Physical Pentest

Physical Penetration Testing: An Introduction

What Is Physical Penetration Testing?

Physical penetration testing is the authorized, simulated attack on an organization's physical security controls. A physical penetration tester (or "physical pentester") attempts to bypass physical barriers - locked doors, access control systems, surveillance cameras, security guards, and organizational policies - to gain unauthorized access to a facility or sensitive area.

The goal is not to cause harm but to identify weaknesses before a real attacker exploits them. The tester documents every vulnerability found, every control bypassed, and every area accessed, then provides the organization with a detailed report and remediation recommendations.

Physical pentesting is the real-world counterpart to network penetration testing. Where a network pentester attacks firewalls, authentication systems, and software vulnerabilities, a physical pentester attacks doors, badges, cameras, guards, and human trust. The skills are different, but the objective is the same: find the weaknesses before someone with malicious intent does.

How It Differs from Digital Penetration Testing

graph TD
    subgraph Digital["Digital Penetration Testing"]
        D1["Target: Networks, applications, systems"]
        D2["Tools: Software scanners, exploits"]
        D3["Access: Remote or on-network"]
        D4["Evidence: Logs, screenshots, data"]
        D5["Risk: System damage, data exposure"]
        D6["Detection: IDS/IPS, SIEM alerts"]
        D7["Reversibility: Usually reversible"]
    end
    subgraph Physical["Physical Penetration Testing"]
        P1["Target: Buildings, rooms, people"]
        P2["Tools: RFID cloner, lock picks, pretexts"]
        P3["Access: On-site, in-person"]
        P4["Evidence: Photos, video, badge clones"]
        P5["Risk: Confrontation, detention, injury"]
        P6["Detection: Guards, cameras, employees"]
        P7["Reversibility: Actions may have witnesses"]
    end
    subgraph Combined["Full-Scope Red Team"]
        C1["Combines both approaches"]
        C2["Physical access enables digital attacks"]
        C3["Digital recon enables physical attacks"]
        C4["Most realistic threat simulation"]
    end

Digital vs physical penetration testing - different targets, different tools, different risks

Physical pentesting differs from digital pentesting in several important ways:

Personal risk: Digital pentesters sit behind a screen. Physical pentesters are on-site, in person, attempting to do things that look suspicious to security personnel and employees. There is a real risk of confrontation, detention by security guards, or even arrest if the authorization documentation is not immediately available. Physical pentesters carry their authorization letter at all times.

Social interaction: Digital pentesting is primarily technical. Physical pentesting is heavily social. Pretexting (using a fabricated scenario to gain trust), tailgating (following someone through a secured door), and social engineering are core techniques. The tester needs to read people, adapt to unexpected situations, and maintain composure when things go sideways.

Irreversibility: If a digital pentest breaks something, it can usually be restored from backups. If a physical pentester is caught on camera entering a restricted area, that footage exists. If they are confronted by an employee, that interaction happened. Physical pentesting creates real-world events that cannot be undone.

Environmental awareness: Physical pentesters need to understand building systems, lock types, alarm systems, camera placements, guard patrol patterns, employee behaviors, and facility layouts. The reconnaissance phase involves physical observation in addition to (or instead of) network scanning.

Why Physical Pentesting Matters

Organizations spend heavily on digital security - firewalls, endpoint protection, SOC teams, incident response plans. But many of these controls can be bypassed by physical access. An attacker who can walk into the server room can plug directly into the network, install hardware implants, steal hard drives, or access systems that are well-protected from remote attack but have no physical security at all.

Physical security failures enable digital attacks:

  • A cloned badge gets the attacker inside the building
  • A dropped USB drive (USB rubber ducky) gets code execution on an employee's workstation
  • A network tap installed in a wiring closet captures internal traffic
  • Physical access to a server allows console login, BIOS password reset, or disk removal
  • A rogue wireless access point plugged into an internal network port creates a persistent backdoor

Physical pentesting reveals these attack paths. It tests not just the technical controls (locks, cameras, access control) but also the human controls (security awareness, visitor policies, challenging strangers, reporting suspicious behavior).

