Behind Closed Doors: Physical Red Team Tactics - Firat Acar & Moritz Thomas

Firat Acar (Red Teamer · Inviza), Moritz Thomas (Red Teamer · Invizo)

Disobey 2026 · Main Stage

Overview

In an era where cyber threats dominate headlines, the foundational layer of physical security often receives less attention than it deserves. This talk, "Behind Closed Doors: Physical Red Team Tactics," presented by seasoned red teamers Firat Acar and Moritz Thomas from the European cybersecurity consultancy Invizo, delves into the critical, often overlooked, realm of physical infiltration. The speakers share a series of "war stories" from their real-world red team engagements, illustrating how sophisticated organizations can be compromised through surprisingly low-tech means, primarily social engineering, combined with clever technical exploits.

Watch on YouTube

Visual summary for Behind Closed Doors: Physical Red Team Tactics - Firat Acar & Moritz Thomas by Firat Acar, Moritz Thomas
Visual summary for Behind Closed Doors: Physical Red Team Tactics - Firat Acar & Moritz Thomas by Firat Acar, Moritz Thomas

Key moments

  1. 0:00 Welcome and talk agenda overview
  2. 2:30 Key differences: pentesting vs. red teaming
  3. 3:30 Phases of a physical red team assessment
  4. 4:30 Understanding Red, Blue, and White Teams
  5. 5:20 First War Story: Industrial Plant infiltration objectives
  6. 6:00 Leveraging OSINT (Google Maps, Shodan) for physical recon
  7. 7:45 Performing on-site embedded reconnaissance to assess controls

Behind Closed Doors: Physical Red Team Tactics - Firat Acar & Moritz Thomas

Speakers: Firat Acar, Red Teamer, Invizo; Moritz Thomas, Red Teamer, Invizo

Conference: Disobey

YouTube: https://www.youtube.com/watch?v=Ni76kbhdLlo

Overview

In an era where cyber threats dominate headlines, the foundational layer of physical security often receives less attention than it deserves. This talk, "Behind Closed Doors: Physical Red Team Tactics," presented by seasoned red teamers Firat Acar and Moritz Thomas from the European cybersecurity consultancy Invizo, delves into the critical, often overlooked, realm of physical infiltration. The speakers share a series of "war stories" from their real-world red team engagements, illustrating how sophisticated organizations can be compromised through surprisingly low-tech means, primarily social engineering, combined with clever technical exploits.

The presentation serves as a stark reminder that even the most advanced digital defenses can be rendered moot if an adversary gains physical access to critical infrastructure. Acar and Thomas meticulously break down their methodologies, from initial open-source intelligence (OSINT) and embedded reconnaissance to the execution of covert and overt entry tactics. Their narratives highlight the severe lack of security awareness among staff, the vulnerabilities in common access control systems, and the ingenuity required to bypass seemingly robust perimeters. This talk is essential for security professionals, blue teams, and organizational leaders seeking to understand and fortify their defenses against determined physical adversaries.

The core message underscores that a comprehensive security posture must integrate robust physical controls, continuous staff awareness training, and a proactive approach to identifying and mitigating human-centric vulnerabilities. By sharing anonymized yet detailed accounts of successful and near-successful breaches, Acar and Thomas provide invaluable insights into the mindset and techniques of physical red teamers, empowering organizations to anticipate and counter these often underestimated threats.

Background

▶ Watch: Welcome and talk agenda overview (0:00)

To frame their practical demonstrations, Acar and Thomas first clarified the distinction between penetration testing (pentesting) and red teaming. Pentesting typically focuses on identifying as many vulnerabilities as possible within a defined scope, such as a web application or mobile app, without necessarily requiring stealth. In contrast, red teaming simulates a full-scale, multi-vectored cyber attack against an organization as a whole, with the primary objective of remaining undetected while achieving specific goals. This necessitates a high degree of stealth and often involves initial footholds gained through social engineering, phishing, or, as highlighted in this talk, physical breaches. The blue team, responsible for defense, is generally unaware that a red team exercise is underway and must treat any incidents as real. A crucial intermediary is the white team, the only internal group aware of the red team's activities, responsible for communication, escalation management, and ensuring the exercise remains within defined bounds.

