From Pwn to Plan: Turning Physical Exploits Into Upgrades
Shawn
DEF CON 33 · Day 1 · Main Stage
Overview
In this compelling DEF CON presentation, Shawn, a seasoned physical red teamer, challenges the traditional "hack and report" mentality prevalent in security assessments. Titled "From Pwn to Plan: Turning Physical Exploits Into Upgrades," the talk advocates for a more professional, collaborative, and impact-driven approach to physical red teaming. Shawn argues that the ultimate measure of a red team's success isn't merely discovering vulnerabilities, but actively fostering their remediation and ultimately enhancing an organization's security posture.

Key moments
- 0:00 Red team's role: Recommend fixes vs. just vulnerabilities
- 2:00 Adversarial vs. collaborative physical red teaming approaches
- 2:50 Technical skills make a good hacker, not a professional
- 4:30 AI lip-reading: a new, accessible surveillance threat
- 6:00 Understanding the "Spicy Security Spectrum" of TTPs
- 7:00 Test physical security before an adversary does
- 7:50 Start with an adversarial walkthrough, not full red team
From Pwn to Plan: Turning Physical Exploits Into Upgrades
Speakers: Shawn
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=NURO3NgtXUQ
Overview
In this compelling DEF CON presentation, Shawn, a seasoned physical red teamer, challenges the traditional "hack and report" mentality prevalent in security assessments. Titled "From Pwn to Plan: Turning Physical Exploits Into Upgrades," the talk advocates for a more professional, collaborative, and impact-driven approach to physical red teaming. Shawn argues that the ultimate measure of a red team's success isn't merely discovering vulnerabilities, but actively fostering their remediation and ultimately enhancing an organization's security posture.
The core message revolves around shifting from an adversarial "wreck the security team's day" mindset to one that proactively partners with physical security and facilities teams. By helping these often-overlooked departments understand the threats, identify root causes, and implement cost-effective solutions, red teams can transition from being perceived as a critical adversary to an invaluable ally. This approach not only ensures that discovered weaknesses are addressed but also cultivates an environment where security improvements are consistently sought and funded.
Shawn draws upon his 15 years of experience in physical red teaming and counter corporate espionage to highlight the critical gaps that red teams fill between cyber and physical security. He emphasizes that as sophisticated attack TTPs (Tactics, Techniques, and Procedures) become commoditized, organizations must move beyond "security theater" and embrace rigorous, actionable testing. The talk provides a practical roadmap for red teamers to not only execute effective physical assessments but, more importantly, translate their findings into tangible, lasting security upgrades, making their work both fun and profoundly rewarding.
Background
▶ Watch: Red team's role: Recommend fixes vs. just vulnerabilities (0:00)
Shawn begins by outlining two contrasting approaches to physical red teaming. The first, adversarial emulation, often involves a red team "wrecking" the security team's defenses, dropping a list of vulnerabilities, and leaving them defensive and unmotivated to fix issues. This is particularly prevalent in physical security, where practitioners may not be accustomed to being tested. The second, and preferred, approach involves proactively identifying vulnerabilities with the security team, gaining their upfront buy-in, and ultimately helping them prevent incidents and "look good." This collaborative model fosters better security outcomes and creates opportunities for more frequent testing.
A central theme of the talk is the distinction between being a "good hacker" and a "professional hacker." While technical skills like using an underdoor tool or lockpicks are crucial, Shawn asserts that true professionalism in physical red teaming encompasses adversarial thinking, technical prowess, and, critically, the professional skills to drive improvements. Red teams, he explains, are uniquely positioned to fill the gaps between specialized security teams – for instance, identifying how a 4G enabled implant in an ATM network bypasses endpoint detection, or how new AI deep fake vectors could be used for physical surveillance, which traditional AI safety or physical security teams might overlook. He cites an example of readily available technology, like a $20 optical lens for a smartphone combined with AI lip reading, achieving 85% accuracy in spying on meetings through windows from a distance – a capability once exclusive to nation-states. This illustrates the spicy security spectrum, where advanced TTPs continually trickle down to common adversaries.
