Skill: Physical Security Testing

SkillCloud & infra

Physical penetration testing covering mechanical lock bypass (pin-tubular/wafer), RFID/NFC badge cloning (Proxmark3/ESP-RFID-Tool/Walrus), HID iCLASS/Mifare duplication, drop box deployment (LAN Turtle/Packet Squirrel), USB weapons (Rubber Ducky/Bash Bunny), hidden camera placement, and on-site engagement operations including tailgating pretext preparation and physical-docs legal templates.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Skill: Physical Security Testing skill

What this skill tells your AI

The instructions your AI receives, as published by brucesongs/kali-claw in skills/physical-security-testing/SKILL.md and read by ahel’s review.

Supplementary Files:

  • payloads.md — Legal/scope templates (TrustedSec physical-docs), lock picking payloads (pin-tubular/wafer/dimple/bump), bypass tool usage (shove knife, under-door, crash bar tape), Proxmark3/ESP-RFID-Tool/Walrus badge cloning, Mifare/HID iCLASS high-freq duplication, LAN Turtle/Packet Squirrel drop boxes, Rubber Ducky/Bash Bunny USB weapon payloads, hidden camera concealment, on-site engagement ops scripts, tailgating pretext prep, exit & evidence handling, and a quick-reference cheat sheet
  • test-cases.md — 12 structured test cases (legal scope review, pin-tumbler pick, RFID 125kHz clone, Mifare Classic clone, HID iCLASS decode, LAN Turtle drop box deploy, Rubber Ducky payload, network implant concealment, hidden camera placement, on-site recon, tailgating pretext, exit/evidence) with severity levels and summary tables
  • guides/physical-security-testing-playbook.md — End-to-end on-site engagement playbook (pre-flight authorization, 5-phase workflow, entry-vector decision matrix, guard/employee interaction rules, evidence chain-of-custody, integration with adjacent skills)

Summary

Physical security testing covers the on-site operations that gain physical access to a target facility — lock picking, badge cloning, drop-box deployment, USB-weapon delivery, hidden-camera placement, and the social engineering that gets a human through the door. This skill is the physical-access complement to radio and firmware skills: where bluetooth-rfid-nfc analyzes the wireless protocol and hardware-security analyzes chips and firmware, this skill asks "how do I get through the door?"

Tools: Proxmark3, ESP-RFID-Tool, Walrus, Hak5 LAN Turtle, Hak5 Packet Squirrel, USB Rubber Ducky, Bash Bunny, P4wnP1, lock pick set, bump keys, under-door tool, shove knife, hidden cameras.

Domain: physical

MITRE ATT&CK: TA0001-Initial Access (physical), T1192-Hardware Additions, T1366-Physical Security Bypass

Description

Physical penetration testing across the full on-site engagement lifecycle: legal scope and authorization (TrustedSec physical-docs templates), pre-engagement reconnaissance (building layout, badge vendor, guard rotation), entry-vector selection (locks vs badges vs USB vs implants vs social), mechanical bypass (pin-tubular, tubular, wafer, dimple; bump keys; shove knife; under-door tool; crash bar tape), radio credential cloning (125 kHz HID Prox/Indala via Proxmark3/ESP-RFID-Tool/Walrus; 13.56 MHz Mifare Classic/DESFire and HID iCLASS via Proxmark3), drop-box deployment (LAN Turtle, Packet Squirrel, Pi Zero W implants) for persistent network access once inside, USB-weapon delivery (Rubber Ducky, Bash Bunny, P4wnP1) for attacker-controlled keystroke injection, hidden camera/audio placement for situational awareness during multi-day engagements, and the social engineering pretexts that turn a locked door into an open one.

This is the access side of the physical+radio stack. Where bluetooth-rfid-nfc analyzes BLE/RFID/NFC protocols and sdr-rf-attack covers broad RF replay, this skill focuses on the operational question: "what credential do I need, how do I clone it, and how do I use it to enter the facility?" Where hardware-security looks at JTAG/UART/firmware extraction, this skill looks at the doors, locks, and readers those devices physically protect.

Difference from bluetooth-rfid-nfc: That skill covers BLE/RFID/NFC radio analysis (sniffing, protocol fuzzing, decryption). This skill brings the physical-access perspective — cloning a 125 kHz HID Prox card to bypass a door reader, duping an HID iCLASS credential for after-hours entry, and the on-site operational discipline (concealment, guard avoidance, evidence handling) that radio work alone doesn't address.