The physical red teaming methodology employed by Invizo is structured into three phases:

  1. Reconnaissance: This involves Open-Source Intelligence (OSINT), leveraging publicly available information from sources like Google Maps, Shodan, and social media to gather details about the target's layout, security features, and potential vulnerabilities. This is complemented by embedded reconnaissance, where red teamers physically visit the premises to observe access controls (locks, keypads, fences), camera placements, and general activity patterns.
  2. Entry: This phase offers two main approaches:
  • Covert Entry: Attempting to gain access without being noticed, often through technical means like access card cloning.
  • Overt Entry: Involving direct interaction and social engineering to manipulate individuals into granting access.
  1. Objectives & Persistence: Once inside, the red team aims to achieve predefined objectives, such as locating sensitive servers, exfiltrating data, or, critically, establishing persistence by planting a rogue device for remote access.

This structured approach, combined with a deep understanding of human psychology and technical exploits, forms the foundation for the compelling stories shared throughout the presentation. The speakers emphasize that success often hinges not on brute-force technical prowess, but on meticulous planning, improvisation, and exploiting human trust and complacency.

Key Findings

▶ Watch: Phases of a physical red team assessment (3:30)

The talk's "war stories" consistently revealed several key findings regarding the state of physical security and the effectiveness of red teaming tactics:

  • Social Engineering is Paramount: Across all scenarios, social engineering proved to be the most potent and consistently successful vector for bypassing physical security. Whether posing as cleaning staff, early consultants, or new joiners, the ability to craft convincing pretexts and manipulate human behavior was critical.
  • Lack of Security Awareness: A recurring vulnerability was the severe lack of security awareness among staff, from receptionists to general employees. Many were "too nice" or insufficiently trained to challenge unexpected visitors or unusual requests, often granting access based on simple politeness or a fabricated sense of urgency.
  • Strong Perimeter, Weak Interior: Several facilities exhibited robust perimeter security (high fences, numerous cameras, sensitive vibration sensors). However, once this initial barrier was breached, internal security controls were often significantly weaker, allowing red teamers relatively free rein to explore and achieve objectives.
  • Technical Controls Are Not Foolproof: Advanced physical access controls like revolving doors with anti-tailgating features or Network Access Control (NAC) systems could be bypassed. The revolving door was defeated by direct social engineering, while NAC was circumvented using a transparent bridge to impersonate a legitimate device.
  • Persistence is Key to Deeper Access: Planting rogue devices, such as a Raspberry Pi with an LTE modem, was a consistent objective, allowing for remote, long-term access to the internal network, including sensitive Operational Technology (OT) networks. This highlights the risk of physical access leading to full network compromise.
  • Voice Phishing (Caller ID Spoofing) is Highly Effective: The ability to spoof internal phone numbers to impersonate employees proved incredibly effective in manipulating receptionists into granting access or providing critical information, bypassing traditional verification methods.
  • Vulnerable Access Card Technologies: The use of older or poorly configured access card systems, specifically Mifare Classic badges with default encryption keys and weak Crypto1 stream cipher, made them susceptible to rapid cloning (within 30 seconds).

These findings collectively underscore that physical security is a complex blend of technology, policy, and human factors. Overreliance on one aspect, particularly technology without adequate human training, creates significant blind spots for adversaries.

Technical Deep Dive

▶ Watch: Understanding Red, Blue, and White Teams (4:30)

The red team's success in these engagements often hinged on a combination of social engineering prowess and clever technical implementations. Several specific technologies and techniques were crucial:

Rogue Device (Raspberry Pi with LTE Modem)

For establishing persistent access, a Raspberry Pi equipped with an LTE modem was the go-to rogue device. This setup allowed the Pi to connect to the target's internal network via Ethernet, and then communicate outbound to the red team's Command and Control (C2) infrastructure in the cloud via the LTE cellular network. This design ensures remote access even if the internal network is segmented or isolated from the internet.

