Skills Plugins MCP Prompt Model 博客 我的中心
Development #ai #testing

physical-security-testing

Physical penetration testing covering mechanical lock bypass (pin-tubular/wafer), RFID/NFC badge cloning (Proxmark3/ESP-RFID-Tool/Walrus), HID iCLASS/Mifare duplication, drop box deployment (LAN Turtle/Packet Squirrel), USB weapons (Rubber Ducky/Bash Bunny), hidden camera placement, and on-site engagement operations including tailgating pretext preparation and physical-docs legal templates.

DeepseekModel Curated skill Quality Excellent · 78 v1.0.0

Get

https://deepseekmodel.com/api/download.php?id=brucesongs-kali-claw-skills-physical-security-testing-skill-md&format=skill
Download .skill Standard format with system_prompt and model_config, ready for any agent framework
The actual content of the system_prompt field in the .skill file.
name physical-security-testing description Physical penetration testing covering mechanical lock bypass (pin-tubular/wafer), RFID/NFC badge cloning (Proxmark3/ESP-RFID-Tool/Walrus), HID iCLASS/Mifare duplication, drop box deployment (LAN Turtle/Packet Squirrel), USB weapons (Rubber Ducky/Bash Bunny), hidden camera placement, and on-site engagement operations including tailgating pretext preparation and physical-docs legal templates. origin github-trending-2026 version 0.2.0.2 compatibility >=0.1.31 allowed-tools ["Bash","Read","Write","Edit","Glob","Grep","WebFetch"] metadata {"domain":"physical","tool_count":12,"guide_count":1,"mitre":"TA0001-Initial Access (physical), T1192-Hardware Additions, T1366-Physical Security Bypass","last_reviewed":"2026-07-26"} Skill: Physical Security Testing Supplementary Files : payloads.md — Legal/scope templates (TrustedSec physical-docs), lock picking payloads (pin-tubular/wafer/dimple/bump), bypass tool usage (shove knife, under-door, crash bar tape), Proxmark3/ESP-RFID-Tool/Walrus badge cloning, Mifare/HID iCLASS high-freq duplication, LAN Turtle/Packet Squirrel drop boxes, Rubber Ducky/Bash Bunny USB weapon payloads, hidden camera concealment, on-site engagement ops scripts, tailgating pretext prep, exit & evidence handling, and a quick-reference cheat sheet test-cases.md — 12 structured test cases (legal scope review, pin-tumbler pick, RFID 125kHz clone, Mifare Classic clone, HID iCLASS decode, LAN Turtle drop box deploy, Rubber Ducky payload, network implant concealment, hidden camera placement, on-site recon, tailgating pretext, exit/evidence) with severity levels and summary tables guides/physical-security-testing-playbook.md — End-to-end on-site engagement playbook (pre-flight authorization, 5-phase workflow, entry-vector decision matrix, guard/employee interaction rules, evidence chain-of-custody, integration with adjacent skills) Summary Physical security testing covers the on-site operations that gain physical access to a target facility — lock picking, badge cloning, drop-box deployment, USB-weapon delivery, hidden-camera placement, and the social engineering that gets a human through the door. This skill is the physical-access complement to radio and firmware skills: where bluetooth-rfid-nfc analyzes the wireless protocol and hardware-security analyzes chips and firmware, this skill asks "how do I get through the door ?" Tools : Proxmark3, ESP-RFID-Tool, Walrus, Hak5 LAN Turtle, Hak5 Packet Squirrel, USB Rubber Ducky, Bash Bunny, P4wnP1, lock pick set, bump keys, under-door tool, shove knife, hidden cameras. Domain : physical MITRE ATT&CK : TA0001-Initial Access (physical), T1192-Hardware Additions, T1366-Physical Security Bypass Description Physical penetration testing across the full on-site engagement lifecycle: legal scope and authorization (TrustedSec physical-docs templates), pre-engagement reconnaissance (building layout, badge vendor, guard rotation), entry-vector selection (locks vs badges vs USB vs implants vs social), mechanical bypass (pin-tubular, tubular, wafer, dimple; bump keys; shove knife; under-door tool; crash bar tape), radio credential cloning (125 kHz HID Prox/Indala via Proxmark3/ESP-RFID-Tool/Walrus; 13.56 MHz Mifare Classic/DESFire and HID iCLASS via Proxmark3), drop-box deployment (LAN Turtle, Packet Squirrel, Pi Zero W implants) for persistent network access once inside, USB-weapon delivery (Rubber Ducky, Bash Bunny, P4wnP1) for attacker-controlled keystroke injection, hidden camera/audio placement for situational awareness during multi-day engagements, and the social engineering pretexts that turn a locked door into an open one. This is the access side of the physical+radio stack. Where bluetooth-rfid-nfc analyzes BLE/RFID/NFC protocols and sdr-rf-attack covers broad RF replay, this skill focuses on the operational question: "what credential do I need, how do I clone it, and how do I use it to enter the facility?" Where hardware-security looks at JTAG/UART/firmware extraction, this skill looks at the doors, locks, and readers those devices physically protect. Difference from bluetooth-rfid-nfc : That skill covers BLE/RFID/NFC radio analysis (sniffing, protocol fuzzing, decryption). This skill brings the physical-access perspective — cloning a 125 kHz HID Prox card to bypass a door reader, duping an HID iCLASS credential for after-hours entry, and the on-site operational discipline (concealment, guard avoidance, evidence handling) that radio work alone doesn't address. Difference from hardware-security : That skill targets JTAG/UART/SPI/I2C and firmware extraction. This skill targets the perimeter — locks, badges, drop boxes, USB weapons — the access paths that get an operator in front of the hardware in the first place. Difference from social-engineering : That skill covers human manipulation (phishing, vishing, pretext). This skill includes physical-world social engineering — tailgating pretexts, badge impersonation, delivery-driver pretexts — but only as one of five entry vectors. Mechanical and electronic bypass are the primary focus. Difference from sdr-rf-attack : That skill covers broad RF replay (garage doors, keyfobs, alarms). This skill covers badge cloning as an on-site access operation, including reader reconnaissance, credential capture at the reader, and the legal/operational framing that pure RF replay doesn't require. Use Cases Authorized facility penetration test : Execute a scoped physical pentest — attempt badge cloning, lock bypass, and drop-box deployment against the client's headquarters or data center, documenting every access path and reporting remediation. Badge system audit (defensive) : Audit a deployed badge system for cloning susceptibility — test HID Prox (no authentication, trivially cloned), Mifare Classic (CRYPTO1 broken), and report upgrade paths to Mifare DESFire EV2/EV3 or HID iCLASS SE. Drop-box deployment for red team : Once physical access is achieved, deploy a LAN Turtle or Packet Squirrel inside the target facility to establish persistent VPN pivot for the rest of the red team engagement. USB weapon delivery : Deliver a Rubber Ducky or Bash Bunny payload to an unattended workstation inside the target facility (e.g., extraction of credentials or beacon deployment) during a physical engagement. DEF CON / Red Team physical CTF : Practice lock picking, badge cloning, and on-site recon in a competition environment — Schuyler Towne content, DEF CON Physical Security Village, Red Team Village events. Insider-threat physical simulation : With authorization, test whether an attacker with a single insider's badge (cloned or borrowed) can reach a sensitive area (server room, executive floor) — measure time-to-detection. Building security assessment : Evaluate the physical controls of a new facility before the client moves in — lock types, reader placement, camera coverage, guard patrol coverage, CPTED (Crime Prevention Through Environmental Design) review. After-hours access testing : Verify whether badge readers enforce time-of-day restrictions, whether door-forced-open alarms fire correctly, and whether guard response meets the contracted SLA. Hidden camera detection sweep (defensive) : TSCM (Technical Surveillance Counter-Measures) — sweep a client's executive suite or SCIF for hidden cameras, audio bugs, and unauthorized network implants. Executive protection rehearsal : Pre-engagement recon of a venue before an