Shawn underscores the common resistance to physical security testing, largely because physical attacks are less frequent than cyber ones, leading many companies to operate on "security theater" rather than proven effectiveness. He strongly recommends starting with an adversarial walkthrough (or "due diligence walkthrough" for more sensitive environments) before a full covert red team engagement. This overt approach allows security and facilities personnel to go hands-on, understand vulnerabilities firsthand, and see how easily commodity tools can be used to bypass defenses. He warns of the "urban adventure" trend, where individuals film themselves exploiting physical security weaknesses for online content, causing significant reputational damage and regulatory issues for companies.
To initiate a physical red team engagement, Shawn proposes a 10-step process:
- Threat Model: Understand realistic threat actors and their potential tactics.
- Listen: Understand leadership's concerns and align the assessment with their priorities.
- Scope: Define the objectives and boundaries of the test.
- Propose the Engagement: Use the threat model and leadership concerns to gain buy-in.
- Prepare: Handle all administrative tasks, including obtaining a letter of authorization. Shawn stresses the importance of verifying that the authorizing individual truly has the authority, referencing the Coalfire incident as a cautionary tale. He also advises over-communicating with authorized personnel, especially during after-hours operations.
- Practice Tactics: Ensure proficiency with tools before field deployment.
- Execute the Operation: Know when to stop—whether it's a capture-the-flag objective or escalating until detected to test response.
- Immediate Debrief and Deescalation: Crucially, within an hour of the operation, debrief anyone interacted with (e.g., social engineering targets), assuring them no one is in trouble and seeking their perspective on what went wrong and how to improve. This root cause analysis is invaluable.
- Report Findings: Communicate, demonstrate with video, and highlight positive changes.
- Follow Up: Promote positive change, re-test fixes, and showcase the return on security investment. Making security teams "look good" is paramount for continued testing opportunities.
Key Findings
▶ Watch: Technical skills make a good hacker, not a professional (2:50)
Shawn's talk reveals several critical findings about the state of physical security and the role of red teaming:
- Physical Security is Broad and Often Fragmented: Physical security extends far beyond mere office or data center protection, encompassing aspects like mail screening, executive protection, and supply chain security. Organizations often have these responsibilities scattered across different teams, creating blind spots that red teams are uniquely positioned to exploit and highlight.
- Commoditization of Advanced TTPs: Capabilities once exclusive to nation-states, such as advanced surveillance and covert access tools, are now readily available and inexpensive. Shawn demonstrates how technologies like AI lip reading with a smartphone lens or specialized covert cameras (e.g., Goatee 7) can achieve sophisticated surveillance from a distance for minimal cost, making high-tier threats accessible to a wider range of adversaries.
- Prevalence of "Security Theater": Many physical security measures are implemented without effective testing, leading to a false sense of security. The lack of frequent physical attacks compared to cyber incidents means many companies don't know if their physical security actually works, often finding it to be mere security theater.
- Significant Reputational and Regulatory Risk from "Low-Hanging Fruit": Simple, easily learned tactics (like using an underdoor tool or canned air) can be exploited by individuals recording "urban adventure" videos. Such incidents can cause substantial reputational damage and lead to regulatory issues, even if no sensitive data is directly compromised.
- The ESP Key as a Game Changer for Access: The ESP key (an adversary in the middle attack device for Wiegand protocol) is highlighted as an exceptionally easy-to-use tool that bypasses common badge readers by simply replaying captured badge data. Its simplicity and effectiveness make it a critical vulnerability for many access control systems.
- The Power of Storytelling and Demonstration: Red teams possess the unique ability to provide compelling video evidence and narratives of successful exploits. This visual and emotional impact is far more effective in securing budget and driving change than traditional audit reports. Shawn advocates for crafting "fictional intel" stories rooted in realistic threat models to engage leadership.
- Root Cause Analysis is Essential for Fixes: Simply identifying a vulnerability is insufficient. A professional red team must delve into why the vulnerability exists (e.g., too many SOPs for security guards, lack of training, leadership scolding) to provide actionable, long-term solutions rather than just blaming individuals.
- The "Fun and Rewarding" Cycle: Shawn concludes that the more improvements a red team can drive through its testing, the more testing opportunities it will be given. This creates a virtuous cycle where red teamers have more fun, see their work make a tangible impact, and continuously improve organizational security.