A critical challenge encountered was the incompatibility of a specific LTE stick, leading to a frantic, late-night troubleshooting session. This highlighted the practical realities of field operations, where unexpected hardware issues can arise. The solution involved a "janky script" with multiple sleep statements, demonstrating the need for on-the-fly improvisation and leveraging community knowledge (forum posts, wikis) to resolve technical hurdles under pressure.

Transparent Bridge (Silent Bridge) for NAC Bypass

In the mountain base scenario, the target's network employed Network Access Control (NAC), meaning devices plugging into wall sockets had to authenticate to the network switch before gaining access. A standard rogue device would fail this authentication. The solution involved a transparent bridge implemented on the Raspberry Pi using a tool called Silent Bridge.

The concept is elegant: the Raspberry Pi, equipped with two network interfaces, is physically placed between a legitimate network device (e.g., a printer) and the wall socket. Silent Bridge is configured to make the Raspberry Pi assume the IP and MAC address of the legitimate device (the "supplicant"). From the perspective of the network switch (the "authenticator"), it still sees the legitimate device's MAC and IP, allowing authentication to proceed normally. However, the Raspberry Pi can then intercept, inspect, and route traffic.

Furthermore, by utilizing ARP (Address Resolution Protocol) and source NAT (Network Address Translation) shenanigans, Silent Bridge could route traffic transparently through the Raspberry Pi, out through its LTE modem to the cloud C2, and then back into the target network. This created a tunnel, effectively bypassing the NAC and providing the red team with full remote access to the internal network, including the sensitive Operational Technology (OT) network, from anywhere in the world, even from deep inside a mountain where traditional Wi-Fi or wired connections would be impossible.

Caller ID Spoofing (Voice Phishing)

For voice phishing attacks, the red team employed a sophisticated setup for caller ID spoofing:

  • Phone Client: Zoiper was used as the software-based phone client on their laptops.
  • PBX Server: An Asterisk PBX server was set up in their local network. Asterisk is an open-source framework for building communication applications, acting as a central hub for managing phone calls.
  • SIP Trunk: To make outbound calls to the public telephone network and enable caller ID spoofing, a virtual SIP trunk was required. This is essentially a virtual phone line that connects the PBX server to the public switched telephone network (PSTN) via the internet. Registering a SIP trunk is a formal process, requiring registration under a company name and taking 1-2 weeks. A specific challenge was encountered with Belgium's security measures preventing spoofing from outside the country, necessitating the registration of a Belgian SIP trunk, which also took approximately two weeks.

Once set up, this allowed the red team to call a target and display any desired caller ID on the recipient's phone. This means if a receptionist had an employee's number saved, a call from the red team could appear as if it was coming from that trusted internal employee, significantly increasing the likelihood of success for social engineering attempts.

Badge Cloning

For physical access control systems using Myfare Classic badges, the red team identified a critical vulnerability. These badges often use default encryption keys and rely on the Crypto1 stream cipher, which is known to be weak and predictable. This allows an attacker with a specialized device, such as the iCopy-X device, to clone a badge within approximately 30 seconds. The process involves reading the data from a target's badge and writing it onto a blank Myfare Classic card, creating a functional duplicate. This highlights the importance of using more secure access card technologies with robust encryption and unique keys.

These technical details underscore that while social engineering opens the door, carefully chosen and deployed technical tools are essential for achieving deep access and persistence in physical red team operations.

Demo / Proof of Concept

▶ Watch: Leveraging OSINT (Google Maps, Shodan) for physical recon (6:00)

The talk presented four distinct "war stories" as demonstrations of their physical red team tactics, showcasing various scenarios and outcomes. All story details and names were anonymized, with AI-generated images used for illustration.

Story 1: The Industrial Plant (Moritz)

Objective: Infiltrate, access production servers, plant a rogue device on the network.

Reconnaissance: OSINT (Google Maps, Shodan) revealed a remote production facility with high fences (2.5-3m), numerous cameras (wide-angle, thermal, night vision), and highly sensitive vibration sensors on fences. Embedded recon confirmed a single main gate and very few unused doors. Climbing fences was deemed impossible without detection.