Methodology and Phases

gantt
    title Physical Penetration Test Phases
    dateFormat  X
    axisFormat %s
    section Planning
    Scoping and Rules of Engagement    :0, 5
    Authorization and Legal Review      :3, 8
    section Reconnaissance
    OSINT - Social media, maps, photos  :8, 14
    On-site observation                 :12, 18
    Identify entry points and targets   :16, 20
    section Preparation
    Prepare pretexts and disguises      :20, 24
    Acquire/prepare tools               :22, 26
    Clone badges if applicable          :24, 28
    section Execution
    Attempt entry - social engineering  :28, 33
    Attempt entry - technical bypass    :30, 35
    Navigate to target areas            :33, 38
    Plant proof of access               :36, 40
    section Reporting
    Document findings                   :40, 45
    Draft report with evidence          :43, 48
    Present to stakeholders             :47, 50

Typical physical penetration test timeline from planning through reporting

A physical penetration test follows a structured methodology, similar in philosophy to digital pentesting but different in practice:

Phase 1: Planning and Scoping

Define what is in scope (which buildings, which areas, which techniques are permitted), establish rules of engagement, obtain written authorization, and coordinate with the organization's point of contact. This phase also identifies the objectives - what does "success" look like? Getting into the building? Reaching the server room? Planting a device on the network? Accessing the executive floor?

Phase 2: Reconnaissance

Gather information about the target facility. This includes:

OSINT (Open Source Intelligence): Satellite imagery (Google Earth), street-level views, building plans from public records, social media posts by employees (badge photos, building interior photos, check-in locations), corporate websites (office locations, floor plans in job listings), and news articles.

On-site observation: Visit the area openly to observe entry points, camera locations, guard patterns, employee behavior (do they badge in individually or hold doors?), delivery schedules, and general security posture. Note which doors are propped open, which areas are unsupervised, and how employees react to strangers.

Technical reconnaissance: Identify the access control system brand and model (often visible on readers), Wi-Fi networks (SSID names often reveal the organization), and any externally visible security systems.

Phase 3: Preparation

Develop attack plans based on reconnaissance. This might include:

  • Crafting pretexts (delivery person, IT contractor, new employee, fire inspector)
  • Preparing disguises or appropriate attire (high-visibility vest, suit and tie, branded polo)
  • Acquiring tools (RFID cloner, lock picks, drop devices, fake badges)
  • Cloning a captured badge if RFID skimming was successful
  • Preparing drop devices (Raspberry Pi, network implant, USB devices) if in scope

Phase 4: Execution

The actual penetration attempts. The tester will typically try multiple approaches, from least aggressive to most:

  1. Open doors: Check for unlocked or propped-open doors, loading docks, smoking areas
  2. Tailgating: Follow an employee through a secured door
  3. Social engineering: Use a pretext to convince someone to let you in or escort you
  4. Badge cloning: Use a cloned RFID credential
  5. Technical bypass: Lock picking, under-door tools, door sensor manipulation

Once inside, the tester navigates toward the agreed-upon targets, documenting everything with photographs and notes. Common proof-of-access methods include placing a unique sticker or card in the target area, photographing sensitive documents or screens, or connecting a monitoring device to the network.

Phase 5: Reporting

The report is the deliverable. It documents every vulnerability found, every technique used (successful or not), photographic evidence, and prioritized remediation recommendations. A good physical pentest report tells a story that executives can understand while providing enough technical detail for the security team to fix the issues.

Common Techniques

Tailgating and Piggybacking

Following an authorized person through a secured door. This is the simplest and most commonly successful physical penetration technique. Most employees will hold the door for someone behind them, especially if the tester is carrying boxes, looks like they belong, or simply walks confidently. See our dedicated article on tailgating and piggybacking for more detail.

Badge Cloning

Copying an employee's RFID badge credential to a blank card. For 125kHz proximity cards (which are still extremely common), this requires only brief proximity to the target's badge and a reader/writer that costs under $50. For details on how this works, see our badge cloning article.

Pretexting

Using a fabricated identity or scenario to gain access. Common pretexts include:

  • IT technician: "I'm here to fix the network switch on the third floor." A clipboard, a polo shirt, and confidence go a long way.
  • Delivery driver: Arrive with a package (or a box of donuts). Most organizations have a process for deliveries, but it often involves someone opening a door and pointing you in a direction.
  • New employee: "It's my first day - I'm supposed to meet [real employee name from LinkedIn]. Can you let me in while I wait?"
  • Fire/safety inspector: Official-looking vest, clipboard, camera. Higher risk because impersonating an official may have legal consequences depending on jurisdiction.
  • Prospective tenant/vendor: For multi-tenant buildings, claiming to be visiting another company's suite to gain building access.

Lock Bypass

Physical lock manipulation including picking (using picks and tension wrenches to operate pin tumbler locks), bumping (using a specially cut "bump key"), shimming (defeating padlock shackles), and using under-door tools to operate interior door handles or push bars from the outside.