Difference from hardware-security: That skill targets JTAG/UART/SPI/I2C and firmware extraction. This skill targets the perimeter — locks, badges, drop boxes, USB weapons — the access paths that get an operator in front of the hardware in the first place.

Difference from social-engineering: That skill covers human manipulation (phishing, vishing, pretext). This skill includes physical-world social engineering — tailgating pretexts, badge impersonation, delivery-driver pretexts — but only as one of five entry vectors. Mechanical and electronic bypass are the primary focus.

Difference from sdr-rf-attack: That skill covers broad RF replay (garage doors, keyfobs, alarms). This skill covers badge cloning as an on-site access operation, including reader reconnaissance, credential capture at the reader, and the legal/operational framing that pure RF replay doesn't require.

Use Cases

  • Authorized facility penetration test: Execute a scoped physical pentest — attempt badge cloning, lock bypass, and drop-box deployment against the client's headquarters or data center, documenting every access path and reporting remediation.
  • Badge system audit (defensive): Audit a deployed badge system for cloning susceptibility — test HID Prox (no authentication, trivially cloned), Mifare Classic (CRYPTO1 broken), and report upgrade paths to Mifare DESFire EV2/EV3 or HID iCLASS SE.
  • Drop-box deployment for red team: Once physical access is achieved, deploy a LAN Turtle or Packet Squirrel inside the target facility to establish persistent VPN pivot for the rest of the red team engagement.
  • USB weapon delivery: Deliver a Rubber Ducky or Bash Bunny payload to an unattended workstation inside the target facility (e.g., extraction of credentials or beacon deployment) during a physical engagement.
  • DEF CON / Red Team physical CTF: Practice lock picking, badge cloning, and on-site recon in a competition environment — Schuyler Towne content, DEF CON Physical Security Village, Red Team Village events.
  • Insider-threat physical simulation: With authorization, test whether an attacker with a single insider's badge (cloned or borrowed) can reach a sensitive area (server room, executive floor) — measure time-to-detection.
  • Building security assessment: Evaluate the physical controls of a new facility before the client moves in — lock types, reader placement, camera coverage, guard patrol coverage, CPTED (Crime Prevention Through Environmental Design) review.
  • After-hours access testing: Verify whether badge readers enforce time-of-day restrictions, whether door-forced-open alarms fire correctly, and whether guard response meets the contracted SLA.
  • Hidden camera detection sweep (defensive): TSCM (Technical Surveillance Counter-Measures) — sweep a client's executive suite or SCIF for hidden cameras, audio bugs, and unauthorized network implants.
  • Executive protection rehearsal: Pre-engagement recon of a venue before an executive event — map entry points, identify choke points, document reader vendors and camera coverage.

Core Tools

Lock Bypass & Mechanical

ToolPurposeNotes
Lock pick set (Peterson, SouthOrd, Sparrows)Pin-tumbler picking with hooks, rakes, and tension wrenchesStandard 0.025" or 0.018" thickness; transparent practice locks first, then progressively harder belt ranks
Bump keysPin-tumbler bumping — cut to depth 9, instant open on many Kwikset/SchlageBumping leaves no tool marks distinguishable from normal wear; legal status varies by jurisdiction
Tubular lock pick (Lishi, tubular bump)Tubular cam locks (vending machines, kiosks, some bike locks)7-pin and 8-pin variants; Lishi tools decode-and-pick in one motion
Wafer lock pick (jigglers, tryout keys)Wafer locks (file cabinets, desks, some vehicle locks)Pre-cut jiggler sets work against low-quality wafer locks in seconds
Dimple lock pick (Lishi dimple)Dimple locks (Kaba, Mul-T-Lock, Assa) — high-security but Lishi 2-in-1 reads bittingLishi tools are restricted in some jurisdictions; verify before travel
Shove knife (under-door bypass)Slip the latch of an inward-opening door from outsideWorks on commercial door hardware with flat latch bolts; fails on anti-shim deadlatches
Under-door tool (copper wire + tape)Pull the inside handle of an outward-opening door from outside via the gap under the doorThe "Hollywood" tool — widely seen in red team content; works on many commercial lever handles
Crash bar tape / filmDefeat panic-exit bars by sliding tape over the latchWorks on certain Von Duprin and similar exit devices; newer hardware has anti-tape shields

