Physical penetration testing: tailgating, badge/RFID cloning, lock bypass, pretexting for on-site access, USB drop, and camera/alarm blind-spot mapping.
60 checks · progress and notes saved in your browser
Establish the legal, ethical, and physical-safety foundation for an authorized on-site engagement before any active technique is attempted: written authorization, force boundaries, de-confliction, and emergency-stop procedures.
Build a site-access map before any active technique: passive OSINT first, then a light active perimeter survey, followed by camera and alarm blind-spot mapping to plan the entry route.
Execute the authorized technique set against ranked entry points — tailgating, badge/RFID cloning, and lock bypass — starting with the highest-value, lowest-exposure doors identified during recon.
Assess whether human controls — front-desk verification, staff vigilance, and endpoint hygiene — actually stop an intruder using an in-person pretext or a dropped media device.
Assess whether discarded materials and unattended workspaces leak sensitive data that never required defeating an access-control system at all.
Execute the pre-agreed proof-of-impact step only after successful access, capture defensible evidence, and close out the engagement safely with a clean chain of custody.