Entry Strategy: Initially considered fence jumping, but deemed too risky due to high visibility, lack of cover, and 24/7 dog walkers. The white team suggested exploiting external cleaning staff schedules.

Execution: The red team crafted a simple social engineering pretext: they were replacement cleaning staff, with the original team having fallen ill due to COVID. They purchased cleaning supplies (mop, bucket) and approached the main gate during lunchtime. Security, accepting the story, directed them to a registration desk, which they bypassed. They found a locked building with a card reader. They intercepted a lone worker returning from lunch, spun their story, and the worker kindly unlocked the door. Inside, signs warned of high voltage and hazards. The white team, initially unavailable for lunch, eventually guided them to the server room.

Outcome: Server cabinets were locked, but side panels easily popped open (maintenance panels). The Raspberry Pi rogue device was connected to the network. An hour later, the original cleaning staff arrived, exposing the breach.

Key Learnings: Extremely powerful and successful low-tech social engineering. Severe lack of security awareness in staff. The client reviewed CCTV and even printed "wanted posters" of the red team.

Story 2: The First Office Building (Firat)

Objective: Gain physical access, plant rogue devices, steal/photograph sensitive documents.

Reconnaissance: A medium-to-large office building with a revolving main entrance door and a receptionist desk. Observed people tailgating during lunch breaks. Identified company merch wearers for potential following.

Entry Strategy: Initially attempted simple tailgating through the revolving door without a badge, but the door intelligently spun him back twice, indicating an anti-tailgating mechanism.

Execution: Switched to social engineering. Approached an employee on a smoke break with a pretext of being an early consultant needing to use the restroom. The employee directed him to the receptionist. The receptionist, after hearing a vague story about an unavailable manager and contact person, allowed him to wait in the lobby. Noticing his bag of food, she offered him access to the canteen, which he initially refused but then accepted. Once in the canteen (a second security perimeter), he waited for people to finish lunch, then tailgated them out. He snuck past the receptionist into an elevator, followed employees to a floor, and tailgated into an office. He sat at a desk, but was quickly questioned by two employees, who then returned with the angry receptionist. He was surrounded and questioned, improvising rapidly ("manager out of office, only know first name").

Outcome: Despite being caught, his rapid improvisation led one employee to offer to escort him to get a visitor's badge for a different floor. He received a badge, legitimizing his presence. However, a "stupid mistake" – asking the receptionist about allowed floors – made her suspicious, and she escorted him to the IT security room. The white team was called for a "leg up," acknowledging he had technically succeeded but for his unnecessary chatter.

Key Learnings: Tailgating detection can be effective. Social engineering requires constant improvisation and knowing when to stop talking. Even when caught, a good pretext and quick thinking can turn the situation around.

Story 3: The Mountain Base (Moritz)

Objective: Infiltrate, plant a rogue device on the OT network.

Reconnaissance: OSINT (Street View, online documentation, 3D maps) revealed a remote mountain facility with a single entrance gate, high-security locks, a keypad/card reader, and a country road connection. Crucially, they discovered public guided tours, but these required a minimum group size and two-week registration. The white team informed them of an upcoming internal guided tour for new joiners.

Entry Strategy: Social engineering as new joiners from a German branch, coincidentally in the area. Prepared personas, a standby "manager" phone number, and "get out of jail letters" for escalation.

Execution: Waited in the snow for the new joiners' bus. Joined the group and were immediately questioned by an attentive HR lady. Gave their story, which was initially accepted. Five minutes later, she returned, unable to confirm their presence with HR HQ. They reiterated their story and provided the manager's contact number. After another 10 minutes, she returned, still unable to confirm, and with a "don't mess with me" look, asked them to leave. They were escorted out.

Outcome: The social engineering attempt failed due to the HR lady's persistence and process-orientation. An internal incident was raised. However, the client granted a "leg up": simulating success by escorting them into the facility at night.