RFID / NFC Cloning

ToolPurposeCommand / Notes
Proxmark3Standalone RFID/NFC analysis, sniffing, and cloning (125 kHz + 13.56 MHz)hf search, lf hid read, lf hid sim, hf mf clone, hf 14a sim
ESP-RFID-Tool (ESP32-based)Portable 125 kHz HID Prox/Indala reader and clonerGitHub trending (572+); smaller and cheaper than Proxmark3; ideal for on-site 125 kHz work
Walrus (TeamWalrus, iOS/Android)Smartphone-based NFC cloning for Mifare Classic/DESFire, HID iCLASS via add-on hardwareApp store install; the consumer/enthusiast entry point; full keys required for encrypted sectors
Flipper ZeroMulti-tool with 125 kHz RFID, NFC, sub-1GHz, IRPopular entry tool; rfid and nfc apps; less capable than Proxmark3 for raw protocol work
TMD-5S / ACR122UUSB NFC reader for Mifare Classic nested-key attacksACR122U + mfoc recovers keys in minutes for default-key cards
HackRF OneBroad SDR for badge replay at 313 MHz/433 MHz gates and keyfobsUse sparingly for badge work; Proxmark3 is purpose-built; see sdr-rf-attack skill for SDR fundamentals

Drop Boxes & Network Implants

ToolPurposeDeployment Notes
Hak5 LAN TurtleUSB-shaped network implant with auto-SSH backdoor, packet capture, DNS spoofingPlugs into an internal PC or network jack; paired with a Cloud C2 for out-of-band C2
Hak5 Packet SquirrelEthernet inline implant with payloads (VPN, nmap, tcpdump)Inline between a device and switch — harder to spot than a Turtle; same Cloud C2
Bash BunnyUSB attack platform with keystroke injection, network, storage modesMulti-vector in a single device; see USB weapons section
Raspberry Pi Zero WDIY implant — small, cheap, WiFi-enabledSSH reverse tunnel over the target's WiFi; conceal in a wall plate or cable bundle
WiFi PineappleWireless assessment / rogue AP deploymentUse only after physical entry; see wireless-pentest skill for protocol detail
Plugable USB-Ethernet adapterConcealment-friendly form factor for a USB-Ethernet implantHide the implant inside a "spare cable adapter" the client won't disturb

USB Weapons

ToolPurposePayload Format
USB Rubber DuckyKeystroke injection — DuckyScriptinject.bin from duckencode; examples: reverse shell, exfil, sticky-keys bypass
Bash BunnyKeystroke + network + storage attack in oneBunnyScript payloads; can impersonate Ethernet adapter for in-line network attack
P4wnP1 (Pi Zero W)DIY Rubber Ducky + BadUSB on a $10 boardP4wnP1 A.L.O.A. firmware; flexible HID/network/storage attacks
Evilducker / DigisparkSub-$5 HID injection (ATtiny85)Smaller and less capable than Ducky; useful for cheap-and-cheerful payloads

Cameras / Audio / Concealment

ToolPurposeNotes
Zetta / Blink / Wyze camerasCompact hidden cameras for on-site situational awarenessPre-engagement recon: log guard rounds; never deploy without explicit scope
Custom Pi Zero cameraDIY concealable camera (Pi Zero W + Pi Camera V2)Battery + cellular uplink for off-grid monitoring; conceal in office clutter
Audio recorder / pen recorderCapture conversations for after-action reportingLegal status varies — one-party vs two-party consent states; check before recording
Cable manipulator / fake outletConcealment for implants and camerasCommercial products exist; DIY versions hide implants in wall plates, surge protectors, clock radios

Recon & OSINT (Physical)

ToolPurposeNotes
Google Street View / satellitePre-engagement building layout, entry points, camera placementVerify on-site; satellite imagery ages
LinkedIn / employee badge photosIdentify badge vendor (HID, Lenel, etc.) from employee photosOften visible at conferences or in office tour videos
Job postingsIdentify badge system vendor ("experience with Lenel OnGuard")Combined with LinkedIn photos, gives the reader vendor pre-engagement
Public building permitsConfirm security system installers and recent camera upgradesCounty/city records; sometimes free
Walk-by reconOn-site: observe reader vendor, badge design, guard patrol cadence, camera coverageLegal grey area — stay on public property; never enter without authorization