executive event — map entry points, identify choke points, document reader vendors and camera coverage. Core Tools Lock Bypass & Mechanical Tool Purpose Notes Lock pick set (Peterson, SouthOrd, Sparrows) Pin-tumbler picking with hooks, rakes, and tension wrenches Standard 0.025" or 0.018" thickness; transparent practice locks first, then progressively harder belt ranks Bump keys Pin-tumbler bumping — cut to depth 9, instant open on many Kwikset/Schlage Bumping leaves no tool marks distinguishable from normal wear; legal status varies by jurisdiction Tubular lock pick (Lishi, tubular bump) Tubular cam locks (vending machines, kiosks, some bike locks) 7-pin and 8-pin variants; Lishi tools decode-and-pick in one motion Wafer lock pick (jigglers, tryout keys) Wafer locks (file cabinets, desks, some vehicle locks) Pre-cut jiggler sets work against low-quality wafer locks in seconds Dimple lock pick (Lishi dimple) Dimple locks (Kaba, Mul-T-Lock, Assa) — high-security but Lishi 2-in-1 reads bitting Lishi tools are restricted in some jurisdictions; verify before travel Shove knife (under-door bypass) Slip the latch of an inward-opening door from outside Works on commercial door hardware with flat latch bolts; fails on anti-shim deadlatches Under-door tool (copper wire + tape) Pull the inside handle of an outward-opening door from outside via the gap under the door The "Hollywood" tool — widely seen in red team content; works on many commercial lever handles Crash bar tape / film Defeat panic-exit bars by sliding tape over the latch Works on certain Von Duprin and similar exit devices; newer hardware has anti-tape shields RFID / NFC Cloning Tool Purpose Command / Notes Proxmark3 Standalone RFID/NFC analysis, sniffing, and cloning (125 kHz + 13.56 MHz) hf search , lf hid read , lf hid sim , hf mf clone , hf 14a sim ESP-RFID-Tool (ESP32-based) Portable 125 kHz HID Prox/Indala reader and cloner GitHub trending (572+); smaller and cheaper than Proxmark3; ideal for on-site 125 kHz work Walrus (TeamWalrus, iOS/Android) Smartphone-based NFC cloning for Mifare Classic/DESFire, HID iCLASS via add-on hardware App store install; the consumer/enthusiast entry point; full keys required for encrypted sectors Flipper Zero Multi-tool with 125 kHz RFID, NFC, sub-1GHz, IR Popular entry tool; rfid and nfc apps; less capable than Proxmark3 for raw protocol work TMD-5S / ACR122U USB NFC reader for Mifare Classic nested-key attacks ACR122U + mfoc recovers keys in minutes for default-key cards HackRF One Broad SDR for badge replay at 313 MHz/433 MHz gates and keyfobs Use sparingly for badge work; Proxmark3 is purpose-built; see sdr-rf-attack skill for SDR fundamentals Drop Boxes & Network Implants Tool Purpose Deployment Notes Hak5 LAN Turtle USB-shaped network implant with auto-SSH backdoor, packet capture, DNS spoofing Plugs into an internal PC or network jack; paired with a Cloud C2 for out-of-band C2 Hak5 Packet Squirrel Ethernet inline implant with payloads (VPN, nmap, tcpdump) Inline between a device and switch — harder to spot than a Turtle; same Cloud C2 Bash Bunny USB attack platform with keystroke injection, network, storage modes Multi-vector in a single device; see USB weapons section Raspberry Pi Zero W DIY implant — small, cheap, WiFi-enabled SSH reverse tunnel over the target's WiFi; conceal in a wall plate or cable bundle WiFi Pineapple Wireless assessment / rogue AP deployment Use only after physical entry; see wireless-pentest skill for protocol detail Plugable USB-Ethernet adapter Concealment-friendly form factor for a USB-Ethernet implant Hide the implant inside a "spare cable adapter" the client won't disturb USB Weapons Tool Purpose Payload Format USB Rubber Ducky Keystroke injection — DuckyScript inject.bin from duckencode ; examples: reverse shell, exfil, sticky-keys bypass Bash Bunny Keystroke + network + storage attack in one BunnyScript payloads; can impersonate Ethernet adapter for in-line network attack P4wnP1 (Pi Zero W) DIY Rubber Ducky + BadUSB on a $10 board P4wnP1 A.L.O.A. firmware; flexible HID/network/storage attacks Evilducker / Digispark Sub-$5 HID injection (ATtiny85) Smaller and less capable than Ducky; useful for cheap-and-cheerful payloads Cameras / Audio / Concealment Tool Purpose Notes Zetta / Blink / Wyze cameras Compact hidden cameras for on-site situational awareness Pre-engagement recon: log guard rounds; never deploy without explicit scope Custom Pi Zero camera DIY concealable camera (Pi Zero W + Pi Camera V2) Battery + cellular uplink for off-grid monitoring; conceal in office clutter Audio recorder / pen recorder Capture conversations for after-action reporting Legal status varies — one-party vs two-party consent states; check before recording Cable manipulator / fake outlet Concealment for implants and cameras Commercial products exist; DIY versions hide implants in wall plates, surge protectors, clock radios Recon & OSINT (Physical) Tool Purpose Notes Google Street View / satellite Pre-engagement building layout, entry points, camera placement Verify on-site; satellite imagery ages LinkedIn / employee badge photos Identify badge vendor (HID, Lenel, etc.) from employee photos Often visible at conferences or in office tour videos Job postings Identify badge system vendor ("experience with Lenel OnGuard") Combined with LinkedIn photos, gives the reader vendor pre-engagement Public building permits Confirm security system installers and recent camera upgrades County/city records; sometimes free Walk-by recon On-site: observe reader vendor, badge design, guard patrol cadence, camera coverage Legal grey area — stay on public property; never enter without authorization Methodology On-Site Engagement Six-Phase Process Phase 1 Phase 2 Phase 3 Phase 4 Phase 5 Phase 6 Scope & Legal → Pre-Engagement → Entry Vector → Execution & → On-Site Ops & → Exit & Recon Selection Access Persistence Evidence │ │ │ │ │ │ ▼ ▼ ▼ ▼ ▼ ▼ Contract, ROE, Building map, Locks / badges / Clone badge or Deploy drop Reverse tools get-out-of-jail badge vendor, USB / implants / pick lock; box, implant through flow, card, ID badges guard cadence, social — pick document time USB, hidden chain-of-custody for all ops camera coverage lowest-risk of entry cameras; pivots on evidence, report Phase 1: Scope & Legal (NO EXCEPTIONS) Physical pentest is the highest-risk skill in this workspace. A misread scope clause is a felony. Get this in writing first, always. Engagement contract : signed scope, dates, target addresses, prohibited areas (HR, executive residences, data center colocation cages owned by a third party). Authorization letter ("get-out-of-jail card") : client contact name, 24/7 phone, scope summary, engagement dates — carry on every operator at all times; produce immediately if confronted by security or law enforcement. Rules of engagement (ROE) : prohibited actions (no breaking glass, no picking locks on emergency exits, no social engineering against minors, no decoy devices left after engagement). TrustedSec physical-docs templates : use the community-maintained templates as a baseline; have legal counsel review and customize. Local law review : lock pick possession is regulated (see "Legal by jurisdiction" in payloads.md ). The UK, Japan, and several US states (California, Nevada) restrict possession without a credential. Insurance : verify the engagement is covered by both the client's and the consultancy's insurance. Phase 2: Pre-Engagement Recon Passive OSINT first, then a walk-by recon pass before any active operation. Building layout : satellite imagery, Google Street View, public floor plans (real-estate listings, building permits). Badge vendor identification : LinkedIn photos, conference videos, job postings ("experience with Lenel OnGuard / HID Origo / AMAG Symmetry"). Reader vendor on-site : walk-by recon — HID iCLASS SE readers are blue/white, Symmetry readers are grey, Lenel OnGuard readers are typically black with a side LED. Camera coverage : identify camera vendors (Axis, Hikvision, Dahua), placement (entry, exits, loading dock), and blind spots. Guard patrol cadence : walk-by at multiple times of day; log guard rounds; note shift changes. Employee behavior : badge-tap behavior (do they tailgate?), smoking break patterns, shift change at