| name | performing-physical-intrusion-assessment |
| description | Conduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls. |
| domain | cybersecurity |
| subdomain | red-teaming |
| tags | ["physical-security","red-team","tailgating","badge-cloning","lock-picking","rfid","physical-pentest"] |
| version | 1.0 |
| author | mahipal |
| license | Apache-2.0 |
| d3fend_techniques | ["Platform Hardening","Hardware Component Inventory","Electromagnetic Radiation Hardening","RF Shielding","Asset Inventory"] |
| nist_csf | ["ID.RA-01","GV.OV-02","DE.AE-07"] |
Performing Physical Intrusion Assessment
Overview
Physical intrusion assessment evaluates an organization's physical security controls by attempting to gain unauthorized access to facilities, server rooms, and restricted areas. This includes tailgating employees, cloning RFID access badges, bypassing locks, deploying rogue network devices, and testing security guard procedures. Physical security testing is a critical component of full-scope red team engagements, as it often provides the most direct path to network access. MITRE ATT&CK maps physical access techniques under T1200 (Hardware Additions) and T1091 (Replication Through Removable Media).
When to Use
- When conducting security assessments that involve performing physical intrusion assessment
- When following incident response procedures for related security events
- When performing scheduled security testing or auditing activities
- When validating security controls through hands-on testing
Most Often Missed & How to Confirm
- Tailgating + pretext is the highest-yield, most-skipped vector: follow staff through badge doors during smoke breaks/deliveries with a plausible pretext (vendor, new hire, courier).
- Badge cloning: capture HID/iCLASS with a Proxmark3 or long-range reader from a few feet, then replay; many sites never rotate card formats.
- Door/lock bypass: under-door tools, latch slipping (loiding), REX motion-sensor triggering, and elevator/stairwell access.
- Network footholds inside: exposed jacks in lobbies/conference rooms, unattended kiosks, and perimeter Wi-Fi.
- Confirm with evidence: reach a live network jack (obtain a DHCP lease/internal IP), photograph a sensitive area, or plant a benign drop box that calls back. Don't conclude "secure" until tailgating, badge clone, lock bypass, and at least one social pretext have been attempted at each entrance and after-hours.
Prerequisites
- Signed authorization letter (carry at all times during assessment)
- Emergency contact for client security team (24/7)
- Get-out-of-jail letter signed by executive authority
- Physical security testing toolkit
- Body camera or documentation equipment
- Disguise/cover identity materials (uniform, badge, clipboard)
MITRE ATT&CK Mapping
| Technique ID | Name | Tactic |
|---|
| T1200 | Hardware Additions | Initial Access |
| T1091 |