Leg-Up Simulation: At night, escorted by a white team member who disabled alarms, they explored the vast underground facility. They found a control room with two Human Machine Interfaces (HMIs) – one read-only, another locked with an admin prompt. They discovered cleartext admin credentials in file cabinets, unlocking the HMI. They identified a color-coded network socket connected to the HMI and a printer, indicating it was the OT network. They used a Raspberry Pi with Silent Bridge as a transparent bridge between the printer and the wall socket to bypass NAC, successfully gaining OT network access. The LTE modem surprisingly worked underground.

Incident: After a few minutes, a phone rang in the control room – likely an alert triggered by the printer disconnect. The white team advised them to run, as security was probably en route. They bolted, but no security turned up for 10-20 minutes.

Key Learnings: Highly persistent HR can defeat social engineering. Strong perimeter security doesn't guarantee internal security. Lack of alarm systems inside the compound was a major flaw. Failure to respond to alarms (printer disconnect) and connect incidents (afternoon social engineering attempt vs. night alarm) showed poor incident response. The client did a plant-wide search but missed the implant.

Story 4: The Second Office Building (Firat)

Objective: Infiltrate, plant rogue devices, get sensitive information.

Reconnaissance: Very large office. Entry only possible by showing a badge to a receptionist, who would then open a glass door. Tailgating not possible. Discovered Mifare Classic badge cloning was possible (30 seconds with an iCopy-X device) due to default encryption keys and weak Crypto1 cipher.

Entry Strategy: Voice phishing (caller ID spoofing) combined with physical presence.

Execution:

  1. Intruder 1 approaches receptionist, claiming dead phone battery, asks her to call his colleague (a remote participant). This gets the red team the receptionist's direct number.
  2. Remote Participant (at the office) receives the call, notes the receptionist's number. After a few minutes, uses caller ID spoofing (via Zoiper, Asterisk, SIP trunk) to call the receptionist, impersonating an internal employee (whose number was obtained via OSINT, e.g., out-of-office mail).
  3. Spoofed Call: The remote participant, as the "employee," tells the receptionist an awaited guest (Intruder 2) will arrive soon and asks her to send them directly to a specific floor (e.g., third floor) as he'll be busy in meetings.
  4. Intruder 2 arrives, claiming to be the awaited guest, creating urgency by saying he's late. The receptionist, having received the "employee's" call, opens the door and sends Intruder 2 up.

Optional Follow-up: Intruder 2 could then look for unattended badges (e.g., at desks while employees are in the toilet) and clone them using the iCopy-X device to let Intruder 1 in for more extensive coverage.

Outcome: This combined voice phishing and physical presence technique was highly effective for gaining entry.

Key Learnings: Caller ID spoofing is a powerful initial access vector. Impersonating external service providers is often more effective than internal staff, as there are fewer internal checks. Badge cloning remains a significant threat for systems using weak technologies like Mifare Classic.

Defensive Implications

▶ Watch: Performing on-site embedded reconnaissance to assess controls (7:45)

The detailed accounts from Firat Acar and Moritz Thomas provide crucial insights for organizations looking to bolster their defenses against physical red team attacks. The following implications should be considered:

