Skip to content

Physical security

Physical security is the link many organizations forget: a firewall is useless if anyone walks in behind an employee. This card covers physical intrusion vectors and in-person social engineering in an authorized engagement.

Tailgating/piggybacking slipping in behind an employee through an access-controlled door
(hands full, "I forgot my badge", courier uniform)
In-person impersonation posing as technician/cleaning/vendor/auditor with a pretext
Shoulder surfing watching passwords/screens over someone's shoulder
Dumpster diving digging through trash for documents/credentials/notes
USB drop dropping "lost" drives with a payload (within authorized scope)
Zone access meeting rooms, printers, network ports, unlocked racks
RFID/NFC many proximity cards (125kHz LF like HID Prox) are cloneable
Proxmark3 reading/cloning cards in proximity; Flipper Zero for LF/HF demos
Reading getting close to an employee (elevator, queue) and reading their card at short range
Defense encrypted cards (secure HF like DESFire), not LF 125kHz; blocking sleeves
- lock picking / bump keys on low-security locks (rooms, cabinets)
- "under-the-door" / shove tools and bypass of poorly installed panic bars
- doors that don't close, windows, service entrances, cleaning schedules
# all of this ONLY with explicit authorization and a signed physical scope
BadUSB/Rubber Ducky a USB posing as a keyboard that types commands when plugged in
"lost" USB drives with a decoy document that calls home when opened (in scope)
Goal measure whether employees plug in unknown devices
- authorization letter ("get out of jail") on hand, with a contact who confirms the operation
- signed physical scope: sites, hours, what can be opened/cloned, limits
- OPSEC: coherent pretext (uniform, agreed fake badge), exit plan
- no damage, no coercion; document with photos only what was agreed
  • Anti-tailgating: mantraps/turnstiles, a no-let-in culture, escorting visitors.
  • Secure HF cards (not cloneable LF), PIN+card in critical zones, RFID sleeves.
  • Clean desk, document shredders, screen lock, printer control.
  • Disable USB or allow only approved devices (EDR device control).
  • Surveillance, visitor logs, and training for reception/security on pretexts.
  • Documented physical pentests (e.g. accounts from teams like TrustedSec/RedTeam Security) show tailgating and RFID cloning with very high success rates.
  • Stuxnet (2010): the jump to an air-gapped network is attributed to USB as the entry vector.
  • Cloning HID Prox cards with Proxmark is a recurring classic in physical engagements.
  • Signed physical authorization + “get out of jail” letter and contact
  • Scope: sites, hours, what can be opened/cloned/plugged in
  • In-person pretext and agreed attire/badge
  • Vectors to test: tailgating, RFID, USB drop, sensitive zones
  • Kit ready (Proxmark/Flipper, USB, picks if in scope)
  • Documentation only of what was agreed; no damage or coercion
  • Report with physical-control improvements and training