Physical pentest tradecraft
TL;DR: Physical pentests test whether an attacker can walk into the building and reach sensitive assets. Tradecraft covers (1) recon (street + open-source), (2) pretext (vendor, contractor, employee), (3) entry techniques (tailgating, lock picking, badge clone, social engineering), (4) on-site OPSEC, (5) implant placement, (6) clean exit. The engagement letter must explicitly include physical scope, named buildings, time windows, and a get-out-of-jail card. Companion to hardware-implants-and-badusb and nfc-and-rfid-cloning.
Pre-engagement
The engagement letter must include:
- Buildings, addresses, floors in scope.
- Time windows — typically business hours; specify night-time / weekend permission separately.
- Targets in scope — generic (“any system”) or named (“crown-jewel data store”).
- Get-out-of-jail letter — signed authorisation that includes a 24/7 contact number for verification.
- Insurance — your firm’s liability coverage.
- Acceptable techniques — lock picking? Badge cloning? RF? Drone overflight? Burglary tools?
- Excluded techniques — usually anything that damages property, blocks emergency exits, or risks injury.
Carry physical and digital copies of the authorisation. Wear it where law enforcement can quickly verify.
Recon
OSINT
- Google Maps, Street View — layout, entry points, parking, dumpsters.
- LinkedIn — employee names, recent hires, badge styles in photos.
- Glassdoor — culture clues (e.g., “people work late on Fridays”).
- The customer’s social media — uniforms, signs, badge photos.
- Real-estate listings — old listings sometimes contain interior photos.
Physical recon
- Drive-by — note times of shift changes, smoke breaks, delivery schedules.
- Identify entry points: front desk, side doors, loading dock, garage.
- Note reader types (nfc-and-rfid-cloning) — HID Prox? iCLASS? MIFARE?
- Look for unmonitored ground-floor windows, conference-room balconies.
- Note CCTV positions and blind spots.
Two visits separated by days; patterns emerge.
Pretexts
The pretext explains your presence to anyone who asks. Choose based on building culture.
| Pretext | When |
|---|---|
| Contracted vendor (HVAC, IT support, telecom) | works for most office buildings |
| Visitor for a named employee | when LinkedIn confirms the employee exists |
| New employee on day 1 | edge case; requires good story for missing badge |
| Delivery person | only at delivery windows; high physical visibility |
| Cleaning crew (after hours) | high success; pair with night work |
| Auditor | works in regulated industries (financial, healthcare) |
| Job interview candidate | for HQs with frequent interview traffic |
Pretext costume: business casual for office; high-vis vest + clipboard for “vendor”; uniform shirts available from print-on-demand if the customer agrees.
Entry techniques
Tailgating
- Coffee in one hand, badge-less, looking distracted → ask someone to hold the door.
- Push a cart of (empty) boxes → they hold the door.
- Wait at smoking area → walk in with returning smokers.
Badge cloning
See nfc-and-rfid-cloning. Long-range HID Prox reader in a backpack can capture badges in a crowded elevator or lobby.
Social engineering at front desk
- “I’m here to see {real-employee-name}”. Front-desk calls; if employee is busy, receptionist waves you in.
- “I left my badge at home; I’m running late for an interview”. Some receptionists issue temporary.
Physical bypass
- Latch slipping with a credit card / shim (older locks; many modern doors immune).
- Lock bumping (specific pin-tumbler locks).
- Pick attacks on filing cabinets, padlocks.
- Pneumatic / under-the-door tools for unlocking via REX (Request-to-Exit) sensor — works against many access systems that trust IR motion sensors. Illegal in many jurisdictions; only on contracted engagements.
- Lock picking — slow, conspicuous; rarely the primary tool.
Through-system bypass
- Reception-area printer on the corporate network with a USB port — drop a USB implant.
- Conference-room ethernet jack — LAN implant (hardware-implants-and-badusb).
- Visitor Wi-Fi — sometimes bridged to internal; test from your phone before commitment.
On-site OPSEC
- Phone on airplane mode + GPS off for in-building movements.
- Burner second phone for “I’m running late” calls.
- No personal items — no driving license, no credit card, no work badge.
- Sterile clothing — no logos, no team colours.
- One safe word with the on-site team in case of trouble.
If you’re caught:
- Don’t run.
- Produce the authorisation letter and the 24/7 contact.
- Be polite, calm, and concede the engagement.
- Customer’s IR may want a verbal debrief on-site; provide it.
Implant placement
- Network jacks behind printers, receptionists’ desks, conference rooms.
- USB on under-desk dock when nobody’s watching.
- Inside ceiling tiles (with extension cable) for hard-to-reach offices.
- O.MG cable swap with an existing charging cable.
Photograph the placement (without people in frame) for the report.
Exit
- Plant implants on the way in; you may not have time on the way out.
- Exit through a different route from entry to reduce camera correlation.
- Don’t loiter outside taking notes.
Report
The customer wants:
- Timeline of the day(s).
- Photos of entry / placement (no employees’ faces).
- Specific control failures (camera at angle X missed Y; receptionist Z accepted pretext A).
- Recommendations: cameras, training, policies, mantraps, smart-card-only access.
Frame the report as “this is what your controls would have stopped, and these are the controls that failed”.
Defence
- Mantraps — only one person at a time; defeats tailgating.
- Smart-card + PIN for high-sensitivity areas.
- Camera coverage with retention long enough for IR.
- Visitor management — pre-registration, ID check, escorts.
- Security-awareness training — “challenge unknown people politely”.
- Penetration of unmonitored entry points — loading docks, smoking exits.
Real-world success rates
In published industry data (eg Verizon DBIR, vendor reports), physical pentests succeed in 80-90% of engagements. The chokepoints are mantraps and smart-card+PIN, not human alertness.
Legal
Physical engagements regularly produce arrests of authorised testers because of unclear paperwork. Bring the authorisation. Cooperate with law enforcement. Have customer counsel on speed-dial. Don’t carry tools you can’t legally possess (regional restrictions on lock picks).
References
- Deviant Ollam — physical pentest talks (research index)
- Red Team Field Manual (RTFM)
- Brent White / Tim Roberts — physical SE talks (search names)
- See also: hardware-implants-and-badusb, nfc-and-rfid-cloning, pretext-design-for-engagements