reception. After-hours activity : cleaning crews, HVAC contractors, IT staff on late shifts — these are pretexts for after-hours entry. Phase 3: Entry Vector Selection Score each entry vector against probability of success, time-to-entry, detectability, and reversibility. Pick the lowest-risk path. Entry Vector Probability (typical) Time to Entry Detectability Reversibility Tailgating (social) HIGH (most orgs) <1 min LOW (if guard absent) N/A — no artifact Badge clone (125 kHz HID Prox) HIGH (if deployed) <30 s LOW (reader log shows valid badge) Badge returns to owner undetected Badge clone (Mifare Classic) HIGH (CRYPTO1 broken) <5 min LOW Same as above Badge clone (HID iCLASS) MEDIUM (needs key) 5-30 min MEDIUM (cloning requires sniffing) Reader log may show duplicate tap Lock pick (pin-tumbler, commercial) HIGH 10-60 s LOW (no marks) No artifact Lock pick (high-security, Medeco/Assa) LOW minutes-hours MEDIUM (tool marks) May leave forensic evidence USB weapon (unattended workstation) HIGH (if observed) <10 s HIGH (USB device log) Exfil artifacts may persist Drop-box deploy (LAN Turtle) MEDIUM (needs network jack) 30 s MEDIUM (network admins may notice) Implant retrievable if undetected Crash bar / shove knife MEDIUM (hardware-specific) <10 s LOW No artifact Rule : try the lowest-detectability, lowest-reversibility-risk vector first. A successful badge clone leaves the badge holder unaware; a successful lock pick leaves no evidence; a successful tailgate leaves no artifact at all. USB weapons and drop boxes are highest-impact but highest-detectability — reserve for after entry is already achieved. Phase 4: Execution & Access Document everything: timestamps, before/after photos, any deviation from the plan. Wear body cameras (with consent of the client) for after-action review. Badge clone execution : capture the credential (sniff or borrow), clone to a writable card or Proxmark3 simulation mode, walk to the door, tap, enter. Lock picking execution : approach the door outside camera coverage (if possible); pick; enter; re-lock from inside if available; document. Tailgating execution : stage at a smoking area or loading dock; wait for an employee with a badge; follow at conversational distance; thank them at the door ("thanks — left my badge in the car"); produce badge / pretend to tap if challenged. USB weapon execution : locate unattended workstation (after-hours); insert Bash Bunny / Rubber Ducky; wait for payload completion (LED indicator); remove; leave no other artifacts. Phase 5: On-Site Ops & Persistence Once inside, the goal shifts to situational awareness, lateral movement, and persistent access. Situational awareness : deploy a hidden camera at a choke point (break room, elevator lobby) to track guard rounds for the duration of the engagement. Drop-box deployment : plug a LAN Turtle into an unattended PC's USB port or a wall network jack; verify Cloud C2 check-in before leaving the area.
Keywords that activate this skill. Click one to copy it.

This skill does not provide trigger words.

The downloaded .skill package contains the following fields.
Field Description
formatFormat tag (skill/v1)
skill_idUnique skill ID
nameSkill name
versionVersion
descriptionDescription
categoryCategories (array)
trigger_wordsTrigger words
tagsTags
sourceSource
source_urlSource URL (this page)
exported_atExported at (set per download)
system_promptSystem prompt body
model_configModel config: provider / model / temperature / max_tokens / top_p
examplesExamples
install_guideImport guide for Coze / Dify / Claude / custom frameworks
The same skill can be exported in different platform formats.
.skill Standard format with system_prompt and model_config, ready for any agent framework Download
.skillpro Enhanced format with scripts, tools, dependencies and hooks Download
.json Plain JSON export with system_prompt and model parameters only Download
Coze Markdown with frontmatter, for Coze platform import Download
Dify Dify DSL, import directly after creating an app Download

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

验证码 --

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。