Physical security
Physical security is the link many organizations forget: a firewall is useless if anyone walks in behind an employee. This card covers physical intrusion vectors and in-person social engineering in an authorized engagement.
Physical intrusion vectors
Section titled “Physical intrusion vectors”Tailgating/piggybacking slipping in behind an employee through an access-controlled door (hands full, "I forgot my badge", courier uniform)In-person impersonation posing as technician/cleaning/vendor/auditor with a pretextShoulder surfing watching passwords/screens over someone's shoulderDumpster diving digging through trash for documents/credentials/notesUSB drop dropping "lost" drives with a payload (within authorized scope)Zone access meeting rooms, printers, network ports, unlocked racksCloning access credentials
Section titled “Cloning access credentials”RFID/NFC many proximity cards (125kHz LF like HID Prox) are cloneableProxmark3 reading/cloning cards in proximity; Flipper Zero for LF/HF demosReading getting close to an employee (elevator, queue) and reading their card at short rangeDefense encrypted cards (secure HF like DESFire), not LF 125kHz; blocking sleevesBypassing physical controls
Section titled “Bypassing physical controls”- lock picking / bump keys on low-security locks (rooms, cabinets)- "under-the-door" / shove tools and bypass of poorly installed panic bars- doors that don't close, windows, service entrances, cleaning schedules# all of this ONLY with explicit authorization and a signed physical scopeUSB drop and devices
Section titled “USB drop and devices”BadUSB/Rubber Ducky a USB posing as a keyboard that types commands when plugged in"lost" USB drives with a decoy document that calls home when opened (in scope)Goal measure whether employees plug in unknown devicesExecution (authorized engagement)
Section titled “Execution (authorized engagement)”- authorization letter ("get out of jail") on hand, with a contact who confirms the operation- signed physical scope: sites, hours, what can be opened/cloned, limits- OPSEC: coherent pretext (uniform, agreed fake badge), exit plan- no damage, no coercion; document with photos only what was agreedDefense (blue team / physical security)
Section titled “Defense (blue team / physical security)”- Anti-tailgating: mantraps/turnstiles, a no-let-in culture, escorting visitors.
- Secure HF cards (not cloneable LF), PIN+card in critical zones, RFID sleeves.
- Clean desk, document shredders, screen lock, printer control.
- Disable USB or allow only approved devices (EDR device control).
- Surveillance, visitor logs, and training for reception/security on pretexts.
Real-world cases
Section titled “Real-world cases”- Documented physical pentests (e.g. accounts from teams like TrustedSec/RedTeam Security) show tailgating and RFID cloning with very high success rates.
- Stuxnet (2010): the jump to an air-gapped network is attributed to USB as the entry vector.
- Cloning HID Prox cards with Proxmark is a recurring classic in physical engagements.
Testing checklist
Section titled “Testing checklist”- Signed physical authorization + “get out of jail” letter and contact
- Scope: sites, hours, what can be opened/cloned/plugged in
- In-person pretext and agreed attire/badge
- Vectors to test: tailgating, RFID, USB drop, sensitive zones
- Kit ready (Proxmark/Flipper, USB, picks if in scope)
- Documentation only of what was agreed; no damage or coercion
- Report with physical-control improvements and training