  • Elevate Security Awareness Training: This is arguably the most critical defensive measure. Staff, especially those in front-line roles like reception, must be trained to "trust but verify." They should be empowered and encouraged to challenge unfamiliar individuals, ask for proper identification, and verify appointments with known internal contacts before granting access. The instinct to be "nice" must be overridden by security protocols. Training should include scenarios for various pretexts (e.g., "replacement staff," "early consultant," "lost," "urgent delivery").
  • Strengthen Visitor Management Protocols: All visitors, regardless of pretext, should be accompanied by a known staff member throughout their stay. Unescorted visitors should be immediately questioned. The practice of allowing visitors to wait unattended or sending them to a specific floor based on an unverified phone call is a significant vulnerability.
  • Implement Robust Physical Access Controls:
  • Access Card Technology: Migrate away from easily clonable technologies like Mifare Classic, especially those using default encryption keys or weak ciphers. Implement more secure, encrypted, and unique badge systems.
  • Anti-Tailgating Measures: While revolving doors can be bypassed by social engineering, they still provide a layer of defense. Ensure their anti-tailgating features are active and staff are trained on their purpose.
  • Internal Controls: Beyond the perimeter, internal doors to sensitive areas (server rooms, OT control rooms) must have strong, multi-factor access controls. Maintenance panels should be secured against easy bypass.
  • Enhance Network Access Control (NAC) and Segmentation:
  • NAC systems are valuable but can be bypassed. Implement additional layers of defense, such as network segmentation, especially for critical OT networks.
  • Monitor for unusual network activity, including new MAC addresses, IP address changes, or devices impersonating legitimate hardware (e.g., a printer suddenly showing different network characteristics).
  • Improve Incident Response for Physical Breaches:
  • Alarm Response: Alarms (e.g., printer disconnect, door forced open) must be investigated promptly and thoroughly. The mountain base story highlighted a critical failure in alarm response.
  • Connecting Incidents: Organizations must have mechanisms to correlate seemingly unrelated incidents (e.g., an afternoon social engineering attempt with a late-night alarm). This requires robust communication channels between physical security, IT security, and relevant departments.
  • Physical Sweeps: Regular, unannounced physical sweeps for rogue devices are essential, especially after any suspected breach or suspicious activity.
  • Counter Voice Phishing (Caller ID Spoofing):
  • Educate staff that caller ID cannot be trusted, especially for internal numbers.
  • Implement a policy for verifying callers: if an unexpected or unusual request comes from an "internal" number, staff should hang up and call back the person on their officially listed internal number (e.g., from the company directory), not the number provided by the caller.
  • Be wary of calls from "external service providers" who claim to be on-site or needing urgent access, as these pretexts are highly effective.
  • Secure Open-Source Information: While difficult, organizations should minimize the amount of sensitive internal information (e.g., detailed floor plans, internal event schedules, employee contact lists) available through public sources like social media, Google Maps, or company websites.

By addressing these defensive implications, organizations can significantly raise the bar for physical red teamers, making breaches more difficult, more detectable, and less impactful.

Key Takeaways

  • Social engineering remains the most potent weapon in physical red teaming, often bypassing advanced technical controls.
  • Security awareness training for all staff is paramount, particularly for front-line personnel like receptionists, to counter social engineering attempts.
  • "Trust but verify" must be ingrained in corporate culture; staff should challenge unfamiliar individuals and verify information through official channels.
  • Physical access controls, including badge systems (e.g., Mifare Classic), must be robust and regularly assessed for vulnerabilities like weak encryption or default keys.
  • Network Access Control (NAC) can be bypassed with techniques like transparent bridging, emphasizing the need for network segmentation and vigilant monitoring for unusual device behavior.
  • Voice phishing via caller ID spoofing is a highly effective initial access vector; employees should be trained to verify callers by calling back on official, known numbers.

About the Speaker(s)

Firat Acar is a dedicated red teamer at Invizo, where he has been working for five and a half years. He is part of Invizo's AIS (Advanced Intrusion Simulation) team, focusing exclusively on red teaming engagements and simulating real-world cyber attacks.

Moritz Thomas is also a red teamer at Invizo, having been with the company for six years. He specializes in Research and Development (R&D) within the red team, driving forward Invizo's efforts in discovering new attack methodologies and tools. Moritz regularly presents on these topics at conferences.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent physical red team war-story talk with four well-structured scenarios and some genuinely useful technical detail — the Silent Bridge NAC bypass and the Zoiper/Asterisk caller-ID spoofing setup are the highlights. Nothing here will surprise an experienced physical pentester, but it's honest, operationally grounded, and light-years better than the usual 'we tailgated and it worked' fluff.

Heather Calloway (CISO) — WEAK

Competent physical red team tradecraft presented through well-structured war stories, but the talk never climbs above the practitioner level. Defenders get a list of what went wrong; executives and security leaders never hear what it means for their governance model or accountability structure.

→ Top-rated talks at Disobey 2026

All talks from Disobey 2026