether an attacker can walk into the building and reach sensitive assets. Tradecraft covers (1) recon (street + open-source), (2) pretext (vendor, contractor, employee), (3) entry techniques (tailgating, lock picking, badge clone, social engineering), (4) on-site OPSEC, (5) implant placement, (6) clean exit. The engagement letter must explicitly include physical scope, named buildings, time windows, and a get-out-of-jail card. Companion to hardware-implants-and-badusb and nfc-and-rfid-cloning.

Pre-engagement

The engagement letter must include:

  • Buildings, addresses, floors in scope.
  • Time windows — typically business hours; specify night-time / weekend permission separately.
  • Targets in scope — generic (“any system”) or named (“crown-jewel data store”).
  • Get-out-of-jail letter — signed authorisation that includes a 24/7 contact number for verification.
  • Insurance — your firm’s liability coverage.
  • Acceptable techniques — lock picking? Badge cloning? RF? Drone overflight? Burglary tools?
  • Excluded techniques — usually anything that damages property, blocks emergency exits, or risks injury.

Carry physical and digital copies of the authorisation. Wear it where law enforcement can quickly verify.

Recon

OSINT

  • Google Maps, Street View — layout, entry points, parking, dumpsters.
  • LinkedIn — employee names, recent hires, badge styles in photos.
  • Glassdoor — culture clues (e.g., “people work late on Fridays”).
  • The customer’s social media — uniforms, signs, badge photos.
  • Real-estate listings — old listings sometimes contain interior photos.

Physical recon

  • Drive-by — note times of shift changes, smoke breaks, delivery schedules.
  • Identify entry points: front desk, side doors, loading dock, garage.
  • Note reader types (nfc-and-rfid-cloning) — HID Prox? iCLASS? MIFARE?
  • Look for unmonitored ground-floor windows, conference-room balconies.
  • Note CCTV positions and blind spots.

Two visits separated by days; patterns emerge.

Pretexts

The pretext explains your presence to anyone who asks. Choose based on building culture.

Pretext When
Contracted vendor (HVAC, IT support, telecom) works for most office buildings
Visitor for a named employee when LinkedIn confirms the employee exists
New employee on day 1 edge case; requires good story for missing badge
Delivery person only at delivery windows; high physical visibility
Cleaning crew (after hours) high success; pair with night work
Auditor works in regulated industries (financial, healthcare)
Job interview candidate for HQs with frequent interview traffic

Pretext costume: business casual for office; high-vis vest + clipboard for “vendor”; uniform shirts available from print-on-demand if the customer agrees.

Entry techniques

Tailgating

  • Coffee in one hand, badge-less, looking distracted → ask someone to hold the door.
  • Push a cart of (empty) boxes → they hold the door.
  • Wait at smoking area → walk in with returning smokers.

Badge cloning

See nfc-and-rfid-cloning. Long-range HID Prox reader in a backpack can capture badges in a crowded elevator or lobby.

Social engineering at front desk

  • “I’m here to see {real-employee-name}”. Front-desk calls; if employee is busy, receptionist waves you in.
  • “I left my badge at home; I’m running late for an interview”. Some receptionists issue temporary.

Physical bypass

  • Latch slipping with a credit card / shim (older locks; many modern doors immune).
  • Lock bumping (specific pin-tumbler locks).
  • Pick attacks on filing cabinets, padlocks.
  • Pneumatic / under-the-door tools for unlocking via REX (Request-to-Exit) sensor — works against many access systems that trust IR motion sensors. Illegal in many jurisdictions; only on contracted engagements.
  • Lock picking — slow, conspicuous; rarely the primary tool.

Through-system bypass

  • Reception-area printer on the corporate network with a USB port — drop a USB implant.
  • Conference-room ethernet jack — LAN implant (hardware-implants-and-badusb).
  • Visitor Wi-Fi — sometimes bridged to internal; test from your phone before commitment.

On-site OPSEC

  • Phone on airplane mode + GPS off for in-building movements.
  • Burner second phone for “I’m running late” calls.
  • No personal items — no driving license, no credit card, no work badge.
  • Sterile clothing — no logos, no team colours.
  • One safe word with the on-site team in case of trouble.

If you’re caught:

  • Don’t run.
  • Produce the authorisation letter and the 24/7 contact.
  • Be polite, calm, and concede the engagement.
  • Customer’s IR may want a verbal debrief on-site; provide it.

Implant placement

  • Network jacks behind printers, receptionists’ desks, conference rooms.
  • USB on under-desk dock when nobody’s watching.
  • Inside ceiling tiles (with extension cable) for hard-to-reach offices.
  • O.MG cable swap with an existing charging cable.

Photograph the placement (without people in frame) for the report.

Exit

  • Plant implants on the way in; you may not have time on the way out.
  • Exit through a different route from entry to reduce camera correlation.
  • Don’t loiter outside taking notes.

Report

The customer wants:

  • Timeline of the day(s).
  • Photos of entry / placement (no employees’ faces).
  • Specific control failures (camera at angle X missed Y; receptionist Z accepted pretext A).
  • Recommendations: cameras, training, policies, mantraps, smart-card-only access.

Frame the report as “this is what your controls would have stopped, and these are the controls that failed”.

Defence

  • Mantraps — only one person at a time; defeats tailgating.
  • Smart-card + PIN for high-sensitivity areas.
  • Camera coverage with retention long enough for IR.
  • Visitor management — pre-registration, ID check, escorts.
  • Security-awareness training — “challenge unknown people politely”.
  • Penetration of unmonitored entry points — loading docks, smoking exits.

Real-world success rates

In published industry data (eg Verizon DBIR, vendor reports), physical pentests succeed in 80-90% of engagements. The chokepoints are mantraps and smart-card+PIN, not human alertness.

Physical engagements regularly produce arrests of authorised testers because of unclear paperwork. Bring the authorisation. Cooperate with law enforcement. Have customer counsel on speed-dial. Don’t carry tools you can’t legally possess (regional restrictions on lock picks).

References