Methodology

On-Site Engagement Six-Phase Process

Phase 1            Phase 2          Phase 3              Phase 4          Phase 5            Phase 6
Scope & Legal  →   Pre-Engagement →  Entry Vector      →  Execution &   →  On-Site Ops &   →  Exit &
                   Recon            Selection              Access           Persistence          Evidence
   │                  │                  │                  │                  │                  │
   ▼                  ▼                  ▼                  ▼                  ▼                  ▼
Contract, ROE,   Building map,    Locks / badges /   Clone badge or    Deploy drop      Reverse tools
get-out-of-jail  badge vendor,    USB / implants /   pick lock;        box, implant      through flow,
card, ID badges  guard cadence,   social — pick     document time     USB, hidden       chain-of-custody
for all ops      camera coverage  lowest-risk        of entry          cameras; pivots   on evidence,
                                                                                           report

Phase 1: Scope & Legal (NO EXCEPTIONS)

Physical pentest is the highest-risk skill in this workspace. A misread scope clause is a felony. Get this in writing first, always.

  • Engagement contract: signed scope, dates, target addresses, prohibited areas (HR, executive residences, data center colocation cages owned by a third party).
  • Authorization letter ("get-out-of-jail card"): client contact name, 24/7 phone, scope summary, engagement dates — carry on every operator at all times; produce immediately if confronted by security or law enforcement.
  • Rules of engagement (ROE): prohibited actions (no breaking glass, no picking locks on emergency exits, no social engineering against minors, no decoy devices left after engagement).
  • TrustedSec physical-docs templates: use the community-maintained templates as a baseline; have legal counsel review and customize.
  • Local law review: lock pick possession is regulated (see "Legal by jurisdiction" in payloads.md). The UK, Japan, and several US states (California, Nevada) restrict possession without a credential.
  • Insurance: verify the engagement is covered by both the client's and the consultancy's insurance.

Phase 2: Pre-Engagement Recon

Passive OSINT first, then a walk-by recon pass before any active operation.

  • Building layout: satellite imagery, Google Street View, public floor plans (real-estate listings, building permits).
  • Badge vendor identification: LinkedIn photos, conference videos, job postings ("experience with Lenel OnGuard / HID Origo / AMAG Symmetry").
  • Reader vendor on-site: walk-by recon — HID iCLASS SE readers are blue/white, Symmetry readers are grey, Lenel OnGuard readers are typically black with a side LED.
  • Camera coverage: identify camera vendors (Axis, Hikvision, Dahua), placement (entry, exits, loading dock), and blind spots.
  • Guard patrol cadence: walk-by at multiple times of day; log guard rounds; note shift changes.
  • Employee behavior: badge-tap behavior (do they tailgate?), smoking break patterns, shift change at reception.
  • After-hours activity: cleaning crews, HVAC contractors, IT staff on late shifts — these are pretexts for after-hours entry.

Phase 3: Entry Vector Selection

Score each entry vector against probability of success, time-to-entry, detectability, and reversibility. Pick the lowest-risk path.

Entry VectorProbability (typical)Time to EntryDetectabilityReversibility
Tailgating (social)HIGH (most orgs)<1 minLOW (if guard absent)N/A — no artifact
Badge clone (125 kHz HID Prox)HIGH (if deployed)<30 sLOW (reader log shows valid badge)Badge returns to owner undetected
Badge clone (Mifare Classic)HIGH (CRYPTO1 broken)<5 minLOWSame as above
Badge clone (HID iCLASS)MEDIUM (needs key)5-30 minMEDIUM (cloning requires sniffing)Reader log may show duplicate tap
Lock pick (pin-tumbler, commercial)HIGH10-60 sLOW (no marks)No artifact
Lock pick (high-security, Medeco/Assa)LOWminutes-hoursMEDIUM (tool marks)May leave forensic evidence
USB weapon (unattended workstation)HIGH (if observed)<10 sHIGH (USB device log)Exfil artifacts may persist
Drop-box deploy (LAN Turtle)MEDIUM (needs network jack)30 sMEDIUM (network admins may notice)Implant retrievable if undetected
Crash bar / shove knifeMEDIUM (hardware-specific)<10 sLOWNo artifact

Rule: try the lowest-detectability, lowest-reversibility-risk vector first. A successful badge clone leaves the badge holder unaware; a successful lock pick leaves no evidence; a successful tailgate leaves no artifact at all. USB weapons and drop boxes are highest-impact but highest-detectability — reserve for after entry is already achieved.