Technical Deep Dive
▶ Watch: AI lip-reading: a new, accessible surveillance threat (4:30)
Shawn dives into a range of TTPs employed in physical red teaming, emphasizing their accessibility and effectiveness. He begins with OSINT for Physical, noting that even without on-site reconnaissance, 3D tours or videos can reveal crucial details like badge readers types, door gaps (e.g., a 3-inch gap between double doors indicating a specific tool needed), and potential Wi-Fi access points. Identifying vendors through public records can also aid social engineering. More advanced OSINT includes using tools like PimEyes for facial recognition or leveraging public records like Freedom of Information Act (FOIA) requests, PACER, or RECAP for legal documentation that might contain sensitive company information or employee details.
For Surveillance, Shawn highlights the evolution from traditional PI methods to modern, less conspicuous techniques. Dashcams in parked vehicles (like a Tesla with 360-degree cameras) can continuously record footage. Covert cameras, such as those from Goatee 7, offer 36x optical zoom and extended battery life, disguised as everyday objects like headrests. Modern smartphones (e.g., newer Galaxies) with high optical zoom capabilities (30-50x) combined with external lenses can enable AI lip reading from significant distances, capturing sensitive conversations through windows.
Recon & Access often involves blending in. Shawn notes the ease of acquiring uniforms (e.g., a Verizon shirt), which allowed his team to walk unquestioned into a police station's server room despite Verizon not being a vendor. Renting a bucket truck with a magnetic logo provides unchallenged access to facilities and roofs. The simple act of carrying a ladder or wearing a hard hat can often bypass security entirely, with people holding doors open for perceived maintenance workers.
Traveling with gear requires caution. Shawn advises preparing a letter on company letterhead, explaining the gear's purpose for security testing, along with a business card, to simplify interactions with TSA or border control, especially when carrying suspicious-looking equipment.
The core TTPs for physical access are detailed:
- Underdoor Tool: Effective in the US and many other countries, this tool hooks door handles or crash bars from underneath the door. Shawn suggests using a phone case or a dedicated device to slide it under, making the process easier.
- Canned Air: This exploits passive infrared (PIR) readers that detect changes in ambient temperature. By turning a can of compressed air upside down and spraying the cold gas at the sensor, the sudden temperature drop triggers the motion sensor, opening the door.
- Latch Attacks: These include using shims or the commercial door hook to retract poorly aligned or incorrect latches. The commercial door hook, in particular, can bypass some "decently high security" doors by manipulating an internal metal bar.
- ESP Key (Adversary-in-the-Middle): This is a highly effective attack on Wiegand protocol-based access control systems. The device taps into the clear-text wires between the badge reader and the door controller. When a legitimate badge is swiped, the ESP key captures the digital "ones and zeros." An attacker can then wirelessly replay this exact sequence from their phone, causing the door to open. Shawn emphasizes its ease of use, even for non-technical individuals, thanks to web apps and manuals.
- Double Door Tools: These are designed to pass through the gap between double doors to hit the internal crash bar, allowing entry.
- Hinge Removal: For doors with external hinges, removing the hinge pins can quickly detach the door from its frame. Shawn notes this is destructive and less preferred for maintaining good relationships but is highly effective.
- Key Recreation: High-quality photos of keys (e.g., from clear key boxes in lobbies) can be used to determine the key's bidding, allowing for online ordering, 3D printing, or manual cutting of a functional duplicate.
- Common Keys: Many offices use commonly keyed locks for things like shred bins. Shawn jokes that shred bins are his favorite target because they centralize sensitive documents behind easily picked or commonly keyed locks. He notes that while easy to open, they are often harder to close.
- Lockpicking: Despite its popular image, Shawn rarely uses lockpicking in the field, finding other tools much faster and less conspicuous, except for shred bins.
- Badge Cloning: While Flipper and Prox Mark require close proximity, long range readers can clone badges from 2-3 feet away. Shawn demonstrates a device (essentially a battery and an ESP key) that can be concealed in a bag, passively scanning and broadcasting multiple badges to a phone. These captured badge IDs can then be cloned to another physical badge or used for replay attacks.
