Comprehensive security assessment (penetration testing)
of the physical perimeter
We simulate the full sequence of intruder actions: from information gathering and attempts to enter the premises to bypassing access control systems and gaining access to the internal infrastructure.
Why run a physical pentest
Physical perimeter security controls often provide only the appearance of security. The goal of a physical pentest is to check whether a real intruder can enter the site, gain access to restricted areas and use physical presence to develop the attack further.
Validating the real resilience of the physical perimeter
We assess how well existing organizational and technical measures can stop an intruder who is deliberately looking for ways to enter the site.
Assessment of RFID access control systems and biometric terminals
We assess whether access control systems are configured correctly, comprehensively analyze the attack surface and look for weaknesses that allow security mechanisms to be bypassed.
Assessment of employee and security team actions
We check whether employees are able to recognize suspicious activity, and whether security staff can detect, stop and correctly handle an intrusion attempt in time.
Testing whether the attack can progress
Entering the office is not always the final goal. We check whether physical access makes it possible to reach critical assets, connect to the corporate infrastructure and establish persistence in the internal network.
What the assessment covers
The scope is adapted to the assessment target, the adversary model and the acceptable level of impact. Individual areas can be tested independently or combined into a comprehensive intrusion scenario.
Physical perimeter
We explore possible ways of unauthorized entry into the organization’s premises, including:
- entrances/exits, visitor reception areas and utility rooms;
- checkpoints and site access arrangements;
- parking lots, loading areas and other auxiliary access points.
We assess the effectiveness of existing physical and organizational barriers.
RFID access control systems and biometric terminals
We review the identification technologies in use, the access control system architecture and its resilience to attacks, including:
- the possibility of cloning access cards or performing relay attacks;
- liveness detection bypass for biometric terminals;
- MITM on the channel between the reader and the controller;
- the possibility of gaining administrative access and bypassing the tamper sensor.
Social engineering
We assess whether physical access can be obtained through interaction with employees, security staff or maintenance personnel.
Internal infrastructure
Gaining access to the premises can become the first stage of an attack on the corporate network. After a successful intrusion we check what opportunities physical presence on site gives the intruder and whether remote access to the internal network can be obtained.
How the project works
The process is transparent for the customer team: regular status updates, approval of potentially dangerous checks and immediate notification of critical risks as soon as they are found.
Define the scope and the adversary model
We agree on the sites, testing goals, acceptable scenarios, restrictions and the interaction procedure if the testing team is detected.
Gather information and study the site
We perform OSINT, analyze available information about the site and identify potential intrusion routes and critical physical security points.
Perform active testing
We test the physical perimeter, access control systems, biometric terminals, doors and locks. We perform social engineering and other agreed scenarios. Critical findings and potentially dangerous actions are approved through the established procedure.
Validate possible attack scenarios
We do not limit ourselves to recording individual weaknesses. We check whether they can be combined into a consistent chain to achieve the project goal: entering a restricted area, gaining access to a critical room or establishing a foothold in the internal infrastructure. At the same time we record at which stage the attack was detected by employees or the security team.
Deliver the report and support remediation
We deliver recommendations, answer questions and perform retesting if needed.
What you get
The result of a physical pentest is not a list of hypothetical weaknesses, but a description of validated intrusion scenarios and the factors that allowed or prevented the attacker from achieving the goal.
Executive summary
A concise assessment of the level of physical security, the most significant risk scenarios and possible business impact.
Technical report
A detailed description of the checks performed and the weaknesses found, the conditions and steps to reproduce them, evidence that the attacks are feasible and a severity assessment.
Recommendations for strengthening protection
Practical recommendations for the security team and the information security and IT departments.
Why us
The Offensive Security team combines project practice, security research, CTF background, bug bounty experience and proprietary methodologies for application and infrastructure assessment.
30+ experts
Practicing experts in application security assessment, modeling the actions of potential adversaries and researching vulnerabilities in application systems and IT infrastructure.
700+ projects
Project experience across finance, telecom, industry, retail, IT, healthcare, transport and government sectors.
30+ CVEs
Vulnerabilities found in Google Chrome, Apple, Microsoft Exchange, VMware, Jenkins, TrueConf, cPanel and others.
100+ bug bounty reports
Accepted reports in HackerOne, Standoff, Google and other programs, plus acknowledgements from major companies.
Team certifications
OSCP, OSWE, OSEP, CRTE, CRTP, CEH, BSCP, WAPT, CPTS, RTO and other professional certifications.
Proprietary methods and R&D
Methods are based on FSTEC, OWASP, PTES, MITRE ATT&CK and are continuously updated for modern attack techniques and changes in the threat landscape.
Examples of publicly disclosed vulnerabilities
Google Chrome
CVE-2024-10229, CVE-2025-4664: vulnerabilities in browser security mechanisms.
TrueConf
CVE-2022-46763, CVE-2022-46764: critical vulnerabilities, including unauthenticated SQL command execution.
VMware vCenter
A series of vulnerabilities, including CVE-2021-22005, reflected in VMware security bulletin VMSA-2021-0020.
Jenkins
CVE-2019-1003029: sandbox bypass enabling arbitrary code execution on the Jenkins controller side.
Microsoft Exchange
CVE-2024-49040: sender spoofing in Microsoft Exchange.
cPanel
CVE-2025-66429: privilege escalation to root level.
Test real attack scenarios before attackers do
Tell us which systems you need to assess. We will propose the right format, scope and testing plan.
Discuss a project