Phase 4: Execution & Access

Document everything: timestamps, before/after photos, any deviation from the plan. Wear body cameras (with consent of the client) for after-action review.

  • Badge clone execution: capture the credential (sniff or borrow), clone to a writable card or Proxmark3 simulation mode, walk to the door, tap, enter.
  • Lock picking execution: approach the door outside camera coverage (if possible); pick; enter; re-lock from inside if available; document.
  • Tailgating execution: stage at a smoking area or loading dock; wait for an employee with a badge; follow at conversational distance; thank them at the door ("thanks — left my badge in the car"); produce badge / pretend to tap if challenged.
  • USB weapon execution: locate unattended workstation (after-hours); insert Bash Bunny / Rubber Ducky; wait for payload completion (LED indicator); remove; leave no other artifacts.

Phase 5: On-Site Ops & Persistence

Once inside, the goal shifts to situational awareness, lateral movement, and persistent access.

  • Situational awareness: deploy a hidden camera at a choke point (break room, elevator lobby) to track guard rounds for the duration of the engagement.
  • Drop-box deployment: plug a LAN Turtle into an unattended PC's USB port or a wall network jack; verify Cloud C2 check-in before leaving the area.
  • Network implant concealment: place a Pi Zero W behind a server rack, inside a cable tray, or inside a wall plate; verify reverse-SSH tunnel back to the consultancy.
  • Lateral movement: from the drop box, scan the internal network, harvest credentials, pivot to higher-value targets (see post-exploitation, ad-ldap-attack skills).
  • Anti-forensics: minimize footprint; clear logs only with client authorization; document what was changed for the report.

Phase 6: Exit & Evidence

The exit is as operationally sensitive as the entry. A botched exit burns the engagement.

  • Reverse the tools: re-lock picked doors, return cloned badges to their storage location, retrieve hidden cameras and drop boxes, remove USB weapons.
  • Reverse the persistence: tear down reverse-SSH tunnels, clear Cloud C2 entries, sanitize implanted devices.
  • Evidence chain-of-custody: every action timestamped; every artifact (cloned badge, picked lock, deployed implant) photographed before-and-after; chain-of-custody form completed.
  • Hand-off: deliver the report with timeline, evidence pack, and remediation recommendations. Keep the evidence pack for the contracted retention period; then securely destroy (shred -uvz for digital; physical destruction for cloned badges).

Quick Selection Guide

ScenarioPrimary ApproachAlternative
First-time physical pentest of an office buildingTailgating pretext + lock picking fallbackBadge clone if vendor is HID Prox
Test a deployed badge system for cloning susceptibilityProxmark3 lf search for 125 kHz; hf search for 13.56 MHzESP-RFID-Tool for portable 125 kHz
Clone an HID Prox card observed at a distanceESP-RFID-Tool / Walrus / Proxmark3 lf hid read then lf hid simBorrow and re-badge
Clone a Mifare Classic cardProxmark3 hf mf autopwn or ACR122U + mfocWalrus app with full keys
Establish persistent network access insideLAN Turtle (USB) or Packet Squirrel (Ethernet)Pi Zero W with reverse-SSH
Deliver a quick exfil payload to an unattended PCUSB Rubber Ducky with reverse-shell payloadBash Bunny in HID mode
Open a commercial inward-opening door from outsideShove knife (if flat latch)Under-door tool (if lever handle)
Open a commercial outward-opening door from outsideUnder-door toolPretext a fire alarm (HIGH risk — likely out of scope)
Recon a building before engagementLinkedIn + satellite imagery + walk-byPublic permits and contractor listings
Hide a long-term implantWall plate concealment / fake surge protectorDrop ceiling tile (high discovery risk)
Audit own facility for cloning susceptibilityDefensive badge audit (payloads.md §13)Hire an external physical pentest consultancy
TSCM sweep for hidden camerasRF detector + thermal camera + physical inspectionNetwork scan for known camera MAC OUI

Defense Perspective

Shortened here. Read the whole file on GitHub.

Signals

GitHub stars
71
Forks
18
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
physical-security-testing
Source
github.com/brucesongs/kali-claw