For advanced reconnaissance, thermal and IR night vision cameras can be used. Shawn primarily uses IR night vision to detect hidden cameras, which often emit IR flood lights invisible to the naked eye. He references resources like Hacker Warehouse, Red Team Tools, and the Physical Security Village for acquiring these tools.
Demo / Proof of Concept
▶ Watch: Test physical security before an adversary does (7:00)
Shawn provided a live demonstration of a long range reader for badge cloning. He held up a device, resembling a small antenna connected to a battery pack, and explained that it's essentially a battery combined with an ESP key. He specifically left the "beep" sound enabled on the device so the audience could hear it in action. As he moved the reader around, it emitted beeps, indicating it was successfully detecting and reading badges from a distance of approximately 2-3 feet, even through clothing or bags. He highlighted that in a covert operation, the beep would be disabled, allowing an attacker to walk through a lobby or crowded area, silently collecting multiple badge IDs. These captured IDs are broadcast wirelessly to a phone, where they can be replayed to open doors or, with additional steps, written to a physical clone badge using tools like a ProxMark or Flipper.
Beyond the live demo, Shawn recounted a powerful proof-of-concept story involving a company that sent high-quality webcams to all employees as a work-from-home perk. Recognizing this as a potential attack vector, his team acquired the same off-the-shelf webcam model and implanted it with a cheap Alibaba 4G SIM card configured to activate and call his cell phone upon voice detection. Instead of sending these bugged devices to employees' homes (which would be unethical and illegal), they used public data like political donations (where high-ranking individuals' home addresses and titles are often listed) and Wigle/War driving to identify executive residences.
For the actual demonstration, they sent un-implanted webcams to the VPs, who plugged them in and used them. Shawn's team then showed the VPs network logs confirming the devices were online and presented a detailed narrative: "We didn't bug you, but we could have. This is what it would have looked like." This approach successfully demonstrated the vulnerability without creating actual risk or ruffling feathers, proving that effective proof-of-concept doesn't always require full-scale, risky execution.
Other tools mentioned, like the underdoor tool and double door tools, were referenced as being available for hands-on interaction at the Physical Security Village downstairs, implying they are common and easily demonstrated.
Defensive Implications
▶ Watch: Start with an adversarial walkthrough, not full red team (7:50)
Shawn stresses that providing actionable mitigation strategies is as crucial as identifying vulnerabilities. He encourages red teams to think through cost-effective solutions, recognizing that physical security teams often have limited budgets.
For double door tools and latch attacks, basic physical hardening can be effective. Installing a central astragal (a piece of metal covering the gap between doors) or a latch guard prevents tools from reaching the crash bar or latch. Alternatively, a security officer could deter attacks, but Shawn notes the significant cost of 24/7 personnel (potentially $250,000 annually per location) makes physical solutions more appealing. Alarms that trigger if a door is pushed without internal motion can also help.
To counter the underdoor tool, a mechanical door sweep that engages and drops down when the door closes can block access, though these are expensive, require maintenance, and may fail if the building shifts. A cheaper, ADA-compliant alternative is a door shroud, a $125 piece of metal that covers the gap, preventing the tool from being inserted. Shawn mentions hotels adopting these widely.
Mitigating the ESP key is more complex. Moving external badge readers inside the glass eliminates direct physical access to the wiring. Upgrading to OSDP (Open Supervised Device Protocol) encrypts data between the reader and controller, but this is "incredibly expensive" and requires pulling out all wiring and switching hardware. A more pragmatic recommendation for less critical environments is to ensure the reader's tamper switch is enabled and that alarms generated from it are prioritized by security operations.
For vulnerabilities stemming from poorly aligned latches (exploitable by shims or other latch attacks), Shawn advocates for empowering and training facilities and local security personnel. He suggests providing them with $25 worth of tools and teaching them how to conduct regular door audits every three months. This "teach a man to fish" approach allows them to proactively identify and ticket misaligned doors or non-functional dead latches caused by building shifts, addressing low-hanging fruit without needing an expensive red team.
To address the canned air attack on passive infrared readers, more sophisticated active infrared sensors can be configured to only trigger if motion is moving towards the door and is warmer than ambient air, ignoring cold air moving away. In Europe, door release buttons are common and prevent this attack, unless placed directly next to a large gap where they can be reached.
