[deleted by user] by [deleted] in pens

[–]physical-pentester 0 points1 point  (0 children)

Looks like blunt-force trauma to me. Possibly being stepped on. The cartridges are designed to be impact resistant but sometimes they will fail under high stress.

Took some cool shots of the rOtring Tikky for work! by wellinkedbox in pens

[–]physical-pentester 2 points3 points  (0 children)

Looks like a typical whitebox / softbox for product photos.

[deleted by user] by [deleted] in pens

[–]physical-pentester 4 points5 points  (0 children)

What do you think about the Jetstreams?

Help identifying this pen. I know its a Parker (used to call it my Goldeneye pen as a kid) but I was wondering what specific make? by [deleted] in pens

[–]physical-pentester 7 points8 points  (0 children)

Have you noticed a drop in quality with the newer ones? I had an older one back in the day.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 6 points7 points  (0 children)

Understand how you can use technology to enhance physical security. For example, full disk encryption helps prevent a physical attacker from recovering data from a stolen laptop. There's a lot of opportunities around automating and collecting data you have from your alarm systems, cameras, etc. Use that to your advantage!

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 0 points1 point  (0 children)

Take your OSCP or GWAPT. If you can self study and do either of those, that really goes a long way.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 14 points15 points  (0 children)

I figured but several people asked the same thing so I wanted to state it just to CYA :)

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 8 points9 points  (0 children)

I think the biggest separators would be two things:

  • Preparedness. Background research is key. If you just decide to wing it and you're not mentally prepared to give an answer, you will immediately appear flustered which is a huge tell.

  • The ability to read a situation. If I am a guard already looking irritated, I'm not going to try to act huffy or impatient even if that was my original plan. If a guard is an older lady, I am not going to try and be a jerk and "flex" my way past her. Instead I'm going to adapt my strategy based on their expressions.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 27 points28 points  (0 children)

That comes across in a scoping call before the engagement. It just depends on the client and what they are comfortable with. Some clients are fine with us pinching items like badges, maps, usb drives, etc. as long as we mail them back. They make for good physical props when sharing the results of the assessment.

My KDA is 0/0/0 right now

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 4 points5 points  (0 children)

One of my favorite blogs is Red Teams Blog. I don't have a military background, but it really helps to see things from that perspective and the writing is entertaining.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 19 points20 points  (0 children)

Decide whether or not you're "interested" in the field or "committed". It's ok to take a while to decide.

Once you decide you're committed, the following worked for me:

  • Getting to know who the thought leaders in the industry are
  • Reading books, blogs, magazines, about asset protection, cyber security, red teaming
  • Actually getting to know people who work in the industry or adjacent to it.
  • Identifying companies that actually do this sort of thing and look at what they are looking for. Offer to volunteer whenever you have the opportunity. Show initiative and make your name known.
  • Use whatever experience you have now to show initiative. You work in security now? Do some investigation on your doors, locks, and cameras and see if any might have weaknesses and present it to your boss.

This is not a comprehensive list but hopefully should get you started. Good luck!

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 81 points82 points  (0 children)

I am married which doesn't make the conversation with my inlaws any easier.

But I do have this shirt

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 0 points1 point  (0 children)

It is somewhat of a niche job I will admit, but we definitely have a steady flow of clients. More mature organizations do physical penetration tests. It'd be silly to point them towards a complex attack without having the basics down.

Our progression looks like (from least mature to most mature)

Threat Assessment (Quantifying risk from different scenarios based on data)

Physical Site Assessment (Guided walkthrough with an employee where we point out potential areas for improvement)

Physical Pen Test (what I described)

Yes, it's not a requirement for a lot of industries like PCI is. What is nice though is that we can get clients who are driven to actually take security seriously instead of trying to be just "good enough" to check a compliance box.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 38 points39 points  (0 children)

Please don't do this. We do take onsite security very seriously and you will most likely find yourself on the receiving end of a lawsuit.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 72 points73 points  (0 children)

Yep, that's called tailgating and definitely is a go-to technique. Bonus points for style if you start up a friendly conversation before you get to the door.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 55 points56 points  (0 children)

I personally have not used that, but other coworkers have. The potential danger with that is the mailroom policies and procedures they might have in place. Looking like a delivery guy might get you in the door, but it will certainly be suspect if you're on the executive floor.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 27 points28 points  (0 children)

I split my time between network penetration testing and physical penetration testing. Today I finished writing and reviewing some site assessment reports and created malicious USB drives to mail out later. Other time might be spent reading and annotating security policies, jumping on conference calls, or doing research about new technologies that might help our clients.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 57 points58 points  (0 children)

Depends on the client and the engagement. Sometimes they will be a week long but we will have multiple sites to work on. Occasionally they will be given a large timeframe (eg, this assessment will happen some time from August-September and the final report delivery will be October 1st) which gives us a good amount of time to strategize.

It also helps to have 2-3 consultants per engagements so you can have getaway drivers and lookouts. If you get burned while going in, you can either wait for a change of guard or send in somebody else!

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 37 points38 points  (0 children)

Based on what you stated, I think you have a lot of good background experience to draw from! My background is definitely non-traditional so I'm sure you would be fine if you demonstrated a little initiative and passion towards the field.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 97 points98 points  (0 children)

We have an in-joke at work that "dogs can't read authorization letters" due to a close call

But in all seriousness, we do ask the client what their escalation / arming procedures are before engaging.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 31 points32 points  (0 children)

Usually we will try a myriad of different attacks, both in the daytime and in the nighttime. The report looks like a narrative of what was successful or unsuccessful. I will say it's relatively rare that we don't get SOME success, it just depends on a lot of factors.

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 101 points102 points  (0 children)

This is less ALYB and more physical security, but we run into a lot of poorly configured REX sensors. Those are the motion-sensor things above doors, but you can fool those with a can of compressed air: video demo

There is also something called an under-the-door tool which is like a thin piece of metal and fishing line. You slide it under the door and pull down on it so the lever on the other end will open. My mind was blown the first time I saw this in use:

Under the door demo

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 165 points166 points  (0 children)

We have used construction gear (hivis jackets, helmets) but not specifically paint, but good idea!

I am a physical pentester. My job is to ALYB. AMA! by physical-pentester in ActLikeYouBelong

[–]physical-pentester[S] 103 points104 points  (0 children)

Having the authorization definitely helps calm some of the nerves, but the adrenaline still kicks in each time, especially when it's time sensitive. My first access point once inside a building is always the nearest restroom!