SolidLab

Comprehensive security assessment (penetration testing)
of the physical perimeter

We simulate the full sequence of intruder actions: from information gathering and attempts to enter the premises to bypassing access control systems and gaining access to the internal infrastructure.

Why run a physical pentest

Physical perimeter security controls often provide only the appearance of security. The goal of a physical pentest is to check whether a real intruder can enter the site, gain access to restricted areas and use physical presence to develop the attack further.

Validating the real resilience of the physical perimeter

We assess how well existing organizational and technical measures can stop an intruder who is deliberately looking for ways to enter the site.

Assessment of RFID access control systems and biometric terminals

We assess whether access control systems are configured correctly, comprehensively analyze the attack surface and look for weaknesses that allow security mechanisms to be bypassed.

Assessment of employee and security team actions

We check whether employees are able to recognize suspicious activity, and whether security staff can detect, stop and correctly handle an intrusion attempt in time.

Testing whether the attack can progress

Entering the office is not always the final goal. We check whether physical access makes it possible to reach critical assets, connect to the corporate infrastructure and establish persistence in the internal network.

What the assessment covers

The scope is adapted to the assessment target, the adversary model and the acceptable level of impact. Individual areas can be tested independently or combined into a comprehensive intrusion scenario.

Physical perimeter

We explore possible ways of unauthorized entry into the organization’s premises, including:

- entrances/exits, visitor reception areas and utility rooms;
- checkpoints and site access arrangements;
- parking lots, loading areas and other auxiliary access points.

We assess the effectiveness of existing physical and organizational barriers.

RFID access control systems and biometric terminals

We review the identification technologies in use, the access control system architecture and its resilience to attacks, including:

- the possibility of cloning access cards or performing relay attacks;
- liveness detection bypass for biometric terminals;
- MITM on the channel between the reader and the controller;
- the possibility of gaining administrative access and bypassing the tamper sensor.

Social engineering

We assess whether physical access can be obtained through interaction with employees, security staff or maintenance personnel.

Internal infrastructure

Gaining access to the premises can become the first stage of an attack on the corporate network. After a successful intrusion we check what opportunities physical presence on site gives the intruder and whether remote access to the internal network can be obtained.

How the project works

The process is transparent for the customer team: regular status updates, approval of potentially dangerous checks and immediate notification of critical risks as soon as they are found.

01

Define the scope and the adversary model

We agree on the sites, testing goals, acceptable scenarios, restrictions and the interaction procedure if the testing team is detected.

02

Gather information and study the site

We perform OSINT, analyze available information about the site and identify potential intrusion routes and critical physical security points.

03

Perform active testing

We test the physical perimeter, access control systems, biometric terminals, doors and locks. We perform social engineering and other agreed scenarios. Critical findings and potentially dangerous actions are approved through the established procedure.

04

Validate possible attack scenarios

We do not limit ourselves to recording individual weaknesses. We check whether they can be combined into a consistent chain to achieve the project goal: entering a restricted area, gaining access to a critical room or establishing a foothold in the internal infrastructure. At the same time we record at which stage the attack was detected by employees or the security team.

05

Deliver the report and support remediation

We deliver recommendations, answer questions and perform retesting if needed.

What you get

The result of a physical pentest is not a list of hypothetical weaknesses, but a description of validated intrusion scenarios and the factors that allowed or prevented the attacker from achieving the goal.

Executive summary

A concise assessment of the level of physical security, the most significant risk scenarios and possible business impact.

Technical report

A detailed description of the checks performed and the weaknesses found, the conditions and steps to reproduce them, evidence that the attacks are feasible and a severity assessment.

Recommendations for strengthening protection

Practical recommendations for the security team and the information security and IT departments.

Description of validated security controls
Immediate notification of critical risks
Retest after remediation

Why us

The Offensive Security team combines project practice, security research, CTF background, bug bounty experience and proprietary methodologies for application and infrastructure assessment.

30+ experts

Practicing experts in application security assessment, modeling the actions of potential adversaries and researching vulnerabilities in application systems and IT infrastructure.

700+ projects

Project experience across finance, telecom, industry, retail, IT, healthcare, transport and government sectors.

30+ CVEs

Vulnerabilities found in Google Chrome, Apple, Microsoft Exchange, VMware, Jenkins, TrueConf, cPanel and others.

100+ bug bounty reports

Accepted reports in HackerOne, Standoff, Google and other programs, plus acknowledgements from major companies.

Team certifications

OSCP, OSWE, OSEP, CRTE, CRTP, CEH, BSCP, WAPT, CPTS, RTO and other professional certifications.

Proprietary methods and R&D

Methods are based on FSTEC, OWASP, PTES, MITRE ATT&CK and are continuously updated for modern attack techniques and changes in the threat landscape.

Examples of publicly disclosed vulnerabilities

Google Chrome

CVE-2024-10229, CVE-2025-4664: vulnerabilities in browser security mechanisms.

TrueConf

CVE-2022-46763, CVE-2022-46764: critical vulnerabilities, including unauthenticated SQL command execution.

VMware vCenter

A series of vulnerabilities, including CVE-2021-22005, reflected in VMware security bulletin VMSA-2021-0020.

Jenkins

CVE-2019-1003029: sandbox bypass enabling arbitrary code execution on the Jenkins controller side.

Microsoft Exchange

CVE-2024-49040: sender spoofing in Microsoft Exchange.

cPanel

CVE-2025-66429: privilege escalation to root level.

Test real attack scenarios before attackers do

Tell us which systems you need to assess. We will propose the right format, scope and testing plan.

Discuss a project