Badge cloning is a persistent challenge. While high-security badges offer some protection, new exploits emerge regularly. Cost-effective mitigations include policy changes like asking employees to remove and store badges in backpacks when leaving the office to prevent long-range cloning, and general security awareness training. However, Shawn cautions against the massive undertaking and cost of re-badging thousands of employees for a vulnerability that may soon have a new bypass.
For hinge pin removal, internal hinges are ideal. If external hinges are unavoidable, security screws can make it harder to remove the pins when the door is closed and locked.
Window surveillance can be mitigated with good privacy film on ground-floor or public-facing windows, preventing visual observation of screens or keyboards. For more advanced threats like laser microphones, multiple panes of glass or specialized technology that pumps white noise or even voice randomization into the glass can defeat them, as newer laser mics can filter out simple white noise.
Finally, Shawn addresses the root cause of social engineering vulnerabilities. Using the example of a security guard granting a temporary badge due to a lost ID story, he explains that simply reporting "security officer susceptible to impersonation" is unhelpful. Instead, a red team should debrief the guard to understand their challenges—e.g., too many SOPs, being scolded by leadership for strictness. The report should then recommend fixing these systemic issues, providing the security manager with a clear roadmap to empower guards rather than just blaming them. This approach leads to more effective, sustainable security improvements and builds goodwill. Shawn also suggests integrating cyber hygiene recommendations, such as advising employees on political donations and general privacy practices, as part of a comprehensive assessment.
Key Takeaways
- Professional Red Teaming Requires Collaboration and Action: Beyond technical exploitation, a professional physical red team focuses on building relationships with security and facilities teams, conducting thorough root cause analysis, and providing actionable, cost-effective recommendations to ensure vulnerabilities are actually fixed.
- Commoditized Threats Demand Proactive Testing: Advanced physical TTPs, once exclusive to nation-states, are increasingly accessible and cheap (e.g., AI lip-reading, ESP keys). Organizations must move beyond "security theater" and conduct regular, realistic physical assessments to stay ahead of these evolving threats.
- Authorization and Debriefing are Non-Negotiable: Strict adherence to a letter of authorization and immediate, empathetic debriefing with all involved parties post-operation are critical for legal safety, ethical conduct, and fostering a positive, improvement-oriented security culture.
- Leverage Demonstrations and Storytelling for Impact: Video evidence, live demonstrations, and compelling narratives (even using "fictional intel" based on real threats) are powerful tools to convey the severity of vulnerabilities to leadership, secure budget, and drive actual security improvements more effectively than written reports alone.
- Focus on Root Causes, Not Just Symptoms: Red team reports should delve into why vulnerabilities exist, such as fragmented teams, inadequate training, or conflicting policies (e.g., too many SOPs for security guards). Providing solutions that address these underlying issues empowers security teams and leads to more sustainable fixes.
- The Virtuous Cycle of Improvement: By consistently delivering tangible security upgrades, red teams earn trust and demonstrate value, leading to more opportunities for testing. This creates a positive feedback loop where testing is fun, improvements are rewarding, and overall organizational security continuously strengthens.
About the Speaker(s)
Shawn is a highly experienced security professional with approximately 15 years in the field of physical red teaming. His expertise extends beyond traditional penetration testing to include investigations and counter corporate espionage, where he actively tracks and counters the tactics of corporate spies. Throughout his career, Shawn has worked both as a consultant and internally, building and leading red teams for various companies, which has provided him with a broad perspective on effective security strategies and the challenges organizations face. His work involves continuously learning new adversarial tactics to stay ahead of evolving threats.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent physical red team practitioner sharing real operational knowledge with genuine field credibility. The collaborative-over-adversarial framing is a useful professional reframe, and the TTP coverage is solid, but none of this is new to anyone who's been to Physical Security Village or read the standard literature. Good conference content, not a landmark talk.
Heather Calloway (CISO) — SOLID
A competent physical red team practitioner making a genuinely useful argument — that red teamers should drive remediation, not just demonstrate access. The TTP coverage is thorough and the collaborative framing is the right message for its audience. But this talk lives entirely at the practitioner layer and never surfaces the institutional or governance failures that make physical security the persistent afterthought it is.