Service 03 · Offensive Security

Physical Red
Teaming

Locks, badges, and people. We test the physical path into your building — tailgating, badge cloning, lock bypass, and on-site social engineering.

Request this engagement
Coverage

What we test

01

Tailgating & Piggybacking

02

Badge Cloning & RFID Bypass

03

Lock Bypass & Physical Entry

04

On-Site Social Engineering

05

Dumpster Diving & Information Leakage

How it runs

Workflow

01

Scope & Rules of Engagement

Targets, boundaries, and safety rules defined in writing — including a signed authorization letter carried on-site for the duration.

02

Reconnaissance

Site layout, badge systems, staff patterns, and the blind spots a real intruder would find first.

03

Pretext Development

Building the cover story and access approach the attempt will run on.

04

Physical Entry Attempt

Attempting real entry through the weakest point found — the same way a motivated intruder would.

05

Escalation

Once inside, testing how far the access actually reaches — server rooms, restricted areas, cash handling.

06

Reporting

How each weakness was first spotted, how it was abused, and what it exposed — narrated with photo and video evidence.

07

Retest

Verifying the fixes actually hold against the same approach.

Deliverables

What you get

  • Full report — planning, methodology, and objectives
  • How each weakness was first identified
  • How access was gained and abused, narrated step-by-step
  • Remediation guidance mapped to each control that failed
  • One retest to confirm the fixes hold
Every finding is documented
PhotoEvery breach point, on camera
VideoFull intrusion walkthrough, where authorized
LogTimestamped record matching the report
Who it's for

You need this if

Offices & Corporate HQ
Data Centers
iGaming & Casino Floors
Retail
Warehouses & Logistics

…or any organization with a physical location worth protecting — cash handling, server rooms, or restricted areas.

Rigor

Standards

Engagements follow PTES physical-testing methodology and are benchmarked against ISO/IEC 27001 Annex A physical security controls.

PTES ISO 27001 Annex A
Questions

FAQ

Is this legal?

Yes. Every engagement carries a signed authorization letter naming the testers, scope, and dates, held on-site for the duration.

Could your testers get mistaken for real intruders?

That risk is part of why the authorization letter exists. Testers carry it at all times, and a point of contact on your side is on standby to de-escalate if anyone is stopped.

What's off-limits?

Agreed in scope beforehand — always excluding force, damage to property, and anything posing a genuine safety risk.

Do you test our staff too?

Yes, by default. On-site social engineering — pretexting, tailgating cooperation — is part of the assessment unless you scope it out.

Get in touch

Find the door you didn't know was open.

Tell us about your site and what you're worried about. We'll come back with a scope, a timeline, and a quote.

Request engagement
Tbilisi, Georgia/ Response within 1 business day/ [email protected]
Often paired with

Go deeper