Door Sensor Manipulation

Many access-controlled doors use request-to-exit (REX) sensors - motion sensors on the interior side that unlock the door when someone approaches to leave. Some REX sensors can be triggered from the exterior using a can of compressed air blown through the gap under the door, or by sliding a thin object under the door to trigger the sensor.

Device Drops

If the tester gains physical access, they may plant devices per the scope agreement: a Raspberry Pi connected to the network for remote access, a USB keylogger on a shared workstation, a rogue WiFi access point, or a cellular-connected device for persistent remote access.

Physical penetration testing without proper authorization is, at best, trespassing and, at worst, breaking and entering. The legal requirements are strict:

Written authorization: A signed letter of authorization from someone with the authority to approve the testing. This must be someone who actually has the legal right to authorize entry - typically a C-level executive, head of security, or facilities director. A department manager may not have the authority to authorize physical testing of the entire building.

Scope definition: The authorization must clearly define what is in scope (which facilities, which areas, which techniques) and what is out of scope (do not attempt entry to the neighboring tenant's suite, do not break windows, do not pick fire doors).

Get-out-of-jail letter: Physical pentesters carry a letter confirming their authorization on their person at all times during testing. If confronted by security or law enforcement, this letter - along with a 24/7 phone number for the authorizing contact - is their protection against arrest and prosecution.

Tenant and landlord considerations: In multi-tenant buildings, the organization may occupy only part of the building. Testing building-wide access controls may require authorization from the building owner or management company, not just the tenant.

Jurisdictional awareness: Laws regarding trespassing, impersonation, lock picking tools, and electronic devices vary by jurisdiction. The pentester needs to understand the local legal framework.

Rules of Engagement

Rules of engagement (ROE) define the boundaries of the test. A well-written ROE covers:

  • Testing window: When testing may occur (business hours only? After hours? Weekends?)
  • Permitted techniques: Which techniques are approved (tailgating yes, lock picking no, badge cloning yes, impersonating law enforcement never)
  • Escalation contacts: Who to call if the tester is confronted, detained, or if an emergency occurs
  • Off-limits areas: Areas that must not be entered regardless of access (data centers with live customer data, hazardous areas, executive protection zones)
  • Evidence handling: What the tester may photograph, what they may take, how evidence is stored and transmitted
  • Abort conditions: Conditions under which the test must stop immediately (police involvement, safety hazard, medical emergency)
  • Knowledge level: Who knows about the test? Are guards informed? Is it a blind test where only the authorizing executive knows?

The knowledge level decision is important. A blind test (where security staff do not know testing is occurring) provides the most realistic assessment but carries higher risk of confrontation. A notified test (where guards know testing is happening but not the specifics) is safer but may skew results.

Reporting and Remediation

The physical pentest report is more than a list of findings. It should include:

Executive summary: High-level results accessible to non-technical leadership. What was the objective? Was it achieved? What are the most critical findings?

Narrative timeline: A chronological account of the testing, describing each attempt, technique, and outcome. This tells the story of the engagement and helps the reader understand the attacker's perspective.

Findings with evidence: Each vulnerability documented with photographs, descriptions of the technique used, the impact of the vulnerability, and the difficulty of exploitation.

Risk ratings: Each finding rated by likelihood and impact. A propped-open fire door to the server room is critical. A missing camera in a low-traffic hallway is informational.

Remediation recommendations: Specific, actionable recommendations for each finding. Not just "improve access control" but "replace HID ProxCard II credentials with DESFire EV3 and migrate reader-controller communication from Wiegand to OSDP v2."

Positive findings: Document what worked well. If guards challenged the tester, if tailgating was prevented, if the alarm system detected an intrusion attempt - these positive findings validate existing controls and encourage the security team.

Conclusion

Physical penetration testing fills a gap that no amount of digital security can cover. An organization can have world-class firewalls and endpoint protection, but if an attacker can walk through the front door, clone a badge, and plug into the network, all of that digital investment is undermined.

Physical pentesting requires a unique blend of technical knowledge (RFID, locks, access control systems), social skills (pretexting, reading people, maintaining composure), and operational discipline (documentation, legal compliance, rules of engagement). It is one of the most challenging and rewarding specializations in the security field.

For those building skills in wireless security and RF technology, the BLEShark Nano provides hands-on experience with BLE 5.0 and WiFi - protocols increasingly relevant to physical security assessment.

Get the BLEShark Nano - $49.99

Physical penetration testing must always be conducted with explicit written authorization. Unauthorized physical intrusion is illegal regardless of intent. This article is for educational purposes only.

Back to blog

Leave a comment